Program ownerNebuSec Corp. · SecurityLast reviewed
Our approach
Controls begin with clear principles.
01
Least privilege
Access is limited to people and systems with a legitimate need, for no longer than that need exists.
02
Defense in depth
We layer preventive, detective, and responsive controls so that no single safeguard carries the entire burden.
03
Continuous improvement
Controls are reviewed as our products, infrastructure, risks, and customer requirements change.
Security program
How we protect customer data and systems
The controls below describe our current public posture. Their implementation may vary by product, deployment model, and customer agreement.
Data protection
Customer data is handled according to its sensitivity and the service that processes it.
In transit
NebuSec requires encrypted connections for customer data transmitted across public networks.
At rest
Systems that persist customer data use encryption controls appropriate to the storage service and data type.
Data lifecycle
We limit collection and retention to operational, contractual, and legal needs, as described in our Privacy Policy.Read the Privacy Policy
Infrastructure security
Managed infrastructure and explicit environment boundaries reduce the systems our team must operate directly.
Service boundaries
Production services, preview environments, and development workflows are separated according to their purpose.
Configuration
Infrastructure and deployment changes are versioned, reviewed, and validated before release where the platform supports it.
Monitoring
Availability checks and operational alerts help the team identify and investigate service disruption. Customers can review service availability and incident updates on the NebuSec status page.View service status
Access control
Access to customer information and production systems is restricted to authorized personnel with a business need.
Authorization
Access is scoped to the service and task rather than granted as broad, standing access.
Customer reports
Private customer security reports are protected by report-specific access policies at the network edge.
Review
Access requirements are revisited when responsibilities, systems, or customer engagements change.
Secure development
NebuSec applies its vulnerability-research experience throughout development and release work.
Change control
Source changes are tracked in version control and reviewed before they are promoted to production.
Automated validation
The public website build blocks high- or critical-severity dependency advisories and validates routes, links, accessibility, and page weight.
Research-led testing
Our team validates security findings through technical analysis and, where appropriate, working reproduction or exploit evidence.
Personnel and endpoint security
Personnel and device controls reduce the risk of unauthorized access to company and customer systems.
Identity security
Workforce access uses centralized identity controls, multi-factor authentication, and single sign-on where supported and appropriate.
Personnel security
Security responsibilities are addressed during onboarding, with background screening applied where appropriate and permitted by law.
Awareness
Personnel receive security guidance relevant to their responsibilities, including secure handling of systems, credentials, and customer information.
Endpoints
Corporate endpoints use safeguards such as disk encryption, screen locking, software updates, and endpoint protection appropriate to the device and role.
Vendor and subprocessor management
Third parties are evaluated according to the access and risk introduced by the service they provide.
Due diligence
Reviews consider the data a vendor handles, its access to company or production systems, and the operational importance of the service.
Safeguards
Security, confidentiality, and data-protection obligations are included in vendor arrangements where appropriate to the relationship.
Subprocessors
Information about subprocessors relevant to a customer service is maintained and can be provided during security review.
Incident response
Security and availability events are handled through a defined path from initial signal to follow-up.
Triage
We assess the affected systems, data, customers, and immediate containment options.
Containment and recovery
The team prioritizes limiting exposure, restoring safe operation, and preserving the evidence needed to understand the event.
Communication
Affected customers receive relevant updates in accordance with contractual and legal obligations.
Assurance and compliance
Security claims should be current, specific, and capable of being verified during customer review.
Certifications
SOC 2 readiness work is underway. NebuSec does not currently claim a completed SOC 2 report, attestation, or any other third-party compliance certification. Completed certifications will be named only after they can be independently verified.
Customer review
Our team can discuss relevant controls, data handling, architecture, and security requirements during procurement.
Security review
Continue the review with our team.
Contact NebuSec to discuss a security questionnaire, architecture, data handling, or requirements specific to your organization.