Implementation Security & Governance

AI and client data should operate inside boundaries
the business can explain and approve.

Nexus incorporates access discipline, implementation controls, testing, documentation, and human-review boundaries into scoped projects and the current Client Portal. This page describes an operating approach and current technical configuration; it is not a cybersecurity audit, legal compliance opinion, certification, penetration test, or guarantee that a system is immune from failure or unauthorized access.

Client Portal

Current workspace controls

The Nexus Client Portal is an authenticated business workspace, not a public document dropbox.

Authenticated accounts

Portal data access requires a user session. Public Quick Scan and diagnostic tools remain separate from authenticated client-workspace data.

Company-level authorization

Current database policies use row-level authorization so a signed-in client is scoped to the company workspace associated with that account. Nexus administrator access is separated through an internal administrator record rather than user-editable profile metadata.

Private document bucket

Portal documents are stored in a private bucket. File paths are company-scoped and access rules check authenticated company membership or authorized Nexus administration before allowing file operations.

Restricted upload types

The initial portal restricts uploads to selected common business document/image formats and applies a 25 MB per-file limit. These controls reduce accidental misuse but are not malware scanning, data-loss prevention, or content certification.

Notification boundaries

In-app and optional browser alerts are convenience features. They are not represented as guaranteed delivery for urgent incidents, legal notices, or contractual service levels.

Sensitive-data boundary

The portal should not be used for passwords, authentication secrets, payment-card data, medical records, highly sensitive personal data, or regulated data unless that data type and handling method are expressly approved in a signed engagement.

Client data and account control

Client-provided data and client accounts remain under the client’s control subject to applicable law, contracts, and third-party platform terms. Ownership and license rights for project deliverables, Nexus pre-existing materials, open-source components, and third-party software are defined in the written client agreement.

Least-privilege access

Nexus seeks the minimum access reasonably necessary for the written scope. Production credentials should be provided through approved credential-management or platform authorization methods—not public forms, ordinary chat messages, or unprotected documents.

Human approval boundaries

Material actions require an identified human owner unless the signed scope expressly authorizes a bounded automated action. Technical capability alone does not authorize Nexus or an AI system to make a business decision.

Testing and acceptance

Where applicable, projects define test cases, failure modes, acceptance criteria, rollback/disable procedures, and responsible owners. Client acceptance is documented against agreed criteria rather than inferred from portal activity alone.

Monitoring and changes

Monitoring, alerting, response times, maintenance, and change-management obligations apply only to the extent specified in the service agreement. No 24/7 monitoring, cybersecurity monitoring, uptime warranty, or incident-response service is implied.

Offboarding and access removal

At project or service termination, Nexus can document handoff items, remove Nexus-controlled access, and identify client actions needed for credential rotation, vendor access removal, data return/deletion, and service shutdown, as defined by contract.

Control levels

Authority is classified before automation.

  • Human-Only: AI may not perform the decision or action.
  • AI Assist: AI retrieves, summarizes, analyzes, or suggests; a human decides.
  • Draft + Human Review: AI prepares an output that requires designated review before release.
  • Controlled Automation: Narrow, pre-authorized actions may execute within documented limits, logs, and exception paths.
Higher-risk work

Specialists remain specialists.

Nexus does not represent itself as a law firm, accounting firm, medical provider, licensed cybersecurity assessor, payment processor, or regulatory certification body. Work involving regulated or high-risk environments may require qualified client counsel, security professionals, compliance specialists, or other licensed experts.

Not automated by default

Unbounded decisions with material human consequences.

Nexus does not default to autonomous hiring or termination decisions, legal determinations, medical decisions, unrestricted financial transactions, credential sharing, security bypasses, or other high-impact actions. Any permitted automation must be narrowly scoped, technically feasible, legally permitted, authorized by the client, and documented with appropriate controls.