Nexiv Labs is now operating six divisions across healthcare, veterinary, commerce and infrastructure. See the group →
Trust centre

How we protect what you give us

Two of our divisions handle health data and one moves money. That sets the security floor for the entire group — not a separate "enterprise tier".

Control framework

Mapped to recognised standards

Our internal control set is mapped to ISO/IEC 27001 Annex A, with additional controls drawn from ISO/IEC 42001 for AI management, UK and EU GDPR, and HIPAA safeguards where health data is in scope.

On certification status. We describe our controls as aligned to these standards. Where a formal certification or attestation has been completed for a specific service, the certificate and its scope are provided under NDA on request — we do not imply certification we do not hold.

ISO/IEC 27001 aligned ISO/IEC 42001 aligned UK & EU GDPR HIPAA safeguards PCI DSS SAQ-A scope
Control coverage
Control domains

What is actually implemented

Encryption

TLS 1.3 in transit with HSTS preload. AES-256 at rest with envelope encryption and per-tenant keys held in a managed KMS. Keys rotate on a 90-day schedule; media in consultations additionally uses per-session keys.

Access management

SSO with enforced MFA, role- and attribute-based authorisation decided centrally, and no standing production access. Elevation is just-in-time against a named ticket, approved by a second person and expires automatically.

Audit & monitoring

Append-only access logs on every record read, write and export, retained and queryable per tenant. Security events stream to a central pipeline with alerting on anomalous access patterns and privilege changes.

Network & workload

Default-deny network policy between services, mutual TLS for internal traffic, workload identity instead of long-lived credentials, and admission control that refuses unsigned images or undeclared data classes.

Supply chain

SBOM generated for every build, dependency and container scanning with a hard gate on high-severity findings, artefact signing verified at deploy, and pinned base images rebuilt on a schedule.

Resilience

Multi-region active-active deployment, point-in-time recovery within five minutes, and disaster recovery exercised quarterly against a stated RTO of 60 minutes — including the failures we find.

Data handling

Classification, residency and retention

Every dataset carries a class. The class determines where it may live, who may read it, how long it is kept and what happens when it expires.

Class Examples Residency Access Default retention
Clinical Consultation records, prescriptions, monitoring data Region-pinned, no cross-region replication Named clinical roles; every read logged Set by the operating organisation
Identity Account details, verification documents Region-pinned Verification team, break-glass alerted Account life + statutory period
Financial Orders, invoices, payout records Region-pinned; card data never touches our servers Finance roles only 6 years (tax/accounting)
Operational Logs, traces, metrics Region-pinned; PII scrubbed at ingestion Engineering, no clinical content 30–90 days
Public Marketing site, documentation, listings Global CDN Open Indefinite

Residency is enforced, not promised

Region pinning is applied by admission policy: a workload that would breach it is refused by the cluster.

Card data stays out of scope

Payment details are captured by our PCI-compliant payment providers directly. We store tokens, never card numbers.

Nothing personal goes on-chain

Where Nexiv Chain anchors a record, only a salted commitment is written — so erasure rights remain intact.

Sub-processors

Who else touches the data

We use third parties for infrastructure, payments and communications. Each is assessed before onboarding, bound by a data processing agreement, and reviewed annually. Customers on a DPA receive 30 days' notice before a new sub-processor is added.

CategoryPurposeData touchedRegion control
Cloud infrastructureCompute, storage, managed databasesAll classes, encryptedTenant-pinned region
Edge & CDNTLS termination, WAF, static deliveryRequest metadata onlyGlobal edge, no origin data at rest
Payment processingCard capture, settlement, payoutsPayment data, direct to processorProcessor's own compliance scope
CommunicationsTransactional email, SMS, pushContact details, message contentRegional sending endpoints
Real-time mediaWebRTC signalling and TURN relayEncrypted media streams in transitRegional media servers
Identity verificationKYC and licence checks for sellers/cliniciansVerification documentsRegion-appropriate provider
ObservabilityLogs, traces, metrics, alertingOperational data, PII scrubbedRegion-pinned collection

The current named sub-processor list, with entity names and locations, is provided as part of our data processing agreement. Request it at support@nexivlabs.com.

Responsible disclosure

Found something? Tell us before you tell anyone else

We welcome reports from security researchers and will not pursue legal action against anyone acting in good faith under this policy.

  • Email support@nexivlabs.com with "SECURITY" in the subject line
  • Include reproduction steps, affected endpoints and impact assessment
  • We acknowledge within 2 business days and give a remediation timeline within 10
  • Please allow 90 days before public disclosure, or sooner by agreement

Out of scope: denial-of-service testing, social engineering of staff or customers, physical attacks, spam or automated scanning that degrades service. Do not access, modify or exfiltrate data belonging to anyone other than a test account you control.

Incident severity & response
  • Sev 1 — CriticalConfirmed data exposure or total service loss. Response begins immediately; affected customers notified without undue delay.
  • Sev 2 — HighMajor functional impairment or a credible exploit path. Response within 1 hour, 24/7.
  • Sev 3 — MediumDegraded performance or a contained issue with a workaround. Response within 4 business hours.
  • Sev 4 — LowMinor defect, no material impact. Scheduled into the normal backlog.
Personal data breach
  • AssessmentRisk to individuals assessed immediately on confirmation.
  • RegulatorNotified within 72 hours where the threshold is met.
  • ControllersNotified without undue delay where we act as processor.
  • IndividualsNotified where there is a high risk to their rights and freedoms.
Due diligence

Questions buyers always ask

Yes. Send it to support@nexivlabs.com and we will complete it, typically within five business days. For common frameworks we can usually supply a pre-completed response pack under NDA to save both sides time.
Yes — independent testing of internet-facing surfaces, with remediation tracked to closure. A summary letter is available under NDA. We also run continuous automated scanning and dependency monitoring between tests, since an annual test alone is a snapshot, not a posture.
Under an agreed rules-of-engagement document, yes — against a dedicated environment, with scope, timing and contact points fixed in advance. We do not permit unannounced testing against shared production, because it is indistinguishable from an attack and triggers our incident response.
You get a structured export in a documented format during the notice period. After termination we delete or return data per the agreement — typically deletion within 90 days, with backups aging out on their normal cycle. Where law requires retention (financial or clinical records), we hold only what is required and only for as long as required.

Need the full evidence pack?

Architecture diagrams, sub-processor list, test summaries and DPA templates are available under NDA.