Trust centre

What your security team will ask

How Nexugen handles your data, who we share it with, how long we keep it, and plain answers to the usual questions.

Security

Every app is checked before it goes live. Secrets are encrypted before they are stored. App databases are backed up every night. Live apps are watched and their owners told when one stops answering. Teams give each person only the access they need.

How Nexugen keeps your app safe

Subprocessors

The companies we use to run Nexugen. Last updated 27 September 2026.

CompanyWhat forDataWhere
ContaboServer hosting for the platform, its database and the apps it runsAll platform data, app code, app files and logsEuropean Union
AnthropicAI that plans, writes and reviews app codePrompts, app code and project content sent for a build or editUnited States
OpenAIAI for some generation tasksPrompts and project content sent for those tasksUnited States
GoogleSign in with Google, and AI for some generation tasksName and email at sign-in; prompts and content sent for those tasksGlobal
Cloudflare (R2)File storage for uploads and app assetsFiles you and your customers uploadGlobal
NeonManaged Postgres databases for apps that need their own databaseThe data your app storesUnited States (US East)
GitHubSign in with GitHub, and code repositories when you connect oneAccount name and email at sign-in; app code you choose to pushUnited States
VercelHosting for apps you choose to deploy thereApp code and the settings needed to run itGlobal
CodemagicBuilding mobile apps for the app storesMobile app code and signing settingsGlobal
BrevoSending account and notification emailsEmail address, name and the messageEuropean Union
PaystackCard payments for Nexugen plans and creditsName, email and payment details (card numbers are held by Paystack, not Nexugen)Nigeria
StripeCard payments for Nexugen plansName, email and payment details (card numbers are held by Stripe, not Nexugen)United States
CreemCard payments and tax handling for Nexugen plansName, email and payment details (card numbers are held by Creem, not Nexugen)Global
NamecheapRegistering domain names you buy through NexugenThe registrant contact details a domain needsUnited States

Data retention

The standard periods. An Enterprise agreement can change them.

Audit log
Kept while your team exists. Enterprise teams can set a period of 90 days or more; 365 days is the Enterprise default.
Build and edit logs
Kept while the project exists. Enterprise teams can set a period of 30 days or more; 90 days is the Enterprise default.
App database backups
Taken nightly, kept 14 days.
Platform database backups
Taken nightly, kept 14 days.
Uptime history
Kept 90 days.
A deleted project
Removed when you delete it. Its database backups age out within 14 days.
A deleted account
Suspended for 30 days so it can be restored if the request was a mistake, then removed.

Incidents

  • If your live app stops answering for two checks in a row, its owner gets an email, and another when it is back.
  • Platform outages are shown on the status page.
  • For a security incident, we email the owners of affected accounts once we know what happened and who is affected, and say what we are doing about it.
  • Enterprise customers get a monthly uptime report with every incident listed.
Platform status

Security questionnaire

Short answers to the questions vendor reviews ask most.

Is data encrypted in transit?

Yes. Nexugen and the apps it hosts are served over HTTPS. Calls from Nexugen to the services it uses also go over HTTPS.

Is data encrypted at rest?

Secrets you give Nexugen, such as API keys and payment keys, are encrypted with AES-256-GCM before they are stored. Files in Cloudflare R2 and app databases on Neon are encrypted at rest by those providers. The platform server disks and the platform database are not separately disk-encrypted today. An app’s environment variables are also written to its server so the app can run.

Where is our data stored?

The platform, its database and the apps it runs are on servers in the European Union. Apps with their own database use Neon in the United States by default. Uploaded files are in Cloudflare R2. Prompts and code are sent to the AI providers listed below, mostly in the United States.

Can we choose where our data is stored?

Not today.

Do you back up our data?

Yes. The platform database is backed up every night and kept 14 days. Each app with its own database is backed up every night, kept 14 days, and can be restored in one click. Backups are kept on the platform’s server; they are not yet copied to a second location.

What happens if the server fails?

We restore from the nightly backups. There is no automatic failover to a second region today.

How do you control who can see our workspace?

Each team member has a role: Viewer, Member, Admin or Owner. Each role can do only what it needs. Live build rooms are private to your team unless you share one.

Do you support single sign-on?

Yes, on Enterprise. SAML 2.0 and OpenID Connect, with SCIM to add and remove people automatically.

Do you support two-step sign-in?

Yes. Two-step sign-in is available on every account.

How are passwords stored?

Passwords are hashed with bcrypt. Nexugen never stores them in plain text.

Is there an audit log?

Yes. Each team has an audit log of who did what and when: sign-ins, team changes, edits, deploys and settings changes.

Who at Nexugen can access our data?

A small number of Nexugen staff who run the platform and give support. Not every staff action is recorded in a log yet.

Are customer apps isolated from each other?

Yes. Each web app runs as its own locked-down service under a separate, restricted system user. It can see only its own files: not other apps, not the platform, and not the platform's settings or secrets. Apps do share servers. Mobile preview servers, which only run while an owner is testing, are not sandboxed this way.

Has a third party tested your security?

No. No third-party penetration test has been done yet.

Do you hold SOC 2 or ISO 27001?

No. Nexugen does not hold either certification today.

How do you handle vulnerabilities?

Every app is checked before it goes live for packages with known security holes, keys left in the code, unprotected actions and unsafe uploads. Apps on a framework version with a known remote-code-execution flaw are not run. Owners can switch on automatic patching.

How is the network protected?

The servers accept connections only for the web (HTTPS and HTTP) and for administration over SSH. Everything else is blocked. A monitor on the server watches for unexpected programs and alerts us.

How will you tell us about a security incident?

We email the owners of affected accounts as soon as we have confirmed what happened and who is affected. For a breach of personal data, we tell you within 72 hours of confirming it, as the DPA sets out. Platform outages are shown on the status page.

Do you train AI models on our data?

Nexugen does not train AI models. Your prompts and code are sent to the AI providers listed below to do the work you ask for.

Do you store card numbers?

No. Card payments are handled by Paystack, Stripe or Creem, which hold the card details.

Who owns the code Nexugen builds?

You do. You can download your app’s code at any time.

How do we get our data back or delete it?

Download your app’s code from the project. For a copy of your account data, email us. Deleting a project removes it straight away. Deleting an account suspends it for 30 days, then removes it.

How long do you keep our data?

See Data retention above. Enterprise teams can set how long audit and build logs are kept.

Do you offer an uptime commitment?

Yes, on Enterprise: 99.9% a month, with service credits if we miss it. See the SLA.

Will you sign a DPA?

Yes. Our standard DPA is written for GDPR and the Nigeria Data Protection Act 2023. Email us to sign it.

How do we report a security problem?

Email hello@nexugen.app with “Security” in the subject.

Documents

Need something else for your review?

Email hello@nexugen.app and we will answer your questionnaire.