Skip to main content
Building multi-tenant SaaS on the Base Platform — .NET, React, and cloud-native architecture.Explore Base Platform
Trust Center

Security, privacy, and reliability by design

How NexorbitLabs approaches customer data protection, responsible operations, and trustworthy software delivery — from secure SDLC practices to accessibility and responsible AI.

At a glance

Trust metrics

Operational and delivery commitments that underpin how we build and operate software.

Not published yet

This section will be published when the content is verified and ready for the public site.

Privacy

Privacy commitment

Purpose limitation, minimization, and transparent handling of personal data — with a full legal policy available.

We collect and process personal data only for stated purposes, limit retention to what delivery and legal obligations require, and support individual rights. Read the Trust Center privacy overview or the full legal Privacy Policy.

Compliance

Programs and roadmap

Published compliance items. Unverified programs are labeled Roadmap — never as certifications.

GDPR

Roadmap

Privacy-by-design delivery patterns for minimization, access control, retention, and subject-rights workflows.

Roadmap: Formalize DPIA templates and processor evidence packs for customer reviews.

CCPA

Roadmap

Consumer privacy request handling patterns for U.S. state privacy obligations where applicable.

Roadmap: Publish request workflows and retention matrices when U.S. processing scope is confirmed.

ISO 27001

Roadmap

Information security management system formalization path.

Roadmap: Define ISMS scope, control owners, and evidence collection before any certification claim.

SOC 2

Roadmap

Trust Services Criteria control evidence for operated services — not attested today.

Roadmap: Build control inventory and independent attestation plan when operated SaaS scope requires it.

HIPAA

Roadmap

Healthcare privacy and security patterns for appropriately scoped engagements.

Roadmap: BAAs, PHI minimization, and environment isolation defined per engagement — no general HIPAA certification claim.

PCI DSS

Roadmap

Payment architectures that prefer tokenized providers and minimize card-data exposure.

Roadmap: Scope reduction guidance only until a specific PCI assessment is commissioned.

Cyber Essentials

Roadmap

Baseline cyber hygiene controls for organizations that require Cyber Essentials alignment.

Roadmap: Assess applicability and evidence needs before any badge or claim is published.

AI Governance

Roadmap

Human oversight, privacy-first model use, evaluation, and risk review for AI features we deliver.

Roadmap: Expand evaluation checklists and customer-facing AI policy detail as products reach Live status.

OWASP practices

Roadmap

Secure SDLC habits informed by OWASP guidance — not a certification.

Roadmap: Continue mapping reviews to ASVS-informed controls by application risk.

Accessibility (WCAG)

Roadmap

WCAG-oriented design and engineering targets for interfaces we control — not an audited conformance claim.

Roadmap: Publish accessibility statement updates when formal audits are completed.

Responsible AI

AI governance principles

Human oversight, privacy-first models, and risk-based controls for AI-assisted products.

Human oversight

High-impact AI outputs are reviewable by people. Escalation paths exist for sensitive decisions.

Privacy-first AI

Training and inference designs minimize personal data. Customer data is not used to train shared models without agreement.

Explainability principles

We prefer systems that can surface why a recommendation was made when the use case demands it.

Reliability

Operational reliability

Uptime goals, maintenance policy, and status commitments for platforms we operate.

Soon

Status page

A public component status and incident feed is planned. Contact us for operational updates on contracted platforms today.

Scheduled

Maintenance window

For platforms we operate under contract, planned maintenance is announced in advance when practical, except for emergency security patches.

Direct

Incident updates

During active incidents on contracted platforms, we aim to share status, impact, and next-update timing with the account team.

FAQ

Common questions

Answers about security, privacy, and how to engage our trust teams.

Contact the security team

Report vulnerabilities, request vendor questionnaires, or ask about our security program.

Talk with our security team

Request documentation, report a vulnerability, or start a vendor security review via nexorbitlabs@gmail.com — or reach us through Contact.