Information Security Policy
This policy describes how Nexus Frontier Tech Limited secures the OneNexus platform and the information it processes, from the infrastructure Signs are produced on to the authorization and access controls that decide who can touch them. It sits alongside our Privacy Policy, which covers what we collect and why; this page covers how we keep it safe.
01Scope and policy statement
This policy covers the information assets Nexus Frontier Tech Limited handles in operating OneNexus, including the onenexus.ai website, any product operating on a subdomain of onenexus.ai such as lab.onenexus.ai, and the infrastructure that produces, corrects and signs Signs. It applies to our directors, employees, contractors and any sub-processor with access to customer content, and it exists to protect the same thing SignChain protects: that a Sign's record can be trusted.
We maintain this policy alongside our obligations under applicable information security and data protection regulation. See our Privacy Policy for how we handle personal information specifically; this page covers the controls around it.
02Information security governance
An Information Security Committee owns this policy and the operational manuals, processes and internal audits that sit under it. The Committee reviews OneNexus's security posture on a regular cycle, and is accountable on an ongoing basis for the confidentiality, integrity and availability of the information assets in scope.
03ISO/IEC 27001:2022 certification
OneNexus is ISO/IEC 27001:2022 certified (certificate IC-IS-2412247), independently verifiable at intercert.com/resources/certification-verification. ISO/IEC 27001 is the international standard for information security management systems: certification means an accredited external auditor has reviewed our security controls, risk assessment process and continual-improvement cycle against the current 2022 revision, rather than us simply asserting them.
Certification isn't a one-time badge. We maintain it through periodic surveillance audits, and the same Information Security Committee that owns this policy owns remediation of anything an audit finds.
04Data protection and encryption
Customer content, including source documents, agent outputs, corrections and signatures, is encrypted in transit and at rest. Access to the underlying infrastructure is limited to personnel who need it to operate the service, and access to production systems is logged.
05Access control and signer authorization
Access inside OneNexus follows the same authorization-level model as signing authority: a user or agent can only reach the systems and content their authorization covers. Administrative access to customer content is restricted on a need-to-know basis and reviewed periodically. Production access is kept separate from the environments engineers use for day-to-day development.
06SignChain integrity and audit logging
SignChain's append-only design is itself a security control. Once a Sign is produced, corrected or signed, that entry cannot be edited or deleted, only superseded by a new one, including by us. Every entry is timestamped and attributable to a specific agent, analyst or signer, so a compromised account is contained to what it can create going forward. It can't rewrite the past.
07Sub-processors and third-party security
We use a limited set of sub-processors to run OneNexus: cloud infrastructure and hosting, one or more AI model providers, and other operational vendors under contract. Each is bound by contract to handle customer content under security terms consistent with this policy, and we review a sub-processor's security posture before onboarding and periodically thereafter. See our Privacy Policy for what each category of sub-processor can access.
The onenexus.ai website has a deliberately small third-party surface, and it is checkable rather than asserted. Fonts, stylesheets, scripts and images are all served from onenexus.ai itself. The site sets no cookies of its own, runs no analytics, and loads no tag manager, advertising pixel or session-recording tool. No page loads any third-party code at all; the enquiry form is screened for automated abuse at the network layer, not by a script in your browser. A Content-Security-Policy is served on every response to enforce this rather than rely on it, restricting where scripts, frames, fonts and connections may come from, and where a form may submit to. Viewing this site leaves no record of your visit with anyone but us and the infrastructure serving it.
08Incident response and notification
We maintain an internal process for identifying, containing and investigating security incidents. Where an incident affects customer content, we'll notify affected account administrators without undue delay once we have enough information to do so, consistent with our contractual and regulatory obligations.
09Employee security and awareness
Access to production systems and customer content is limited to personnel whose role requires it, and is revoked promptly when it no longer does. Personnel with such access complete information security training covering their responsibilities under this policy on a periodic basis.
10Reporting a security concern
If you believe you've found a security vulnerability in OneNexus, or that an account or Sign may be compromised, contact dpo@nexusfrontier.tech. Include what you observed and, where possible, the relevant Sign or SignChain entry ID. SignChain's audit trail makes most issues traceable to a specific action.
11Changes to this policy
We review this policy periodically and update the "Last updated" date above when we make changes. Where a change is material, we'll notify account administrators directly rather than relying on you to check this page.