Skip to content
OneNexus by Nexus Frontier Tech
Platform
The Signing Standard Governed AI Orchestration
Signs
Financial Spreads ESG Assessments KYC Files Client Statements
Log in Request a demo
Menu
Platform The Signing Standard Governed AI Orchestration Signs Financial Spreads ESG Assessments KYC Files Client Statements Log in
Legal

Information Security Policy

Effective 1 January 2022 · Last updated 12 August 2026

This policy describes how Nexus Frontier Tech Limited secures the OneNexus platform and the information it processes, from the infrastructure Signs are produced on to the authorization and access controls that decide who can touch them. It sits alongside our Privacy Policy, which covers what we collect and why; this page covers how we keep it safe.

On this page
  1. Scope and policy statement
  2. Information security governance
  3. ISO/IEC 27001:2022 certification
  4. Data protection and encryption
  5. Access control and signer authorization
  6. SignChain integrity and audit logging
  7. Sub-processors and third-party security
  8. Incident response and notification
  9. Employee security and awareness
  10. Reporting a security concern
  11. Changes to this policy

01Scope and policy statement

This policy covers the information assets Nexus Frontier Tech Limited handles in operating OneNexus, including the onenexus.ai website, any product operating on a subdomain of onenexus.ai such as lab.onenexus.ai, and the infrastructure that produces, corrects and signs Signs. It applies to our directors, employees, contractors and any sub-processor with access to customer content, and it exists to protect the same thing SignChain protects: that a Sign's record can be trusted.

We maintain this policy alongside our obligations under applicable information security and data protection regulation. See our Privacy Policy for how we handle personal information specifically; this page covers the controls around it.

02Information security governance

An Information Security Committee owns this policy and the operational manuals, processes and internal audits that sit under it. The Committee reviews OneNexus's security posture on a regular cycle, and is accountable on an ongoing basis for the confidentiality, integrity and availability of the information assets in scope.

03ISO/IEC 27001:2022 certification

OneNexus is ISO/IEC 27001:2022 certified (certificate IC-IS-2412247), independently verifiable at intercert.com/resources/certification-verification. ISO/IEC 27001 is the international standard for information security management systems: certification means an accredited external auditor has reviewed our security controls, risk assessment process and continual-improvement cycle against the current 2022 revision, rather than us simply asserting them.

Certification isn't a one-time badge. We maintain it through periodic surveillance audits, and the same Information Security Committee that owns this policy owns remediation of anything an audit finds.

04Data protection and encryption

Customer content, including source documents, agent outputs, corrections and signatures, is encrypted in transit and at rest. Access to the underlying infrastructure is limited to personnel who need it to operate the service, and access to production systems is logged.

05Access control and signer authorization

Access inside OneNexus follows the same authorization-level model as signing authority: a user or agent can only reach the systems and content their authorization covers. Administrative access to customer content is restricted on a need-to-know basis and reviewed periodically. Production access is kept separate from the environments engineers use for day-to-day development.

06SignChain integrity and audit logging

SignChain's append-only design is itself a security control. Once a Sign is produced, corrected or signed, that entry cannot be edited or deleted, only superseded by a new one, including by us. Every entry is timestamped and attributable to a specific agent, analyst or signer, so a compromised account is contained to what it can create going forward. It can't rewrite the past.

07Sub-processors and third-party security

We use a limited set of sub-processors to run OneNexus: cloud infrastructure and hosting, one or more AI model providers, and other operational vendors under contract. Each is bound by contract to handle customer content under security terms consistent with this policy, and we review a sub-processor's security posture before onboarding and periodically thereafter. See our Privacy Policy for what each category of sub-processor can access.

The onenexus.ai website has a deliberately small third-party surface, and it is checkable rather than asserted. Fonts, stylesheets, scripts and images are all served from onenexus.ai itself. The site sets no cookies of its own, runs no analytics, and loads no tag manager, advertising pixel or session-recording tool. No page loads any third-party code at all; the enquiry form is screened for automated abuse at the network layer, not by a script in your browser. A Content-Security-Policy is served on every response to enforce this rather than rely on it, restricting where scripts, frames, fonts and connections may come from, and where a form may submit to. Viewing this site leaves no record of your visit with anyone but us and the infrastructure serving it.

08Incident response and notification

We maintain an internal process for identifying, containing and investigating security incidents. Where an incident affects customer content, we'll notify affected account administrators without undue delay once we have enough information to do so, consistent with our contractual and regulatory obligations.

09Employee security and awareness

Access to production systems and customer content is limited to personnel whose role requires it, and is revoked promptly when it no longer does. Personnel with such access complete information security training covering their responsibilities under this policy on a periodic basis.

10Reporting a security concern

If you believe you've found a security vulnerability in OneNexus, or that an account or Sign may be compromised, contact dpo@nexusfrontier.tech. Include what you observed and, where possible, the relevant Sign or SignChain entry ID. SignChain's audit trail makes most issues traceable to a specific action.

11Changes to this policy

We review this policy periodically and update the "Last updated" date above when we make changes. Where a change is material, we'll notify account administrators directly rather than relying on you to check this page.

OneNexus a product of Nexus Frontier Tech

Run it. Check it. Sign it.

Certified ISO/IEC 27001:2022 Certificate IC-IS-2412247 · independently verifiable AIFinTech100 2026
Platform
The Signing Standard Governed AI Orchestration
Signs
Financial Spreads ESG Assessments KYC Files Client Statements
Terms and Policies
Privacy Policy Website Terms of Use Information Security Policy Acceptable Use Policy
© 2026 Nexus Frontier Tech Limited Nexus Signing Standard™ · SignChain™