Security Policy
Nelix's commitment to security and data protection
Security Policy
Last Updated: January 27, 2025
Our Security Commitment
At Nelix, security is not just a feature—it's the foundation of everything we do. We are committed to protecting your data and documents with industry-leading security measures and practices.
Security Architecture
Infrastructure Security
Cloud Infrastructure
- Multi-Region Deployment: Services deployed across multiple AWS regions for redundancy
- Virtual Private Cloud (VPC): Isolated network environment with strict access controls
- Web Application Firewall (WAF): Protection against common web exploits
- DDoS Protection: AWS Shield Standard and Advanced for mitigation
Container Security
- Isolated Execution: Each document analysis runs in an isolated container
- Immutable Infrastructure: Containers are read-only and disposed after use
- Regular Updates: Automated security patches and updates
- Runtime Protection: Container runtime security monitoring
Data Security
Encryption
- In Transit: TLS 1.3 for all data transmission
- At Rest: AES-256 encryption for stored data
- Key Management: AWS KMS with automatic key rotation
- Certificate Management: Automated certificate renewal and management
Document Handling
- Temporary Processing: Documents exist only during analysis
- Automatic Deletion: Immediate removal after processing
- No Persistent Storage: Documents never stored permanently
- Memory Clearing: Secure memory wiping after processing
Application Security
Authentication & Authorization
- Multi-Factor Authentication (MFA): Available for all accounts
- Single Sign-On (SSO): SAML 2.0 support for enterprise
- Role-Based Access Control (RBAC): Granular permission management
- Session Management: Secure session handling with automatic timeout
API Security
- Rate Limiting: Protection against abuse and DoS attacks
- API Key Management: Secure generation and rotation
- Request Validation: Input sanitization and validation
- OAuth 2.0: Industry-standard authorization framework
Security Practices
Development Security
Secure Development Lifecycle
- Code Reviews: Mandatory peer review for all code changes
- Static Analysis: Automated security scanning in CI/CD pipeline
- Dependency Scanning: Regular vulnerability scanning of dependencies
- Security Testing: Integration of security tests in development
Version Control
- Signed Commits: GPG signing for code authenticity
- Branch Protection: Protected main branches with required reviews
- Access Control: Principle of least privilege for repository access
Operational Security
Monitoring & Logging
- Continuous automated monitoring: Automated security monitoring
- Centralized Logging: Aggregated logs for security analysis
- Anomaly Detection: AI-powered signal detection
- Incident Alerting: Real-time security alerts
Incident Response
- Response Process: A defined incident response process with named owners
- Incident Playbooks: Documented response procedures
- Communication Plan: Clear escalation and notification processes
- Post-Incident Review: Lessons learned and improvements
Compliance & Auditing
Compliance Standards
- GDPR: Designed to support EU data protection requirements
- CCPA: Designed to support California Consumer Privacy Act requirements
Security Features for Users
Account Security
Passwords
- Passwords are validated at sign-up; we recommend a long, unique passphrase and a password manager
Account Protection
- Recovery Options: Secure account recovery process
Data Protection
Privacy Controls
- Data Minimization: We collect only necessary information
- Deletion: Scan and account deletion requests are handled through security@nelix.ai
- Access: You can request a copy of your personal data through security@nelix.ai
Monitoring
- Service monitoring: Errors and failures in the analysis pipeline are logged and alarmed
Vulnerability Disclosure Program
We welcome security researchers to help us maintain the highest security standards.
Responsible Disclosure
- Report Security Issues: security@nelix.ai
- Bug Bounty Program: Coming soon
Scope
- Nelix web application
- API endpoints
- Infrastructure components
- Mobile applications (when available)
Out of Scope
- Social engineering attacks
- Physical attacks
- Attacks on users
- Denial of Service attacks
Security Updates
Patch Management
- Security patches and dependency updates are applied promptly after review.
- System Updates: Maintenance windows announced in advance
Communication
- Email Notifications: Direct notification for critical issues
Best Practices for Users
Recommended Security Measures
- Enable MFA: Always use multi-factor authentication
- Strong Passwords: Use unique, complex passwords
- Regular Reviews: Periodically review account access
- API Key Rotation: Regularly rotate API keys
- Least Privilege: Grant minimum necessary permissions
Security Hygiene
- Keep your browser and OS updated
- Use secure networks for access
- Log out when finished
- Report suspicious activities immediately
Third-Party Security
Service Providers
The providers that process data on our behalf are listed, with their purpose and location, in our GDPR page. Each provides data-processing terms as part of its standard service agreement.
- Supabase: authentication and database
- AWS: document storage and analysis (eu-west-2)
- Cloudflare: web hosting
- Paddle: payment processing (Merchant of Record)
- Sentry: error monitoring
- Google Analytics: web analytics
Contact Security Team
For security concerns, questions, or to report vulnerabilities:
Security Team Email: security@nelix.ai
Office Hours Support
Monday - Friday: 9 AM - 6 PM EST
24/7 for critical security incidents
Security Roadmap
- Aligning with the AWS Well-Architected Framework
- Working toward CSA STAR Level 1
This Security Policy is reviewed and updated periodically. For questions or concerns about our security practices, please contact our security team.