Back to Home

Security Policy

Nelix's commitment to security and data protection

Effective: January 1, 2025
Last Updated: January 27, 2025

Security Policy

Last Updated: January 27, 2025

Our Security Commitment

At Nelix, security is not just a feature—it's the foundation of everything we do. We are committed to protecting your data and documents with industry-leading security measures and practices.

Security Architecture

Infrastructure Security

Cloud Infrastructure

  • Multi-Region Deployment: Services deployed across multiple AWS regions for redundancy
  • Virtual Private Cloud (VPC): Isolated network environment with strict access controls
  • Web Application Firewall (WAF): Protection against common web exploits
  • DDoS Protection: AWS Shield Standard and Advanced for mitigation

Container Security

  • Isolated Execution: Each document analysis runs in an isolated container
  • Immutable Infrastructure: Containers are read-only and disposed after use
  • Regular Updates: Automated security patches and updates
  • Runtime Protection: Container runtime security monitoring

Data Security

Encryption

  • In Transit: TLS 1.3 for all data transmission
  • At Rest: AES-256 encryption for stored data
  • Key Management: AWS KMS with automatic key rotation
  • Certificate Management: Automated certificate renewal and management

Document Handling

  • Temporary Processing: Documents exist only during analysis
  • Automatic Deletion: Immediate removal after processing
  • No Persistent Storage: Documents never stored permanently
  • Memory Clearing: Secure memory wiping after processing

Application Security

Authentication & Authorization

  • Multi-Factor Authentication (MFA): Available for all accounts
  • Single Sign-On (SSO): SAML 2.0 support for enterprise
  • Role-Based Access Control (RBAC): Granular permission management
  • Session Management: Secure session handling with automatic timeout

API Security

  • Rate Limiting: Protection against abuse and DoS attacks
  • API Key Management: Secure generation and rotation
  • Request Validation: Input sanitization and validation
  • OAuth 2.0: Industry-standard authorization framework

Security Practices

Development Security

Secure Development Lifecycle

  • Code Reviews: Mandatory peer review for all code changes
  • Static Analysis: Automated security scanning in CI/CD pipeline
  • Dependency Scanning: Regular vulnerability scanning of dependencies
  • Security Testing: Integration of security tests in development

Version Control

  • Signed Commits: GPG signing for code authenticity
  • Branch Protection: Protected main branches with required reviews
  • Access Control: Principle of least privilege for repository access

Operational Security

Monitoring & Logging

  • Continuous automated monitoring: Automated security monitoring
  • Centralized Logging: Aggregated logs for security analysis
  • Anomaly Detection: AI-powered signal detection
  • Incident Alerting: Real-time security alerts

Incident Response

  • Response Process: A defined incident response process with named owners
  • Incident Playbooks: Documented response procedures
  • Communication Plan: Clear escalation and notification processes
  • Post-Incident Review: Lessons learned and improvements

Compliance & Auditing

Compliance Standards

  • GDPR: Designed to support EU data protection requirements
  • CCPA: Designed to support California Consumer Privacy Act requirements

Security Features for Users

Account Security

Passwords

  • Passwords are validated at sign-up; we recommend a long, unique passphrase and a password manager

Account Protection

  • Recovery Options: Secure account recovery process

Data Protection

Privacy Controls

  • Data Minimization: We collect only necessary information
  • Deletion: Scan and account deletion requests are handled through security@nelix.ai
  • Access: You can request a copy of your personal data through security@nelix.ai

Monitoring

  • Service monitoring: Errors and failures in the analysis pipeline are logged and alarmed

Vulnerability Disclosure Program

We welcome security researchers to help us maintain the highest security standards.

Responsible Disclosure

  • Report Security Issues: security@nelix.ai
  • Bug Bounty Program: Coming soon

Scope

  • Nelix web application
  • API endpoints
  • Infrastructure components
  • Mobile applications (when available)

Out of Scope

  • Social engineering attacks
  • Physical attacks
  • Attacks on users
  • Denial of Service attacks

Security Updates

Patch Management

  • Security patches and dependency updates are applied promptly after review.
  • System Updates: Maintenance windows announced in advance

Communication

  • Email Notifications: Direct notification for critical issues

Best Practices for Users

Recommended Security Measures

  1. Enable MFA: Always use multi-factor authentication
  2. Strong Passwords: Use unique, complex passwords
  3. Regular Reviews: Periodically review account access
  4. API Key Rotation: Regularly rotate API keys
  5. Least Privilege: Grant minimum necessary permissions

Security Hygiene

  • Keep your browser and OS updated
  • Use secure networks for access
  • Log out when finished
  • Report suspicious activities immediately

Third-Party Security

Service Providers

The providers that process data on our behalf are listed, with their purpose and location, in our GDPR page. Each provides data-processing terms as part of its standard service agreement.

  • Supabase: authentication and database
  • AWS: document storage and analysis (eu-west-2)
  • Cloudflare: web hosting
  • Paddle: payment processing (Merchant of Record)
  • Sentry: error monitoring
  • Google Analytics: web analytics

Contact Security Team

For security concerns, questions, or to report vulnerabilities:

Security Team Email: security@nelix.ai

Office Hours Support

Monday - Friday: 9 AM - 6 PM EST
24/7 for critical security incidents

Security Roadmap

  • Aligning with the AWS Well-Architected Framework
  • Working toward CSA STAR Level 1

This Security Policy is reviewed and updated periodically. For questions or concerns about our security practices, please contact our security team.