Pricing Documentation API Status Contact Sales Sign In
N NexaLink
Request Demo Get API Keys
Home Company Trust & Security

Security is not a feature.
It is our foundation.

NexaLink processes billions in financial transactions. Our security, compliance, and privacy infrastructure is built to earn the trust of the world's most regulated institutions.

6 Active Certifications
99.97% Uptime SLA
0 Breaches (Lifetime)
5-Day Security Review SLA
1Trust Page Framing
Certifications & Compliance

Compliance at Every Layer

Independently audited, continuously monitored, and maintained by a dedicated security team. Download the latest reports directly.

Certification Status Last Audit Scope Report
SOC 2 Type II
AICPA Trust Services
Active November 2025 All platform services Download
PCI-DSS Level 1
Payment Card Industry
Active September 2025 Payment processing, card data Download
ISO 27001
Information Security Mgmt
Active January 2026 Global operations Download
GDPR
EU Data Protection
Compliant Ongoing EU customer data processing DPA
CCPA / CPRA
California Consumer Privacy
Compliant Ongoing US consumer data Policy
SOX Compliance
Sarbanes-Oxley
Compliant October 2025 Financial controls & reporting Download

Full audit reports are available under NDA. Request access

2Certification Grid
Security Architecture

Defense in Depth

Multiple independent layers of security ensure that a breach of any single layer does not compromise the system.

Client App
mTLS / TLS 1.3
API Gateway
WAF / DDoS / Rate Limit
App Services
Zero Trust / RBAC
Encryption at Rest
AES-256-GCM with customer-managed keys (BYOK). All data encrypted before storage.
Encryption in Transit
TLS 1.3 enforced on all connections. Certificate pinning for financial institution links.
Network Isolation
VPC-isolated microservices, private subnets, no direct internet access for data services.
Key Management
HSM-backed key management via AWS KMS. Automatic rotation every 90 days. FIPS 140-2 Level 3.
Bug Bounty
Via HackerOne
Pen Testing
Quarterly by NCC Group
SAST / DAST
Every CI/CD pipeline
24/7 SOC
Security Operations Center
3Security Architecture
Data Residency & Privacy

Your Data, Your Region

Choose where your data lives. NexaLink supports full data residency requirements with region-locked processing and storage.

🇺🇸
United States
US-EAST-1, US-WEST-2
SOC 2, PCI-DSS, SOX, CCPA compliant data centers
FFIEC-aligned data handling procedures
FedRAMP High authorization (in progress)
AWS GovCloud support available
Primary Region
🇪🇺
European Union
EU-WEST-1 (Ireland), EU-CENTRAL-1 (Frankfurt)
Full GDPR compliance with EU-only processing
Schrems II compliant with supplementary measures
Standard Contractual Clauses (SCCs) included
Data Protection Officer available upon request
Available
🇮🇳
Asia-Pacific
AP-SOUTHEAST-1 (Singapore), AP-SOUTH-1 (Mumbai)
MAS TRM guidelines compliant (Singapore)
RBI data localization (India) supported
APRA CPS 234 aligned (Australia)
Cross-border transfer agreements available
Expanding

Data Handling Principles

Collection & Minimization

We collect only the data necessary to provide services. Customers control exactly which data points are accessed, and we support granular permissioning at the field level.

Processing & Retention

Data is processed in-region unless explicitly configured otherwise. Default retention is 90 days with configurable policies. Automated purging on account closure.

Deletion & Portability

Full data export in standard formats (JSON, CSV). GDPR/CCPA deletion requests processed within 72 hours. Cryptographic erasure for all copies including backups.

Pre-Built Questionnaires

Skip the Back-and-Forth

Download pre-completed security questionnaires in standard formats. Our responses are reviewed and updated quarterly.

SIG Lite

Shared Assessments Standard Information Gathering questionnaire (Lite version). 180+ questions pre-answered.

Updated Q4 2025 XLSX

SIG Full

Complete SIG questionnaire covering all 18 risk domains, 800+ questions with comprehensive responses and evidence.

Updated Q4 2025 XLSX

CAIQ v4

Cloud Security Alliance Consensus Assessment Initiative Questionnaire. Cloud-specific security controls documented.

Updated Q1 2026 XLSX

NexaLink Security Pack

Our comprehensive security whitepaper, architecture overview, and consolidated answers to the 50 most common questions.

Updated Q1 2026 PDF

Have a custom questionnaire? Our security team will complete it within 5 business days.

Submit Custom Questionnaire
4Questionnaire Downloads
Continuous Monitoring

Transparency, Not Just Promises

Real-time visibility into our operational and security posture. Updated continuously, not just at audit time.

NexaLink Security Dashboard
Last updated: 2 minutes ago
All Systems Operational
99.97%
Uptime (Last 365 Days)
SLA Target: 99.95%
0
Security Incidents (12 Mo)
Monthly incident tracker
14d
Since Last Pen Test
0 Critical Findings
Quarterly by NCC Group
4.2min
Mean Time to Detect (MTTD)
Industry avg: 197 days
API Gateway Connect Service Pay Service Verify Service Protect Service
View Full Status Page
5Monitoring Dashboard
Fast-Track Program

5-Day Security Review SLA

We know security reviews are the longest pole in the procurement tent. Our dedicated compliance team guarantees a 5-business-day turnaround on all security assessments.

Dedicated Security Liaison
Named point of contact from our security team assigned to your review from day one.
Live Architecture Review
60-minute deep dive with our infrastructure team covering architecture, data flows, and controls.
Pre-Signed NDA & DPA
Standard legal agreements ready to countersign. No legal back-and-forth required.
Start Security Review

5-Day Review Timeline

1
Day 1: Kick-off & Documentation
Security pack delivered. NDA executed. Custom questionnaire intake (if applicable).
2
Day 2: Architecture Deep Dive
Live call with infrastructure team. Detailed architecture walkthrough and Q&A session.
3
Day 3: Questionnaire Completion
Custom questionnaire responses delivered. Evidence packages compiled.
4
Day 4: Gap Analysis & Remediation
Address follow-up questions. Remediation plan for any identified gaps.
5
Day 5: Final Package & Sign-off
Complete security assessment package. DPA countersigned. Compliance team available for board-level briefing.
6Fast-Track Program

Ready to Start Your Security Review?

Our compliance team is standing by. Get your security pack, schedule an architecture review, or submit your custom questionnaire today.

6 of 6 recommendations

Play Audience Journey

Walk through the site as a specific buyer persona

Enterprise FI Banks & large FIs
SMB Soon
Developer Soon
Partner Soon
Compliance Soon
Goal:
Step 1 of 18