How we protect your data, and how to report issues
If you believe you’ve found a security vulnerability, please report it privately to [email protected] — do not open a public issue. Include a description, steps to reproduce, the affected component, and the impact. We acknowledge reports within 2 business days and provide a remediation timeline after triage. Please allow us reasonable time to fix issues before public disclosure.
Passwords are hashed with bcrypt; multi-factor authentication (TOTP) is available and can be required org-wide. Data is encrypted with AES-256-GCM at rest and TLS 1.3 in transit. We enforce strict security headers (CSP, HSTS), per-tenant isolation with automated regression tests, SSRF and archive-extraction hardening, and dependency/secret/SAST scanning in CI.
AI features are processed by our AI sub-processor (Anthropic). For analytics, only aggregated statistics are sent — never your raw dataset rows. Anthropic does not use API submissions to train its models. You can opt out of AI features in account settings.
We maintain a documented incident-response process and notify affected users and regulators of any personal-data breach within the timelines required by applicable law (e.g., GDPR’s 72 hours).
In scope: the Nexmetry application (API + web app), authentication, multi-tenant isolation, file handling, and data export/erasure. Out of scope: issues requiring a compromised host/account, social engineering, volumetric DoS, and third-party sub-processors (report those to the vendor).
Security contact: [email protected]