Security
Last updated: 12 August 2026
This statement describes the technical and organisational measures NexusEdge ResilienceLab ("NexusEdge") applies to protect the Platform and the data processed through it. It is provided for transparency and does not constitute a contractual warranty beyond what is set out in a signed agreement with your organisation.
1. Regulatory alignment
Our security controls are designed with reference to:
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), which requires appropriate technical and organisational measures to protect personal data;
- Federal Decree-Law No. 34 of 2021 on the Fight Against Rumours and Cybercrimes;
- guidance from the UAE Cybersecurity Council and the Telecommunications and Digital Government Regulatory Authority (TDRA); and
- recognised international frameworks, including ISO/IEC 27001 controls and the NIST Cybersecurity Framework, as a baseline for good practice.
Reference to a framework indicates alignment with its control objectives; it does not, by itself, represent a formal certification unless explicitly stated in a signed agreement.
2. Hosting and infrastructure
- The Platform is hosted on managed cloud infrastructure that provides physical and environmental security for the underlying data centres.
- Production data is encrypted in transit using TLS and at rest using industry-standard encryption algorithms.
- Each client organisation is provisioned as a logically isolated tenancy, and access between tenancies is restricted through row-level controls enforced at the application layer.
3. Access controls
- Access to production systems is granted on a least-privilege basis and reviewed periodically.
- Administrative access requires multi-factor authentication and is logged for audit purposes.
- Support access to a client tenancy is time-bound and requires explicit authorisation by an administrator of that tenancy.
4. Authentication
- User accounts authenticate using email and password, with optional single sign-on where configured for an organisation.
- Passwords are stored using one-way salted hashing. We cannot view your password in plaintext.
- Session tokens are issued with a limited lifetime and rotated on authentication events.
5. Data protection
- Personal data is processed in line with the principles set out in our Privacy Policy and the UAE PDPL.
- Backups are encrypted and access-restricted; retention periods align with the periods stated in our Privacy Policy.
- Where data is transferred outside the UAE, we rely on a lawful basis under Article 22 of the UAE PDPL and apply safeguards such as standard contractual clauses.
6. Monitoring and logging
- Security-relevant events, including authentication, administrative actions, and changes to tenant configuration, are logged.
- Logs are retained for a period consistent with operational need and legal obligation, and are access-controlled.
- We do not use logs to build profiles of individual user behaviour for advertising.
7. Vulnerability management
- We monitor dependency and infrastructure advisories and apply security updates on a risk-prioritised basis.
- Changes to the Platform follow a controlled release process with review and testing before deployment to production.
- We do not run a public bug bounty programme. Suspected vulnerabilities may be reported to operations@nexusedge.info.
8. Incident response
We maintain an incident response process designed to detect, contain, investigate, and remediate security incidents. Where an incident is reasonably likely to result in a risk to the rights and freedoms of data subjects, we will assess our notification obligations under the UAE PDPL and, where required, notify the UAE Data Office and affected individuals without undue delay.
9. Sub-processors
We engage sub-processors to host and operate specific components of the Platform. Sub-processors are engaged under written agreements that require equivalent technical and organisational measures. A list of sub-processors can be provided to clients under the terms of their agreement.
10. Business continuity
We maintain backup and recovery procedures intended to support continuity of the Platform. Recovery objectives are defined per system and tested periodically. However, no system can be guaranteed to be fully available at all times; we recommend that clients maintain their own continuity plans for critical operations.
11. What we do not claim
- We do not claim that the Platform is immune to all security incidents; no system can make that guarantee.
- We do not claim formal certifications unless they have been issued and are referenced in your signed agreement.
- We do not claim that data is stored exclusively within the UAE unless your agreement explicitly provides for local data residency.
12. Contact
For security questions or to report a suspected vulnerability, contact operations@nexusedge.info or +971 507065691.