Security
How NEXUS protects partner data and operates the platform.
Our approach
NEXUS Cloud Pte. Ltd. operates a programmatic platform handling significant volumes of bid and delivery data. We maintain technical and organizational measures designed to protect that data against unauthorized access, loss, and alteration, and we contract for those measures with every partner.
Data protection
- Data is encrypted in transit and at rest.
- Partner data is logically separated, and data provided under one Schedule is not used to deliver services under another without prior written consent.
- Clean room collaborations operate on common identifiers only, without exposing underlying records to either party.
- Partners retain ownership of their own data at all times.
Access control
Access to production systems and partner data is granted on a least-privilege basis, is tied to named individuals, and is reviewed periodically. Administrative access requires multi-factor authentication. Access is revoked promptly when a role changes or ends.
Incident response
We maintain an incident response process covering detection, containment, investigation, and notification. Where we confirm or reasonably suspect unauthorized access to, or acquisition, disclosure, or loss of partner data, we notify the affected party in writing within seventy-two (72) hours of becoming aware, with reasonable detail of the nature and scope of the incident, the categories of data affected, and the measures taken or proposed. We cooperate with the affected party and with any applicable regulatory authority through investigation and resolution.
Platform integrity
We monitor supply continuously for invalid traffic, domain spoofing, and misdeclared inventory, and we screen demand-side creative for malware and policy breaches. Standards we enforce are set out in the Advertising Policy and Publisher Policy.
Compliance
We comply with applicable data protection regulation including the GDPR, CCPA, CPRA, LGPD, and PIPL, and enter into a Data Processing Addendum where required. We support the IAB Transparency and Consent Framework. We screen partners against sanctions regimes including OFAC SDN and EU resolutions, and we require compliance with applicable anti-bribery law including the Singapore Prevention of Corruption Act, the U.S. Foreign Corrupt Practices Act, and the UK Bribery Act 2010.
Reporting a vulnerability
If you believe you have found a security vulnerability in the NEXUS platform, report it to [email protected]. Please include enough detail to reproduce the issue, and give us reasonable opportunity to remediate before any public disclosure. We do not pursue legal action against researchers who report in good faith and act within these terms.