Trust

Security

How NEXUS protects partner data and operates the platform.

Version 2.1  ·  Effective 28 April 2026

Our approach

NEXUS Cloud Pte. Ltd. operates a programmatic platform handling significant volumes of bid and delivery data. We maintain technical and organizational measures designed to protect that data against unauthorized access, loss, and alteration, and we contract for those measures with every partner.

Data protection

  • Data is encrypted in transit and at rest.
  • Partner data is logically separated, and data provided under one Schedule is not used to deliver services under another without prior written consent.
  • Clean room collaborations operate on common identifiers only, without exposing underlying records to either party.
  • Partners retain ownership of their own data at all times.

Access control

Access to production systems and partner data is granted on a least-privilege basis, is tied to named individuals, and is reviewed periodically. Administrative access requires multi-factor authentication. Access is revoked promptly when a role changes or ends.

Incident response

We maintain an incident response process covering detection, containment, investigation, and notification. Where we confirm or reasonably suspect unauthorized access to, or acquisition, disclosure, or loss of partner data, we notify the affected party in writing within seventy-two (72) hours of becoming aware, with reasonable detail of the nature and scope of the incident, the categories of data affected, and the measures taken or proposed. We cooperate with the affected party and with any applicable regulatory authority through investigation and resolution.

Platform integrity

We monitor supply continuously for invalid traffic, domain spoofing, and misdeclared inventory, and we screen demand-side creative for malware and policy breaches. Standards we enforce are set out in the Advertising Policy and Publisher Policy.

Compliance

We comply with applicable data protection regulation including the GDPR, CCPA, CPRA, LGPD, and PIPL, and enter into a Data Processing Addendum where required. We support the IAB Transparency and Consent Framework. We screen partners against sanctions regimes including OFAC SDN and EU resolutions, and we require compliance with applicable anti-bribery law including the Singapore Prevention of Corruption Act, the U.S. Foreign Corrupt Practices Act, and the UK Bribery Act 2010.

Reporting a vulnerability

If you believe you have found a security vulnerability in the NEXUS platform, report it to [email protected]. Please include enough detail to reproduce the issue, and give us reasonable opportunity to remediate before any public disclosure. We do not pursue legal action against researchers who report in good faith and act within these terms.