Secure account access
- Strong password hashing, secure session cookies and scheduled session rotation
- CSRF protection and rate limits on sensitive workflows
- TOTP two-factor authentication for customers and operations personnel
- Role-based access for compliance, finance, support, audit and super administrators
Private document controls
KYC and supplement files are validated, renamed, encrypted with AES-256-GCM and stored in private storage. Access is streamed through authorised routes and recorded in the audit log.
Financial integrity
Invoices, verified payments, recognised revenue and refunds are posted through double-entry journal entries. Linked hashes make unauthorised changes detectable.
Card-data minimisation
Nexana stores only approved masked card metadata. Full card number, CVV and PIN remain in the contracted provider’s secure environment.