Security by design

Security and privacy

Nexana applies access controls, encryption, audit logging and document retention rules to protect application data.

Secure account access

  • Strong password hashing, secure session cookies and scheduled session rotation
  • CSRF protection and rate limits on sensitive workflows
  • TOTP two-factor authentication for customers and operations personnel
  • Role-based access for compliance, finance, support, audit and super administrators

Private document controls

KYC and supplement files are validated, renamed, encrypted with AES-256-GCM and stored in private storage. Access is streamed through authorised routes and recorded in the audit log.

Financial integrity

Invoices, verified payments, recognised revenue and refunds are posted through double-entry journal entries. Linked hashes make unauthorised changes detectable.

Card-data minimisation

Nexana stores only approved masked card metadata. Full card number, CVV and PIN remain in the contracted provider’s secure environment.