Security

Designed for sensitive partner and financial operations

Nexora combines tenant-aware controls, scoped access and immutable operational evidence. No certification is claimed without external verification.

Tenant boundaries

Tenant context is propagated through the SaaS control plane, RLS policies, caches, workers and audit events. Legacy engine migration remains explicitly tracked until complete.

Identity

MFA step-up, session rotation, revocation, login evidence and planned passkey support protect privileged operations.

Authorization

RBAC, scoped permissions, explicit backend checks and controlled support sessions limit access.

Secrets and webhooks

Hashed API keys, encrypted secrets, signed webhooks and destination validation reduce credential and SSRF risk.

Financial controls

State machines, idempotency, immutable ledger evidence and payout ambiguity protection preserve financial invariants.

Privacy controls

Export, retention, pseudonymization, deletion scheduling and legal hold workflows are designed for tenant governance.