Vendor due diligence
Everything you need to review us as a service provider.
You hold your vendors to a standard. Hold us to the same one. This page answers the questions a compliance team, CCO, or examiner asks before a firm puts records into a third-party system — including the answers that are still “not yet.”
Section 01
Company and operating profile
- Who is the legal contracting entity?
- ThirdNexa LLC, a United States limited liability company operating the ThirdNexa service. ThirdNexa LLC is the sole operator identity for the platform and the counterparty on all customer agreements.
- What does the service do?
- ThirdNexa is a multi-tenant software service for third-party (vendor) oversight at SEC- and FINRA-regulated firms: vendor inventory, due diligence questionnaires, periodic reviews, findings, contract tracking, decision records, and exam evidence packs.
- How long has the service been operating, and what is its maturity?
- ThirdNexa is an early-stage service currently operating a limited founding beta with a small number of firms. We state this plainly so reviewers can weight concentration and key-person risk appropriately.
- Who leads the company?
- The founder has spent nearly two decades building compliance technology for investment advisers and broker-dealers. Day-to-day engineering and support are led by the founder, with named support contacts published below.
- Who do we contact for security, privacy, or contract questions?
- Security and diligence questions: support@thirdnexa.com. Commercial and contract questions: sales@thirdnexa.com. We aim to respond to written diligence requests within two business days.
- Will you complete our own questionnaire?
- Yes. Send your CAIQ, SIG-Lite, internal vendor questionnaire, or exam-driven request and we will complete it in your format, clearly separating controls in place today from planned work.
Section 02
Hosting and architecture
- Where and how is the service hosted?
- ThirdNexa runs entirely on managed cloud infrastructure in the United States. Application traffic is served from a managed edge runtime, and customer data is stored in a managed PostgreSQL database with automated backups. ThirdNexa operates no physical servers and no office-based infrastructure.
- Is the platform multi-tenant?
- Yes. Firms share application infrastructure and a logical database, with per-firm access rules enforced in the database layer rather than by page visibility alone.
- Can customers select a hosting region or data residency?
- No. All data is hosted in a single United States region today. Customer-selectable residency is a roadmap item and is not offered.
- How are changes released?
- Changes are version-controlled, built through an automated pipeline, and released continuously. A regression test suite covering role permissions and cross-firm data isolation runs against the application, and results are retained for internal review.
Section 03
Information security controls
- Is data encrypted?
- Yes. Data is encrypted in transit using current TLS and encrypted at rest by the managed database and storage layers, including backups. This covers vendor records, contracts, questionnaire responses, findings, and uploaded evidence files.
- How do users authenticate?
- Email and password authentication with mandatory authenticator-app multi-factor authentication. There are no shared or generic logins, and anonymous sign-up into an existing firm is not possible.
- Do you support SAML single sign-on?
- Not today. Enterprise single sign-on is a roadmap item. We do not advertise it as an available capability.
- How is access to firm data restricted inside a firm?
- Role-based permissions: Firm Admin, Compliance Officer, Reviewer, and Auditor/Read-Only. Sensitive actions are restricted by role and enforced on the server — for example, accepting risk on a finding is limited to firm administrators, and a finding cannot be verified by the person assigned to remediate it.
- How is one firm's data separated from another's?
- Row-level security policies in the database scope every read and write to the workspaces a user is authorized to access. Consultancies that oversee multiple client firms are bound by the same policies per client firm.
- Who at ThirdNexa can access customer data?
- Access is limited to a small number of authorized personnel on a least-privilege basis, for support, incident response, and operating the service. Staff support access is a distinct, recorded capability rather than an unrestricted back door.
- Have you completed a SOC 2 audit or independent penetration test?
- No. A SOC 2 readiness program and an independent penetration test are planned and tracked internally with staged milestones. We do not claim a SOC 2 report, and we will not advertise one until the work is complete and the report is available to share under NDA.
- How would you handle a security incident?
- We investigate, contain, and notify affected firms in writing with the facts known at the time, then follow up with findings and remediation. We design for Regulation S-P incident-response expectations, including supporting the customer's own notification obligations with the records they need.
Section 04
Subprocessors
The service organizations below may process customer data on ThirdNexa's behalf. We publish this register so your vendor file can reflect the full chain, and we will notify customers of material changes.
- Cloud application and database platform (United States)
- Hosts the application runtime, managed PostgreSQL database, authentication, file storage, and backups. This is where customer vendor oversight records reside.
- Edge network and content delivery
- Serves application traffic, terminates TLS, and provides network-level protection. Processes request metadata in transit.
- AI inference gateway
- Used for assisted spreadsheet import interpretation and in-product help answers. Requests run through zero-data-retention endpoints; content is not used for model training.
- Transactional email delivery
- Sends reminders, invitations, alerts, and notifications. Processes recipient name, email address, and message content.
- Payment processing
- Handles subscription payments. Card details are entered directly with the payment processor; ThirdNexa never receives or stores card numbers.
Section 05
AI data governance
- Is customer data used to train AI models?
- No. Customer content is not used to train or fine-tune any model serving ThirdNexa.
- Do AI providers retain our prompts?
- AI requests are routed through zero-data-retention endpoints with provider-side storage disabled.
- What does ThirdNexa itself retain about AI use?
- We retain our own activity records of AI use for auditability, support, and responsible operation. Provider zero retention is not the same as ThirdNexa keeping no record.
- Does AI make compliance decisions?
- No. AI assists with reading messy files and answering product questions. ThirdNexa never labels a vendor approved or compliant and never issues regulatory or legal conclusions — the firm records every decision, with its own rationale.
Section 06
Record-keeping and audit trail
- Are oversight decisions auditable?
- Yes. Approvals, risk-tier changes, exceptions, and finding closures are written to an append-only decision log that records the actor, the timestamp, and a written rationale. Entries cannot be edited or deleted through the application.
- Is finding remediation history preserved?
- Yes. Finding updates are append-only, and verification must be performed by a reviewer or administrator who is not the assignee.
- What regulatory expectations does the design support?
- The service is built around SEC Regulation S-P safeguards and incident-response expectations, adviser compliance-program review obligations, FINRA supervisory expectations for outsourced activities, and electronic books-and-records retention. ThirdNexa supplies the recording and evidence tools; the firm remains responsible for its own compliance determinations.
- Can we produce evidence for an examination?
- Yes. Firms can generate scoped oversight reports and an exam evidence pack covering vendor inventory, due diligence, reviews, findings, and decision rationale.
Section 07
Business continuity and resilience
- How is data backed up?
- The managed database platform performs automated backups with point-in-time recovery. Backups are encrypted.
- What are your recovery objectives?
- Our internal targets are recovery of service within four hours and data loss of no more than one hour in a platform-level failure. These are operating targets, not contractual guarantees, and they have not been validated by a third-party audit.
- What happens if ThirdNexa ceases operations?
- Customers can export their full records at any time without contacting us, so a firm's oversight file remains usable independently of the service. We will give written notice and a defined export window in any wind-down.
Section 08
Data ownership, portability, and exit
- Who owns the data?
- The customer. Vendor records, questionnaire responses, contracts, uploaded documents, notes, and decision history remain the firm's property.
- How do we get our data out?
- Self-service export from inside the application: spreadsheet exports of records and activity, plus generated PDF reports and exam evidence packs. No fee, no request ticket.
- What happens to data after termination?
- On written request following termination we delete customer data from the live service, and it ages out of encrypted backups on the platform's backup retention cycle. Export your records before requesting deletion.
- Is the service ever placed in a read-only state?
- Yes. When a subscription lapses, the workspace becomes view-and-export only rather than being deleted, so a firm never loses access to its oversight history because of a billing event.
Planned, not available today
What we are still working on.
- SOC 2 readiness program and Type I, then Type II report
- Independent third-party penetration test with a shareable summary
- Data processing agreement and published subprocessor change notifications
- Enterprise single sign-on (SAML)
- Customer-selectable data residency
Our public language changes only when the corresponding work is complete and documented. If an item above is a gating requirement for your firm, tell us — we will be direct about timing instead of implying coverage we do not have.
ThirdNexa is a software platform provided by ThirdNexa LLC. ThirdNexa does not provide legal, regulatory, or compliance advice, and use of the platform does not guarantee compliance with any law or regulation or any particular examination outcome. Each firm remains solely responsible for establishing and maintaining policies, procedures, supervision, controls, and oversight appropriate to its regulatory obligations. ThirdNexa LLC is not affiliated with or endorsed by the SEC, FINRA, or any other regulatory authority.
Send us your questionnaire.
We complete it in your format and separate current controls from planned work. Security controls are also summarized on our security page.
