Security & data governance

Built for compliance, engineered for trust.

Financial-services firms need more than a reassuring badge. ThirdNexa uses concrete access, isolation, encryption, and accountability controls to protect the records behind vendor oversight.

Control ledger

The safeguards operating today.

These statements describe current ThirdNexa controls. They are intentionally specific and do not imply an audit, certification, or customer-selectable hosting region.

01 / Data protection

Protected in storage and transit

ThirdNexa encrypts data in transit and at rest, helping protect vendor records, contracts, reviews, findings, and uploaded evidence throughout the platform.

Encryption is part of the platform baseline.

02 / Access control

A second factor for every account

Authenticator-app multi-factor authentication is mandatory. Role-based permissions and least-privilege internal access limit who can reach firm records and what they can do.

MFA is required on every plan.

03 / Tenant boundaries

Firm separation enforced with the data

Per-firm access rules are enforced at the database layer, not left to page visibility alone. Users see records only for workspaces they are authorized to access.

Consultancy access follows the same firm boundaries.

04 / Accountability

Decisions retain their context

ThirdNexa preserves actor and time information across important oversight activity. Recorded decisions and finding updates keep the rationale and history available for later review.

The firm remains the decision-maker.

AI data governance

Useful assistance without turning firm data into training material.

Zero-retention model processing

AI inputs are processed through zero-data-retention endpoints with storage disabled. Customer content is not used to train the models serving ThirdNexa.

ThirdNexa keeps an accountability record

Zero retention by the model provider is distinct from ThirdNexa's own records. We retain AI activity information needed for auditability, support, and responsible operation of the service.

Assurance roadmap

Clear about what comes next.

ThirdNexa is building toward a formal SOC 2 program, an independent penetration test, a customer diligence package, and enterprise identity capabilities. Those items are roadmap commitments—not certifications or controls we claim to offer today.

We do not currently advertise a SOC 2 report, SAML single sign-on, or customer-selectable data residency. Our public language will change only when the corresponding work is complete and documented.

Bring us your security questionnaire.

We’ll answer directly and distinguish current controls from planned work. Our full vendor due diligence package is already published.