Trust Center

One graph. Six core relationship modules. Provenance on every write. Agents that act with permission. Here is exactly how NEXUS earns those claims.

Data ownership

You own your workspace data. Export it anytime from Settings in portable, machine-readable formats. Delete it from active systems from Settings — some audit, billing, and legal records may be retained as required by law and security obligations.

We do not sell your personal information, and we do not use your workspace data to train machine learning models or for advertising purposes.

Provenance

Every write records who or what changed it, where it came from, when it changed, and how confident NEXUS is. Fields are classified as human-entered, agent-inferred, API-synced, imported, or derived.

Derived values (lead scores, attribution, vesting) are recomputable — never opaque. Modeled numbers are always labeled with their confidence; NEXUS never presents modeled attribution as deterministic.

Agent safety

Agent actions are scoped by token permissions and risk class. Reads run automatically within scope. Writes are scope-checked and logged. Financial actions (spending money, equity grants, billing) and bulk outreach always require human approval before executing.

Agents authenticate with scoped tokens that grant only the permissions you choose. All 39 MCP tools are guarded by the scoped-token authorizer, every action is written to the audit log, and tokens can be revoked instantly from API Keys.

Security

Encryption in transit (TLS) and at rest (AES-256). Logical tenant isolation with row-level security — each workspace's data is accessible only to authenticated members of that workspace.

SOC 2-aligned controls: append-only audit logging with actor, source, timestamp, and change history; access controls; approval gates on high-risk operations. We will publish audit reports here when formal certification completes.

AI and visual analysis providers

If you enable Visual Testing or agent-powered analysis, screenshots, prompts, metadata, or selected workspace content may be sent to configured AI providers (such as OpenAI, Anthropic, or Google) for processing. We use these providers only to deliver the requested feature — never to train NEXUS models.

Visual-testing screenshots may contain sensitive workspace data. Review provider settings before enabling scheduled runs.

Retention and deletion

Account information and workspace data are retained while your account is active. If you delete your account, personal information and workspace data are removed within 30 days, except where retention is required by law (for example, billing records).

After plan downgrades or account termination, your data is exportable for 30 days. Nothing is silently deleted.

Subprocessors

Stripe (payments and billing) · Google (OAuth authentication) · Amazon Web Services (infrastructure and encrypted storage) · Analytics providers (anonymized usage data) · AI/VLM providers (only when you enable Visual Testing or agent analysis features).

Questions?

Read the full Privacy Policy and Terms of Service, or contact us at RMonaghanVentureStudios@rmvs.org. Enterprise security reviews, SLAs, and custom data-retention terms are available under a separate written agreement.

← Back to home
© 2026 NEXUS · Relationship Intelligence Platform