Security

Your work, handled with care.

How we protect your assets — and how to report a vulnerability responsibly. Found something? We want to hear from you.

Report a vulnerability

Reach us at security@nexports.in. We follow coordinated disclosure and appreciate a reasonable window to fix issues before they’re made public.

  1. 1
    Report privately
    Email security@nexports.in with steps to reproduce, impact, and any proof-of-concept. Please don’t open a public issue.
  2. 2
    We acknowledge
    We aim to acknowledge your report within 2 business days and will keep you updated as we investigate.
  3. 3
    We remediate
    We triage by severity and aim to fix critical issues within 7 days. We’ll let you know when it’s resolved.
  4. 4
    We credit you
    With your permission, we’re happy to credit you once a fix ships. We don’t run a paid bug-bounty at this stage.

How we protect your data

Encrypted in transit

All traffic between the plugin, portals and our backend uses HTTPS/TLS.

Encrypted at rest

Assets and metadata are stored encrypted at rest (Cloudflare R2 object storage and a managed Postgres database).

Scoped, short-lived access

Asset uploads use short-lived, single-purpose signed URLs. Backend credentials are server-side only and never shipped inside the plugin.

Minimal retention

Free portals expire and are permanently deleted (24 hours; signed-in free portals lock at expiry and are purged 30 days later). We keep only what a portal needs to work.

Passwordless auth

Sign-in is email magic-link — we never store passwords. Payment card data is handled by our payment provider, not by us.

No trackers

The plugin ships no third-party analytics or advertising trackers.

Certifications

Nexports is an independently built product and is not currently accredited to formal standards such as SOC 2, ISO 27001, PCI DSS, HITRUST or SSAE 18. We follow the security practices above and keep the data we hold to a minimum. If your organisation has specific compliance requirements, email security@nexports.in and we’ll do our best to help.