How we protect your assets — and how to report a vulnerability responsibly. Found something? We want to hear from you.
Reach us at security@nexports.in. We follow coordinated disclosure and appreciate a reasonable window to fix issues before they’re made public.
All traffic between the plugin, portals and our backend uses HTTPS/TLS.
Assets and metadata are stored encrypted at rest (Cloudflare R2 object storage and a managed Postgres database).
Asset uploads use short-lived, single-purpose signed URLs. Backend credentials are server-side only and never shipped inside the plugin.
Free portals expire and are permanently deleted (24 hours; signed-in free portals lock at expiry and are purged 30 days later). We keep only what a portal needs to work.
Sign-in is email magic-link — we never store passwords. Payment card data is handled by our payment provider, not by us.
The plugin ships no third-party analytics or advertising trackers.
Nexports is an independently built product and is not currently accredited to formal standards such as SOC 2, ISO 27001, PCI DSS, HITRUST or SSAE 18. We follow the security practices above and keep the data we hold to a minimum. If your organisation has specific compliance requirements, email security@nexports.in and we’ll do our best to help.