Legal

Privacy, Terms & Compliance

Everything about how Nexefy Security handles your data, what you agree to when using our platform, and the standards we hold ourselves to. Last updated August 2026.

Privacy Policy

We collect only what is required to operate Nexefy Security: your account email, the domains and assets you submit for scanning, scan results, and basic product telemetry.

  • Account data — email, display name, and authentication metadata, stored securely and never sold.
  • Scan data — targets you submit, findings we generate, and reports you export. Visible only to you and members you invite.
  • Usage data — aggregated, non-identifying metrics used to improve reliability and performance.

How we use it

To run scans you request, deliver reports, send service notifications, prevent abuse, and improve detection quality. We do not use your scan results to train third-party models or share them with advertisers.

Retention & deletion

Scan results are retained for the lifetime of your account, or until you delete them. Deleting your account removes your personal data and reports within 30 days. You may request an export or deletion at any time via our contact page.

Terms of Service

By creating an account you agree to these terms. If you use Nexefy Security on behalf of an organization, you confirm you are authorized to bind that organization.

Authorized scanning only

You may only scan domains, applications, and infrastructure that you own or have explicit written permission to test. Unauthorized scanning is prohibited and may be illegal. Violations result in immediate account termination.

Acceptable use

  • No reverse engineering, resale, or white-labelling of the platform without a written agreement.
  • No attempts to disrupt, overload, or circumvent rate limits and access controls.
  • No uploading of malware, unlawful content, or third-party data you lack rights to.

Plans & billing

Paid plans renew automatically until cancelled. You can cancel at any time and keep access until the end of the current billing period. Fees already paid are non-refundable except where required by law.

Disclaimer

Security scanning reduces risk but cannot guarantee the absence of vulnerabilities. The service is provided "as is" without warranties, and our liability is limited to the amount you paid in the preceding twelve months.

Compliance

We design Nexefy Security around least-privilege access, encrypted transport and storage, and auditable operations.

  • Encryption — all traffic is served over TLS, and data at rest is encrypted by our infrastructure providers.
  • Access control — row-level security isolates every customer's data; internal access is role-based and logged.
  • Auditability — administrative actions are written to an append-only audit log.
  • Vulnerability reporting — found an issue in our platform? Report it through the contact page and we will respond promptly.

Data processing

We process customer data as a processor acting on your instructions. Sub-processors are used for hosting, database, and email delivery. If you require a data processing agreement, reach out through the contact page.

Questions

For privacy requests, security disclosures, or compliance documentation, contact our team and we will get back to you.