Security controls described without compliance theater.
Nexodo documents the controls operating today, the boundaries that remain, and the claims we do not make. That gives product and security teams a concrete starting point for evaluation.
Identity
Verified Google authentication and HTTP-only app sessions.
Isolation
Organization ownership and server-side roles.
Recovery
Nightly integrity checks and AES-256-GCM encrypted backups.
Authentication
Verified identity with application-level authorization.
Supabase brokers Google authentication. Nexodo verifies token signature, issuer, audience, expiration, and email before creating a signed HTTP-only application session.
Invitations expire and must match the intended email address. Roles are enforced on the server for owners, editors, and viewers rather than relying on hidden interface controls.
Tenant isolation
Organization ownership is part of each data operation.
Products, attributes, imports, assets, integrations, and events are explicitly scoped to an organization. External integration entities also use organization-specific identifiers.
Stripe objects are tagged so webhook processing can reject events that do not belong to this application context.
External systems
Provider credentials remain with the connection provider.
Shopify, Google Sheets, Drive, Dropbox, and OneDrive connections are managed through Composio. Nexodo stores a connection identifier instead of retaining the provider token.
Stripe checkout is created server-side. Webhooks verify signatures and replay state before subscription changes are accepted.
Runtime and recovery
Restricted containers, HTTPS policy, and encrypted backup recovery.
The application runs as a non-root user in a read-only container with dropped capabilities and dedicated writable volumes. HTTPS, HSTS, Content Security Policy, iframe denial, MIME protection, and restrictive browser permissions are active.
Nightly jobs check database integrity and create AES-256-GCM encrypted backups. Restore operations do not overwrite by default and verify integrity after recovery.
Current boundary
What Nexodo does not claim.
Nexodo does not claim SOC 2, ISO 27001, HIPAA, or another independent certification. Backups and DAM storage currently remain on isolated volumes on the OVH host; off-site replication is pending.
These boundaries are disclosed so a buyer can assess the current product against its own risk requirements.
Buyer verification
Match the controls to your own data classification and threat model.
Before adoption, identify the product data, supplier documents, user roles, external connections, and recovery objectives in scope. Confirm which information is commercially sensitive, who should approve changes, how access is removed, and what evidence your organization requires from a vendor.
Run a bounded evaluation with non-sensitive or representative data, review role enforcement, inspect integration permissions, test session and invitation behavior, and request current answers for any control that matters to procurement. Organizations requiring a specific certification, off-site backup arrangement, data residency commitment, or contractual security term should resolve that requirement before production use.
- Classify data and assign least-privilege roles
- Review integration scopes and credential ownership
- Confirm recovery expectations and storage boundaries
- Record certification or contractual requirements before rollout
Frequently asked questions
Clear answers before you evaluate a PIM.
Is Nexodo SOC 2 certified?+
No. Nexodo does not currently claim SOC 2 or ISO 27001 certification.
Where are backups stored?+
Encrypted backups currently remain on an isolated Docker volume on the OVH host. Off-site replication is pending.
Does Nexodo store provider access tokens?+
Provider credentials are managed by Composio; Nexodo stores the managed connection identifier.
Continue your product data research
Pay for catalog scale, not for every collaborator.
Read more →PIM softwarePIM software that keeps every product value accountable.
Read more →Shopify PIMPut governed product data upstream of Shopify.
Read more →Supplier product data onboardingOnboard supplier product data without surrendering control.
Read more →Test Nexodo with a supplier file your team already uses.
Import a CSV or Google Sheet, review changed values, and see whether the workflow fits your catalog before you commit.
- Use a representative product sample
- See source evidence and import history
- No invented feature claims