Skip to content
Nelsonian Solutions

How we work

Security and data protection

The posture this platform is built to. It is stated so that a procurement or security reviewer can check it, and it is tested in the build pipeline rather than asserted.

Posture

Authentication and sessions
Email and password with strong hashing, plus passkeys. Multi-factor authentication is mandatory for every staff role and enforced at the session level. Password-reset tokens are single-use, expiring and hashed at rest, with no account enumeration.
Role-based access and tenant isolation
Every request is authorised server-side. A client organisation can read only its own data. Cross-tenant access is tested per resource type as a standing regression suite.
No card data
The platform never receives, stores, logs or transmits a card number, CVV or expiry. Hosted checkout or tokenised fields only. PCI-DSS SAQ-A scope.
Encryption
TLS 1.2 or later in transit with HSTS; encryption at rest for data and documents.
Private storage
Client documents live in a private bucket with public read disabled and verified by test, served only through short-lived signed URLs, with every download recorded.
Audit logging
Every privileged write records actor, action, entity, before and after values, timestamp and request identifier. The log is append-only.
Soft delete and retention
Nothing is hard-deleted. Every record carries a retention class, and retention is enforced by a scheduled job.
Backups
Nightly backups with point-in-time recovery, and a restore rehearsed and documented before launch. An untested backup is not a backup.
Security headers
A content-security policy without unsafe-inline or unsafe-eval, HSTS with preload, frame-ancestors denied, a referrer policy and a permissions policy denying camera, microphone, geolocation and payment.
Incident response and disclosure
A documented procedure with a named owner, a security.txt with a disclosure contact, and a client-notification template.
Sub-processors
A published, versioned list of third parties that process data on the firm's behalf, with purpose and region.

security.txt