🔒 Setup Guidelines
Follow these steps before publishing your Data Security Policy:
- Review Content: This document details security standards tailored for file processing tools (such as encryption standards and automated file purging). Confirm it reflects your hosting configuration.
- Fill in Variables: Replace all [Bracketed Text] with your operational contact points and security emails.
- Remove this Box: Once finalized, delete this entire
<div class="guidelines-box">...</div> block from your code.
Data Security Policy
Last Updated: [August 8, 2026]
At NexaStax, safeguarding the integrity, confidentiality, and availability of your data is our highest priority. Because our platform offers micro-SaaS utilities like PDF conversion and media optimization, we maintain rigorous technical and organizational security controls designed to protect user files and personal information from unauthorized access or disclosure.
1. Encryption Standards (Transit & Rest)
We enforce modern cryptographic standards across all interactions with the NexaStax platform:
- Encryption in Transit: All data transferred between your browser and our servers is encrypted using industry-standard Transport Layer Security (TLS 1.3 / TLS 1.2) protocols.
- Encryption at Rest: Temporary files, user configurations, and associated metadata stored on our cloud infrastructure are protected using robust AES-256 encryption algorithms.
2. Automated File Deletion & Lifecycle
To minimize data exposure risks, files uploaded for conversion or optimization (such as PDFs and media assets) are handled under a strict ephemeral data policy:
- Files are processed securely on isolated processing nodes.
- All uploaded and converted files are automatically purged from our servers within a short operational window (typically within [2 hours] of processing completion).
- Users can also manually trigger immediate deletion via the tool interface where applicable.
3. Infrastructure & Network Security
Our infrastructure is hosted on enterprise-grade cloud environments protected by multi-layered defense systems:
- Web Application Firewalls (WAF) and automated DDoS mitigation guard against malicious traffic and automated attacks.
- Network segmentation ensures that tool processing environments are strictly isolated from core administrative databases.
4. Access Control & Authorization
Access to production systems and customer data storage is restricted based on the principle of least privilege:
- All administrative access requires multi-factor authentication (MFA) and secure SSH key validation.
- Access logs are continuously monitored to identify and audit any anomalous behavior or unauthorized access attempts.