This page summarizes the security practices NxusCloud Inc. follows in delivering managed IT, cloud, and consulting services. It is published for transparency with clients, partners, and prospective clients evaluating our security posture. It is a summary of our internal policy, not the complete internal document, and is not a substitute for the specific security commitments in a signed Master Services Agreement or Statement of Work.
1. Purpose and Scope
This policy establishes the baseline security requirements for NxusCloud systems, personnel, and the client environments we manage. It applies to all NxusCloud personnel and contractors with access to NxusCloud or client systems.
2. Access Control
Access to client and internal systems is granted on a least-privilege, role-based basis and reviewed regularly. Multi-factor authentication (MFA) is required for administrative access, remote access, and any access to systems containing sensitive data. Privileged access uses just-in-time elevation, such as Microsoft Entra Privileged Identity Management, rather than standing admin rights, where supported. Access is revoked promptly upon role change or termination of a team member.
3. Data Classification and Handling
Client and internal data is classified by sensitivity, and handling requirements scale accordingly — from encrypted, access-logged handling of restricted data (such as protected health information or credentials) down to standard handling of public marketing content. Confidential and restricted data is encrypted both at rest and in transit.
4. Encryption Standards
Data in transit is encrypted using TLS 1.2 or higher, including HTTPS/SSL enforced site-wide via automatically renewing certificates. Data at rest containing confidential or restricted information is encrypted using industry-standard algorithms.
5. Endpoint and Network Security
Company and client-managed endpoints run current endpoint detection and response (EDR) tooling and receive security patches on a defined, tested cadence. Network perimeter and edge protection, including a Cloudflare-backed network, is used to mitigate DDoS attacks and filter malicious traffic for hosted client sites. Remote access to client environments requires MFA and a secure connection method.
6. Incident Response
Suspected security incidents are handled under our internal Incident Response Plan, which defines containment, investigation, and client notification procedures. All NxusCloud personnel are required to report suspected incidents immediately upon discovery.
7. Vendor and Third-Party Risk
We evaluate the security posture of critical vendors and subprocessors, including cloud infrastructure and network security providers, before onboarding and periodically thereafter.
8. Security Awareness
NxusCloud personnel complete security awareness training covering phishing, credential hygiene, data handling, and incident reporting.
9. Policy Review
This policy is reviewed at least annually and upon material changes to our environment or applicable regulatory requirements.
Questions About This Policy
To request additional detail for a security review, vendor questionnaire, or compliance audit, please contact us.