Security & Compliance

Trust isn't a page. It's the platform.

Every NXHub tenant inherits the same security posture as our largest enterprise deployments. Encryption, audit, disaster recovery, and regulatory reporting ship on day one — not as an upsell.

Trust & Compliance

Audit-ready on day one.

NXHub launches in LATAM with the data-protection regimes your regulators actually enforce — and the global frameworks your board and auditors already trust. North America and EU activate as those markets come online.

LATAM · Launch markets
LGPD (Brazil)

Lei 13.709 — full data-subject rights, DPO contact, RIPD records.

Active
Ley 81 (Panamá)

ANTAI personal-data oversight across every tenant.

Active
LFPDPPP (México)

ARCO rights workflow, privacy notices, INAI-aligned controls.

Active
Ley 1581 (Colombia)

Habeas Data registry, SIC reporting, consent receipts.

Active
Ley 25.326 (Argentina)

AAIP-aligned controls and cross-border transfer safeguards.

Active
Ley 19.628 (Chile)

Modernised privacy law — purpose limitation and subject access.

Active
Global
SOC 2 Type II

Independently audited security & availability controls.

Active
ISO/IEC 27001

Information-security management aligned to international standard.

Active
PCI DSS

Card data tokenised at Stripe — never touches NXHub systems.

Active
North America & EU · Roadmap
HIPAA

Enterprise BAA + PHI-grade safeguards. Activates with US healthcare launch.

Roadmap
CCPA

California residents. DSAR workflow ships with the US rollout.

Roadmap
GDPR

EU/EEA. DPA and subprocessor list available today on request.

Roadmap

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, per-tenant key scoping for storage.

Continuous audit trail

Every privileged action logged to an append-only ledger — actor, payload, outcome.

Disaster recovery

Point-in-time recovery to any microsecond within the trailing 14 days.

Full attestations, regional DPAs, and subprocessor lists available on request via the Trust Center.

Trust Center

Need SOC 2 reports or our DPA?

Attestations, subprocessor lists, penetration-test summaries, and the master DPA are available under NDA via the Trust Center.