Updated September 6, 2026

Security controls, with their scope.

This page describes application mechanisms and the deployment evidence an organization should request before using sensitive data. A source-code capability is not a guarantee that every deployment or integration is configured correctly.

No certification claim.

We do not claim SOC 2 Type II certification, blanket GDPR compliance, an independently audited security posture or universal database-enforced tenant isolation. Advanced privacy research features are not a substitute for verified operational controls.

Organization and project access

The application uses organization membership checks, role-based authorization and explicitly scoped data access. This is logical isolation implemented by application checks and data relationships, not dedicated infrastructure or database row-level security for every customer. Scope must be enforced at each relevant read and write boundary.

Project and organization permissions depend on the endpoint and role. API keys and integration credentials must be scoped, stored and revoked through the applicable administrative controls. Do not infer universal coverage from the existence of a guard or middleware.

Authentication and deployment configuration

OIDC login and TOTP MFA are supported through the configured identity provider. Availability and enforcement depend on that provider's realm, client and account settings; a feature being supported does not mean MFA is enforced for every user.

API authentication, rate limiting and signed webhook verification exist on supported paths. Signature algorithms and replay/idempotency controls vary by integration. Consumers must verify signatures using the relevant trusted secret or key; retry support is not a universal exactly-once delivery guarantee.

Encryption, infrastructure and operational assurance

Production deployments should use HTTPS, restricted infrastructure access and appropriately configured secret storage. Database/object-storage encryption, key rotation, backup retention, restoration testing, network segmentation and monitoring are deployment-level properties. Confirm their current configuration and evidence with the operator before processing sensitive data.

This page does not attest to a particular TLS version on every internal connection, automatic rotation of every key, dedicated customer infrastructure, zero-downtime releases, a recovery-time objective, completed penetration testing or continuous availability. Provider and infrastructure outages can interrupt work.

Review and external effects

Draft review, approval workflows, budget checks and emergency-stop controls support operator oversight. Approval applies to a specific action and its parameters; it does not eliminate current authorization, consent, budget or safety checks. Keep a human reviewer for factual, brand, legal and audience decisions.

An offline review decision remains locally queued until the server accepts it. A queued job is not provider acceptance or delivery. Emergency stop blocks new effects through the applicable execution controls; it cannot recall content or spending already accepted by an external provider.

Quality scores and multi-model reviews can identify issues, but do not certify accuracy, lawful content or business outcomes. Confirm required account permissions, sender registration and contact-level consent for each channel.

Decision evidence and verification

The decision ledger supports scoped evidence exports. Signed attestation packs require a configured signing key and are limited to the supported records, export window and size. Verify with a trusted, independently obtained key identity; a public key supplied only by an untrusted pack is not a trust anchor.

Signatures and hash chains establish integrity of the exported bytes, not that every platform action was recorded, that upstream data is true or that a decision was correct. Review coverage counts, omitted records and timestamps. Logs and traces are not a blanket legal-compliance determination.

Privacy requests, export and erasure

Consent records and scoped export/erasure workflows support data handling. Coverage varies by data domain. A completed application request does not automatically erase third-party provider copies, backups, legally retained billing records or every integration's records.

Request the export manifest, domain coverage, retention exceptions and evidence of downstream completion before describing an export or erasure as complete. The privacy contact is privacy@ultimatenexus.ai. See the Privacy Policy for rights and request handling. These limitations do not waive applicable legal rights.

AI providers and experimental privacy

Prompts, relevant business context and other data needed for a requested operation may be sent to configured AI, media or channel providers. Review their retention, training, regional processing and contractual terms. Do not assume anonymization, a no-training agreement or a particular processing region from a feature label.

Simulated or sidecar-dependent confidential inference, federated training, on-device and cryptographic research outputs are not independently verified production privacy guarantees. Do not use a synthetic proof, hash-derived metric or an unavailable external service as assurance evidence.

What to request before procurement

Request this information from security@ultimatenexus.ai. Availability of an assessment or contractual commitment must be confirmed; this page does not create an SLA.

Responsible disclosure and incidents

Report potential vulnerabilities to security@ultimatenexus.ai. Include the affected area, potential impact and non-destructive reproduction steps. Do not access or disclose other customers' records, credentials or personal data. Give us a reasonable opportunity to investigate before public disclosure.

We do not operate a formal bug bounty program. In the event of a confirmed breach affecting customer data, affected customers will be notified without undue delay and in accordance with applicable legal requirements. A notification commitment is not a promise that no breach can occur.