Legal
Security & Data Practices
Our approach
Security is built into how we deliver software: least-privilege access, encrypted transport (HTTPS/TLS), secrets stored outside source code, dependency updates on active projects, and code review on production changes.
Specific controls for your project are documented in the statement of work and may include additional requirements for regulated industries.
Client data handling
Project credentials and data are stored in approved tools with access limited to engineers assigned to the engagement.
We do not use client production data to train third-party AI models without explicit written consent.
At project end, credentials are rotated or revoked per the handover plan, and access is removed from our systems.
Incident response
If we become aware of a security incident affecting your project data, we will notify you without undue delay and cooperate on containment and remediation as agreed in contract.
Responsible disclosure
If you discover a vulnerability affecting devnexum.com or our services, please report it responsibly to hello@devnexum.com with enough detail to reproduce the issue.
We will acknowledge valid reports within 5 business days and work on a fix before public disclosure where appropriate. We do not pursue legal action against good-faith security research.
Contact
For privacy or legal requests, email hello@devnexum.com.