Legal

Security & Data Practices

Effective 24 June 2026This document is provided for transparency. Have your legal adviser review it before relying on it for compliance decisions.

Our approach

Security is built into how we deliver software: least-privilege access, encrypted transport (HTTPS/TLS), secrets stored outside source code, dependency updates on active projects, and code review on production changes.

Specific controls for your project are documented in the statement of work and may include additional requirements for regulated industries.

Client data handling

Project credentials and data are stored in approved tools with access limited to engineers assigned to the engagement.

We do not use client production data to train third-party AI models without explicit written consent.

At project end, credentials are rotated or revoked per the handover plan, and access is removed from our systems.

Incident response

If we become aware of a security incident affecting your project data, we will notify you without undue delay and cooperate on containment and remediation as agreed in contract.

Responsible disclosure

If you discover a vulnerability affecting devnexum.com or our services, please report it responsibly to hello@devnexum.com with enough detail to reproduce the issue.

We will acknowledge valid reports within 5 business days and work on a fix before public disclosure where appropriate. We do not pursue legal action against good-faith security research.

Contact

For privacy or legal requests, email hello@devnexum.com.