Security

Security built into every layer.

This page is maintained by Content Nexa to answer common security and privacy questions about the platform. It describes controls that exist today — not a certification.

Authentication

Sign-in is handled by managed authentication with support for email/password and social sign-in. Sessions use industry-standard tokens.

Permissions and roles

Access to workspace data is scoped by role. Sensitive actions require appropriate permissions, and roles are stored separately from user profiles to prevent privilege escalation.

Workspace isolation

Each workspace's content, connections and data are isolated. Row-level security policies enforce that users can only read and write data they are authorised to see.

Encryption in transit

All traffic to Content Nexa is served over HTTPS. Access tokens for connected integrations are stored server-side and never exposed to the browser.

Audit and activity

Key actions in your workspace are recorded so administrators can review who did what and when. Approval flows keep a human in the loop for sensitive operations.

Responsible AI

Content generated by AI is reviewable before publishing. Human approval is available across content, campaigns and agent actions. See our AI Transparency page for more.

What Content Nexa doesn't claim

We don't claim SOC 2, ISO 27001, HIPAA, PCI or GDPR certifications on this page. If you need a formal assessment or DPA, contact us.

Shared responsibility

Content Nexa

Platform security, hosting, authentication, permissions, encryption in transit.

Workspace admins

User access, role assignment, integration approvals and content review.

Users

Strong passwords, safe handling of connected accounts and reporting suspicious activity.