Authentication
Sign-in is handled by managed authentication with support for email/password and social sign-in. Sessions use industry-standard tokens.
Permissions and roles
Access to workspace data is scoped by role. Sensitive actions require appropriate permissions, and roles are stored separately from user profiles to prevent privilege escalation.
Workspace isolation
Each workspace's content, connections and data are isolated. Row-level security policies enforce that users can only read and write data they are authorised to see.
Encryption in transit
All traffic to Content Nexa is served over HTTPS. Access tokens for connected integrations are stored server-side and never exposed to the browser.
Audit and activity
Key actions in your workspace are recorded so administrators can review who did what and when. Approval flows keep a human in the loop for sensitive operations.
Responsible AI
Content generated by AI is reviewable before publishing. Human approval is available across content, campaigns and agent actions. See our AI Transparency page for more.
What Content Nexa doesn't claim
We don't claim SOC 2, ISO 27001, HIPAA, PCI or GDPR certifications on this page. If you need a formal assessment or DPA, contact us.
Shared responsibility
Platform security, hosting, authentication, permissions, encryption in transit.
User access, role assignment, integration approvals and content review.
Strong passwords, safe handling of connected accounts and reporting suspicious activity.

