How we protect your data
Everything on this page can be checked: each commitment maps to a signed document, a published policy or a control you can ask us to demonstrate.
SOC 2 (Security + Confidentiality) readiness program in progress; Type I audit engagement planned for Q4 2026. The report will be available to clients under NDA on issuance.
What we commit to
- A signed HIPAA Business Associate Agreement before any protected health information is exchanged.
- AES-256 encryption at rest and TLS 1.2 or better in transit for every system that holds client data.
- Append-only audit logs of document access, portal sign-ins and onboarding actions, retained six years.
- Least-privilege access: roles are held in a separate table and checked on the server for every request.
- Two-step sign-in required for every NEXACC staff and administrator account.
- Client files stored in a private bucket, reachable only through short-lived signed links.
- Your records returned within five business days of a thirty-day notice to end the engagement, and breach notification within thirty calendar days of discovery.
Policies
HIPAA
The full HIPAA package — Business Associate Agreement, encryption policy, audit-logging and disclosure-accounting policy — is published in one place.
Vendors & sub-processors
Our sub-processor list is being published here as each vendor review is completed. Ask us at info@nexacc.com for the current list in the meantime.
Report a security concern
Email info@nexacc.com with what you found and how to reproduce it. We acknowledge reports within one business day, investigate, and tell you the outcome. Please do not access, alter or download anyone else's data while testing.
