Security & Trust

Your data. Locked down.

Real claims, not marketing fluff. Every statement below has a verifiable third-party source. If you find anything you can't verify, email security@nexoraaero.com.

Transport & storage

Encryption everywhere.

Every byte that leaves your browser is encrypted in flight. Every byte we store is encrypted at rest by our infrastructure provider.

TLS 1.3 in transit

HTTPS everywhere with HSTS. SSL Labs A grade. Verifiable at ssllabs.com.

Independently verifiable

AES-256 at rest

Database storage encrypted by Supabase (AWS RDS encryption). Backups encrypted with separate keys.

Provider-attested

No card data on our servers

Cards go directly from your browser to Stripe/Razorpay. We literally never see them, can't see them, can't leak them.

Architecture guarantee
Payments

Cards never touch our servers.

Every payment runs through a PCI-DSS Level 1 certified processor. We see an order ID, an amount, and a verified signature — never the card number, CVV, or expiry.

Stripe — international cards

PCI-DSS Service Provider Level 1 (highest tier). Stripe handles all card data. We get a webhook + verified signature.

stripe.com/docs/security

Razorpay — Indian payments

PCI-DSS L1 + RBI-licensed payment aggregator. Backend signature verification via Supabase Edge Function (HMAC-SHA256).

razorpay.com/security

Escrow on every order

Funds hold in escrow until you accept delivery. If the seller never delivers, you get a full refund — no questions.

14-day window
Authentication

Your account is yours.

Passwords are hashed with bcrypt (never stored in plain text). Sessions use signed JWTs. OAuth via Google/GitHub if you'd rather not have another password.

bcrypt password hashing

Cost factor 10. Passwords cannot be reversed even by us. We can reset, not retrieve.

OAuth — Google & GitHub

Skip the password entirely. We get only your email and name — never a token, never your password.

Row-level access control

Supabase RLS policies enforce that you can only read/write your own records — even if a query bypasses the app.

Sub-processors

Who else touches your data.

Honest list. Every third party we use, what they do, and where to verify their security posture.

Database & Auth Supabase SOC 2 Type II · HIPAA · ISO 27001 supabase.com/security ↗
Card payments (intl) Stripe PCI-DSS L1 · SOC 1/2 · ISO 27001 stripe.com/docs/security ↗
Card payments (IN) Razorpay PCI-DSS L1 · RBI-licensed PA razorpay.com/security ↗
PayPal payments PayPal PCI-DSS L1 · Buyer Protection paypal.com/security ↗
Static hosting Hostinger / Netlify DDoS protection · TLS · CDN netlify.com/security ↗
Stock imagery Pixabay No PII collected · Royalty-free pixabay.com/privacy ↗
Compliance — honest status

What we have. What we don't.

We won't pretend to hold certifications we don't. Here's the full truth — including the things we're working on.

StandardStatusNotes
HTTPS / TLS 1.3LiveEnforced site-wide via HSTS
PCI-DSSInheritedStripe + Razorpay are L1. We use SAQ-A scope (no card data ever touches us)
GDPRAlignedPrivacy policy + cookie banner + data-export endpoint. Not formally audited
CCPAAlignedRight to delete + data export available on request via privacy@nexoraaero.com
SOC 2 Type IINot yetOur sub-processors (Supabase, Stripe) hold SOC 2. We plan to pursue this at $100K+ MRR
ISO 27001Not yetInherited from Supabase. Direct certification planned post-Series A
HIPAANot applicableWe don't process health data

Why we're not lying with trust badges

It's tempting to slap a "SOC 2 Certified" badge on the homepage. We won't — because we aren't, and you deserve to know what's real vs. what's been outsourced to a more mature provider. Everything above is verifiable from the linked sources.

Responsible disclosure

Found a security issue? Tell us first.

If you discover a vulnerability, please email security@nexoraaero.com with reproduction steps. We respond within 24 hours, fix critical issues within 7 days, and publicly credit researchers (with consent) in our security changelog.

Our promise: We will not pursue legal action against good-faith researchers who follow responsible disclosure. PGP key available on request.

If something goes wrong

Incident response.

We hope you never need this section. If we ever have a confirmed data breach affecting your data, here's exactly what happens.

Within 72 hours

Email notification to every affected user with: what was accessed, when, by whom (if known), and recommended actions.

Public post-mortem

Published at /security-changelog within 30 days. Includes timeline, root cause, fixes, and process changes.

Free credit monitoring

If the breach involves payment data (it shouldn't — see above), we cover 12 months of credit monitoring.

Questions about how we protect your data?

We answer security questions personally. No bots, no canned responses.

Email security@nexoraaero.com Privacy policy Terms of service