This page is maintained by nexus modulabs to answer common security and privacy questions about nexus AI Studio. It describes app-visible controls in place today.
Every project, contact and document is scoped to your workspace via database-level policies - never just app code.
Multi-workspace with role-based access. Roles live in a dedicated table, not on the user record - no privilege escalation by edit.
Email + password and Google sign-in. Sessions are managed by the platform; passwords never touch our code.
Every share, comment, approval and admin change recorded with actor, timestamp and project context.
Public or token-protected share links, with expiry and one-click revoke. Approvals are time-stamped and version-bound.
Managed Lovable Cloud backend - regular backups and a managed Postgres database.
App runs on a globally distributed edge runtime for low latency without a single point of failure.
Admin tooling is gated by a server-side `has_role` check; impersonation requires elevated role and shows a banner.
nexus AI Studio provides the platform controls described above. Your team is responsible for: managing workspace membership and roles, choosing what to share publicly, keeping account credentials safe, and verifying that BOMs and quotations are accurate before contracting. We do not claim independent certification (e.g. SOC 2, ISO 27001) on this page; reach out if you need a current security questionnaire.
If you believe you've found a vulnerability, please contact us via the contact page. We take responsible disclosure seriously and will respond promptly.