Security
Security at Nexo Access.
Current source-level facts and clearly named limits.
Page reviewed August 26, 2026.
Architecture
Built for HIPAA compliance
The separate Nexo Access platform is the regulated application. Its role-based portal doors, row-level database isolation, and auditable operational records are documented in the platform architecture. Production verification remains gated by the pre-live compliance checklist before real protected health information is handled.
Marketing website
What this website collects
Only what you type into the apply and contact forms, and it reaches us by email. This website has no member accounts and no database of its own.
Do not submit protected health information through this site. The forms avoid soliciting it: they ask only for business contact details and display a warning not to include member or health information. Submissions are sanitized before they are sent. There is no advertising on this site, and nothing collected here is sold or shared for marketing.
Control design
How the platform is built
The platform is designed for TLS-protected network traffic, role-based access, and audit logging. Those controls are code and architecture decisions; their production operation must be verified before launch.
The marketing-site mail path is designed around a send-only, least-privilege identity. That statement describes the intended permission boundary, not evidence from an external audit or a live operating claim.
Assurance boundary
What we do not claim
No SOC 2, HITRUST, or comparable third-party attestation has been supplied, and no external platform audit has been supplied. The launch-gated statement above is the full public compliance claim at this stage.
If a reviewer needs an attestation we do not have, the honest answer is that we do not have it yet, and we would rather tell you here than at the end of a procurement.
Legal gate
The HIPAA notice
The HIPAA Notice of Privacy Practices is published. It takes effect on the date Nexo Access first handles your member information, so it carries no effective date yet. Read the HIPAA Notice. For how this website handles ordinary contact information, see the privacy policy.
Contact
Reporting a security concern
If you have found something that looks wrong, tell us at info@nexoaccess.com. Include what you saw and how to see it again. Please do not include protected health information in the report.