Nsites

Legal

Security

Nsites builds enterprise analytics and payment intelligence for organizations that operate under real regulatory scrutiny. Security is designed into the platform rather than added afterward.

Platform Architecture

Nsites applications run on managed cloud infrastructure with network isolation, least-privilege service accounts, and separate environments for development, staging, and production. Application access is brokered through authenticated sessions, and administrative operations are restricted to a small set of verified accounts.

Data Protection

Customer data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using industry-standard AES-256 encryption. Row-level authorization rules govern which records an authenticated user may read or modify, so tenants cannot access one another's data. Backups are encrypted and retained on a defined schedule to support recovery objectives.

Access Control

Access to production systems requires individual named accounts with multi-factor authentication. Permissions follow the principle of least privilege, are reviewed periodically, and are revoked promptly when a role changes or an engagement ends. Credentials and API keys are stored in managed secret stores and are never embedded in source code.

Payments and Cardholder Data

For Nsites PowerPlay Payments, card data is processed through PCI DSS compliant processing partners and certified device pathways such as Tap to Pay on iPhone. Nsites does not store full payment card numbers, magnetic stripe data, or card verification values on its own systems. Sensitive payment values are tokenized by the processor so downstream analytics operate on non-sensitive identifiers.

Monitoring and Incident Response

Application and infrastructure activity is logged and monitored for anomalous behavior. Nsites maintains an incident response process covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting customer data, Nsites will notify affected customers without undue delay and provide the facts known at the time along with remediation steps.

Vendor and Subprocessor Management

Third-party providers used for hosting, analytics, communications, and payment processing are evaluated for their security posture before onboarding and are bound by contractual confidentiality and data protection obligations. Nsites limits the data shared with each provider to what is required for the service performed.

Business Continuity

Nsites uses redundant, managed infrastructure and automated backups to support availability and recoverability. Recovery procedures are documented and tested so that critical analytics and payment services can be restored following a disruption.

Customer Responsibilities

Customers are responsible for safeguarding their own account credentials, provisioning and deprovisioning their users appropriately, configuring role assignments within their workspace, and ensuring that data supplied to Nsites may lawfully be processed for the intended analytics purposes.

Reporting a Vulnerability

If you believe you have identified a security vulnerability in an Nsites product or website, please report it to allan@nsites.tech with enough detail to reproduce the issue. Nsites asks that you avoid accessing or modifying data belonging to others and that you allow a reasonable period for remediation before public disclosure. We acknowledge good-faith reports and will keep you informed of our progress.

Security Contact

Security questions, due diligence requests, and documentation requests can be directed to allan@nsites.tech.