Legal
Security
Nsites builds enterprise analytics and payment intelligence for organizations that operate under real regulatory scrutiny. Security is designed into the platform rather than added afterward.
Platform Architecture
Nsites applications run on managed cloud infrastructure with network isolation, least-privilege service accounts, and separate environments for development, staging, and production. Application access is brokered through authenticated sessions, and administrative operations are restricted to a small set of verified accounts.
Data Protection
Customer data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using industry-standard AES-256 encryption. Row-level authorization rules govern which records an authenticated user may read or modify, so tenants cannot access one another's data. Backups are encrypted and retained on a defined schedule to support recovery objectives.
Access Control
Access to production systems requires individual named accounts with multi-factor authentication. Permissions follow the principle of least privilege, are reviewed periodically, and are revoked promptly when a role changes or an engagement ends. Credentials and API keys are stored in managed secret stores and are never embedded in source code.
Payments and Cardholder Data
For Nsites PowerPlay Payments, card data is processed through PCI DSS compliant processing partners and certified device pathways such as Tap to Pay on iPhone. Nsites does not store full payment card numbers, magnetic stripe data, or card verification values on its own systems. Sensitive payment values are tokenized by the processor so downstream analytics operate on non-sensitive identifiers.
Monitoring and Incident Response
Application and infrastructure activity is logged and monitored for anomalous behavior. Nsites maintains an incident response process covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting customer data, Nsites will notify affected customers without undue delay and provide the facts known at the time along with remediation steps.
Vendor and Subprocessor Management
Third-party providers used for hosting, analytics, communications, and payment processing are evaluated for their security posture before onboarding and are bound by contractual confidentiality and data protection obligations. Nsites limits the data shared with each provider to what is required for the service performed.
Business Continuity
Nsites uses redundant, managed infrastructure and automated backups to support availability and recoverability. Recovery procedures are documented and tested so that critical analytics and payment services can be restored following a disruption.
Customer Responsibilities
Customers are responsible for safeguarding their own account credentials, provisioning and deprovisioning their users appropriately, configuring role assignments within their workspace, and ensuring that data supplied to Nsites may lawfully be processed for the intended analytics purposes.
Reporting a Vulnerability
If you believe you have identified a security vulnerability in an Nsites product or website, please report it to allan@nsites.tech with enough detail to reproduce the issue. Nsites asks that you avoid accessing or modifying data belonging to others and that you allow a reasonable period for remediation before public disclosure. We acknowledge good-faith reports and will keep you informed of our progress.
Security Contact
Security questions, due diligence requests, and documentation requests can be directed to allan@nsites.tech.
