Security Overview
How Nubesti approaches platform security, access control, data protection, and vulnerability reporting.
Last updated: September 21, 2026
Security is the product. This overview describes how Nubesti LLC protects the platform and the data entrusted to us. It is not a substitute for a customer’s own security program.
1. Our commitment
We design the platform so that authorized testing of your systems does not become unauthorized access to anyone else’s. Tenant isolation, least privilege, and auditability are baseline requirements.
2. Infrastructure
- Production web properties are served through Cloudflare with TLS 1.2+ and modern security headers
- Data in transit is encrypted with TLS
- Data at rest is encrypted using industry-standard algorithms (AES-256 where we control the store)
- Administrative access uses unique identities and multi-factor authentication
3. Application and product security
- Secure development practices, code review, and dependency monitoring
- Role-based access in the product so you can limit who launches tests or sees reports
- Logging of security-relevant events for investigation
- Separation between marketing site, application, and customer-designated targets
4. Customer responsibilities
You must keep portal credentials safe, authorize only in-scope assets, configure integrations carefully, and treat findings as confidential. You decide what evidence leaves the platform.
5. Backups and resilience
We maintain backups of platform configuration and customer workspace data sufficient to recover from infrastructure failure. Backup copies are access-restricted and retained for a limited rotation period.
6. Vulnerability disclosure
Report issues in Nubesti systems (not customer targets) under the dedicated Vulnerability Disclosure Policy. Email [email protected]. We aim to acknowledge within 24 hours. The canonical researcher file is /.well-known/security.txt.
7. Compliance posture
We align controls with common enterprise expectations (including GDPR/CCPA handling described in the Privacy Policy and DPA). Formal certifications may be provided to enterprise customers under NDA when available.