Security

Security at AICE Nexus

Your projects hold API keys, documents and data. Here is how the console protects them, and what to do if you find a problem.

Two-factor sign-in

Authenticator-app codes with one-time recovery codes. Organizations can require them for every member, and sensitive actions ask for a fresh code.

Keys that never reach the browser

The console talks to services from its own server. Project API keys are shown once, can be rotated at any time, and every issue or rotation is logged.

Strong password storage

Passwords are hashed with Argon2id. Repeated failed sign-ins lock the account, and sessions expire after inactivity and after a fixed maximum.

Roles per organization

Admins, editors and viewers get only what their role allows, checked on the server for every request, not just hidden in the interface.

Audit trail

Two-factor sign-ins and changes, key rotations, role changes and platform actions are recorded, so you can see who changed what and when.

Isolated tenants

Each organization's projects, keys and service data are scoped to it. Service calls carry a signed token naming the tenant.

Report a vulnerability

If you believe you've found a security issue, tell us privately first so we can fix it before it's public. Include what you found, how to reproduce it and what an attacker could do with it.

  • Only test against your own account and data.
  • Don't access, change or delete other people's data, or degrade the service for others.
  • Give us reasonable time to fix the issue before disclosing it.

We won't pursue action against research done in good faith within these rules.