Security
Security at AICE Nexus
Your projects hold API keys, documents and data. Here is how the console protects them, and what to do if you find a problem.
Two-factor sign-in
Authenticator-app codes with one-time recovery codes. Organizations can require them for every member, and sensitive actions ask for a fresh code.
Keys that never reach the browser
The console talks to services from its own server. Project API keys are shown once, can be rotated at any time, and every issue or rotation is logged.
Strong password storage
Passwords are hashed with Argon2id. Repeated failed sign-ins lock the account, and sessions expire after inactivity and after a fixed maximum.
Roles per organization
Admins, editors and viewers get only what their role allows, checked on the server for every request, not just hidden in the interface.
Audit trail
Two-factor sign-ins and changes, key rotations, role changes and platform actions are recorded, so you can see who changed what and when.
Isolated tenants
Each organization's projects, keys and service data are scoped to it. Service calls carry a signed token naming the tenant.
Report a vulnerability
If you believe you've found a security issue, tell us privately first so we can fix it before it's public. Include what you found, how to reproduce it and what an attacker could do with it.
- Only test against your own account and data.
- Don't access, change or delete other people's data, or degrade the service for others.
- Give us reasonable time to fix the issue before disclosing it.
We won't pursue action against research done in good faith within these rules.