Legal
Security & Incident Response
Last updated: July 22, 2026
Getway protects customer accounts, API keys, usage logs, billing records, and trade workflow data through layered technical and operational controls.
1. Security controls
- TLS 1.2+ in transit and encryption at rest for production data stores.
- Hashed API keys, session protections, OTP verification, SSO/SCIM on eligible plans.
- Role-based access control, tenant isolation, audit logs, and least-privilege staff access.
- Rate limiting, abuse monitoring, dependency patching, and vulnerability triage.
- Restricted support workflows for security, privacy, and compliance tickets.
2. Customer responsibilities
Customers must protect user accounts, configure least-privilege roles, rotate API keys, verify webhook signatures, keep integration secrets out of client-side code, and notify us promptly of suspected compromise.
3. Incident reporting
Report suspected vulnerabilities, credential exposure, data exposure, or abuse to security@neximprove.com. Include affected workspace, timestamps, request IDs, affected endpoints, and safe reproduction details where available.
4. Breach and regulatory response
We classify, contain, investigate, and remediate incidents using an internal incident response SOP. Where legally required, Neximprove will coordinate notifications to affected customers and competent authorities. Indian CERT-In reporting requirements may require specified cyber incidents to be reported within 6 hours of notice.
5. Security testing
Do not run scans, exploitation attempts, load tests, or social engineering against Getway without written approval. Responsible disclosure reports are welcome at security@neximprove.com.