Security Overview
The administrative, technical, and physical safeguards we apply to client systems and data.
- Effective
- August 26, 2026
- Updated
- August 26, 2026
This overview describes the safeguards NextEra Group applies to its own systems and to client systems we build or operate. It is written to answer the questions that come up in procurement and vendor security review.
Controls specific to an engagement are defined in the applicable statement of work. Where a client’s requirements exceed what is described here, those requirements govern.
1. Organizational security
- Personnel are bound by written confidentiality obligations that survive the end of their engagement.
- Access to client environments is granted on a least-privilege, need-to-know basis and reviewed when roles change.
- Background screening is conducted where a client requires it and law permits.
- Security and privacy training is provided at onboarding and refreshed periodically.
2. Access control
- Multi-factor authentication is required on all administrative and remote access.
- Credentials and secrets are held in a managed secrets store, never in source control.
- Access is revoked promptly on personnel departure or role change.
- Shared accounts are avoided; where unavoidable, access is logged and credentials rotated.
3. Data protection
- In transit: TLS 1.2 or higher for all external connections.
- At rest: AES-256 or provider-equivalent encryption for stored data and backups.
- Production data is not copied into development environments. Where realistic test data is required, it is anonymized or synthesized.
- Data is segregated by client; we do not commingle client data in shared datastores without explicit agreement.
4. Secure development
- Changes go through peer review and version control before reaching production.
- Automated dependency scanning flags known vulnerabilities, which are triaged by severity.
- Environments are separated across development, staging, and production.
- Infrastructure is defined as code where practical, so configuration is reviewable and reproducible.
5. Infrastructure and availability
- We build on established cloud providers that maintain SOC 2 Type II and ISO 27001 certification for their platforms.
- Backups are automated, encrypted, and restore-tested on a defined schedule.
- Logging and alerting cover authentication events, administrative actions, and error conditions.
- Recovery objectives are agreed per engagement rather than assumed.
6. AI-specific controls
- AI provider agreements are configured so that client content is not used to train general-purpose models, unless the client directs otherwise in writing.
- What may be sent to a model is scoped in the engagement documents; sensitive fields are redacted or excluded by default.
- Prompts and outputs are logged only where the client has agreed, with a defined retention period.
- Systems that act on model output include human review at any step with material consequences.
7. Incident response
We maintain a documented incident response process covering detection, triage, containment, eradication, recovery, and post-incident review. Where we act as processor, affected clients are notified within 48 hours of our becoming aware of a personal data breach, per Section 8 of our DPA.
8. Vendor management
Subprocessors are assessed before engagement and are listed on our Subprocessors page. Each is bound by data protection terms no less protective than those we offer clients.
9. What this overview is not
We are a small consultancy, and we state our posture plainly rather than implying certifications we do not hold. NextEra Group is not currently SOC 2 or ISO 27001 certified as an organization; the cloud platforms we build on are. If your procurement process requires an organizational certification, tell us early so we can discuss whether we are a fit.
10. Reporting a vulnerability
Email info@nexteragp.com with steps to reproduce. See our Acceptable Use Policy for our good-faith research commitment.