A CMS Nexus Growth Advisor will contact you within one business day.
Last updated: July 2026 · CMS Nexus
Effective as of July 2026.
Infrastructure security
Product security
Operational security
Application security
CMS Nexus is committed to maintaining the confidentiality, integrity, and availability of all data entrusted to us by our users. We design our security program around industry-recognized frameworks and apply a defense-in-depth approach across our infrastructure, application, and operations. This page describes the technical and organizational measures we have implemented to protect your data. We continuously review and improve our security practices in response to evolving threats.
In Transit. All data transmitted between your browser or application and CMS Nexus servers is encrypted using TLS 1.2 or TLS 1.3. We enforce HTTPS across all Platform endpoints without exception. Connections that attempt to use older, insecure protocols are rejected. Our TLS certificates are managed and rotated automatically to prevent expiration-related vulnerabilities.
At Rest. All data stored on our servers — including databases, file storage, and backup archives — is encrypted using AES-256 encryption. Encryption keys are managed through a dedicated key management service with strict access controls, automatic key rotation, and full audit logging of all key operations.
We implement the principle of least privilege across our entire infrastructure. Internal access to customer data is restricted to authorized personnel who require it for legitimate operational purposes such as technical support, and only with explicit customer consent. All internal access events are logged and reviewed.
Multi-factor authentication (MFA) is mandatory for all CMS Nexus employee accounts with access to production systems. We conduct periodic access reviews and immediately revoke credentials when an employee changes roles or departs the organization. Remote access to production infrastructure is restricted to secured, audited connections.
For Platform users, we offer MFA options including authenticator apps and email verification to secure your account.
CMS Nexus infrastructure is hosted on cloud providers that maintain SOC 2 Type II, ISO 27001, and PCI DSS certifications. Our primary data centers provide enterprise-grade physical security including 24/7 on-site security personnel, biometric access controls, video surveillance, and redundant power and cooling systems.
We deploy across multiple availability zones to ensure high availability. Network security includes DDoS mitigation, Web Application Firewall (WAF), intrusion detection systems, and network segmentation that isolates customer data environments from each other and from internal systems.
We perform automated daily backups of all customer data. Backups are encrypted, stored in geographically separate regions, and retained for a minimum of 30 days. Backup integrity is verified through automated restoration tests conducted on a scheduled basis.
We maintain a documented Business Continuity and Disaster Recovery (BCDR) plan that is reviewed and tested annually. Our Recovery Time Objective (RTO) is under 4 hours and our Recovery Point Objective (RPO) is under 24 hours for most failure scenarios. In the event of a declared disaster, our response team is activated immediately to minimize disruption to Platform availability.
Our security team conducts continuous automated vulnerability scanning across our infrastructure and application layers. Critical and high-severity vulnerabilities are triaged and remediated within 24 hours of identification. Medium-severity issues are addressed within 7 days, and low-severity issues within 30 days.
We engage independent third-party security firms to conduct comprehensive penetration tests at least annually, covering our web application, API, and network infrastructure. Findings are tracked to resolution and penetration test summaries are available to enterprise customers upon request under NDA.
We maintain a responsible disclosure program. Security researchers who identify and responsibly report vulnerabilities are acknowledged and, where applicable, rewarded. To report a vulnerability, contact security@cmsnexus.com.
We operate a 24/7 security monitoring program using a Security Information and Event Management (SIEM) system that aggregates and analyzes logs from across our infrastructure. Automated alerts are configured for anomalous behavior, unauthorized access attempts, and policy violations. Our on-call security team responds to critical alerts at any hour.
We maintain a formal Incident Response Plan (IRP) that is tested through tabletop exercises at least twice per year. In the event of a confirmed security incident affecting customer data, we will: (a) contain and remediate the incident using documented procedures; (b) conduct a thorough root cause analysis; (c) notify affected users within 72 hours as required by applicable law; and (d) implement preventive measures to reduce the likelihood of recurrence. All incidents are documented internally and reviewed by leadership.
All CMS Nexus employees complete mandatory security awareness training upon joining and at least annually thereafter. Training covers phishing recognition, secure handling of sensitive data, password hygiene, social engineering, and incident reporting procedures. Employees with privileged access to production systems undergo additional specialized security training.
We conduct simulated phishing exercises to measure and improve employee awareness. Employees who handle personal data are required to sign confidentiality agreements and adhere to our internal data handling policies. Background checks are conducted for employees in roles with access to sensitive systems, in accordance with applicable law.
We maintain a formal vendor management program. Before onboarding any third-party service provider that processes customer data, we conduct a security assessment to evaluate their controls, certifications, and compliance posture. We require vendors to sign Data Processing Agreements (DPAs) and to meet security standards consistent with our own.
Vendors are reviewed periodically and whenever there are material changes to their services or security posture. Vendor relationships that no longer meet our security standards are terminated, and data is deleted or returned in accordance with contractual obligations.
CMS Nexus operates in compliance with applicable data protection and privacy regulations, including the General Data Protection Regulation (GDPR), the Lei Geral de Proteção de Dados (LGPD), and the California Consumer Privacy Act (CCPA). We conduct annual compliance reviews to ensure our practices remain aligned with regulatory requirements as they evolve.
Enterprise customers may request a Data Processing Agreement (DPA) and, where available, a summary of our compliance certifications. Contact security@cmsnexus.com to request these documents.
Security is a shared responsibility. While CMS Nexus takes extensive measures to protect the Platform and its infrastructure, users are responsible for maintaining the security of their own Platform Accounts. You should: (a) use a strong, unique password and enable MFA on your account; (b) keep your login credentials confidential and not share them with unauthorized parties; (c) promptly notify us if you suspect unauthorized access to your account; (d) keep your devices and browsers up to date with the latest security patches; and (e) be cautious of phishing attempts that may impersonate CMS Nexus communications.
CMS Nexus is not liable for security incidents that result from a user's failure to maintain adequate account security practices.
If you discover a potential security vulnerability or have concerns about the security of your data, please contact our security team immediately:
security@cmsnexus.com
We respond to critical reports within 24 hours and treat all submissions as strictly confidential. Please do not publicly disclose vulnerabilities until we have had a reasonable opportunity to investigate and remediate the issue. We appreciate the efforts of the security research community in helping keep CMS Nexus and our users safe.
Privacy Policy|Terms of Service|Privacy & Security
© 2026 CMS NEXUS. ALL RIGHTS RESERVED.