Security

How Nexvo protects merchant data.

Security Overview

Nexvo Tech Pte. Ltd. operates Nexvo Commerce as a B2B SaaS platform for multi-channel commerce. Merchants connect marketplace stores, synchronize product and order data, and manage operations through a centralized workspace. Because our customers trust us with commercially sensitive information, security is embedded across product design, infrastructure, and internal operations.

Our security program focuses on protecting data in transit and at rest, enforcing strong authentication for marketplace integrations, limiting access to merchant data, and maintaining visibility through monitoring and audit logs. The controls below summarize the practices we apply to safeguard your business on Nexvo Commerce.

HTTPS Everywhere

All web and API traffic is encrypted in transit using industry-standard TLS. We enforce secure connections for authentication, marketplace sync, and dashboard access.

OAuth Authentication

Marketplace connections use OAuth-based authorization flows. We never request marketplace passwords, and access tokens are scoped to the permissions you approve.

Role-Based Access Control

Workspace administrators assign roles and permissions so team members access only the data and actions required for their responsibilities.

Credential Protection

Integration tokens and secrets are stored using secure credential management practices with restricted internal access and rotation procedures.

Data Encryption

Sensitive data is protected at rest and in transit. Encryption is applied to authorization credentials, session data, and other high-sensitivity records.

Infrastructure Security

Production environments use network segmentation, hardened configurations, and controlled deployment processes to reduce attack surface.

Backups

Regular backups support business continuity and recovery. Backup retention and restoration procedures are designed to protect against data loss events.

Monitoring

Operational monitoring, audit logs, and integration health checks help us detect anomalies, investigate incidents, and maintain platform reliability.

Limited Data Access

Internal access to merchant data follows least-privilege principles. Production access is granted on a need-to-know basis and logged where applicable.

Audit Logs

Platform activity and administrative actions generate operational logs that support security review, troubleshooting, and compliance inquiries.

Incident Response

We maintain procedures to assess, contain, and remediate security incidents. Validated issues are prioritized based on severity and potential impact.

Responsible Disclosure

Security researchers and customers may report vulnerabilities in good faith. We review reports promptly and work to address confirmed issues.

Incident Response

When we identify a potential security incident, our team follows documented response procedures to assess scope, contain impact, remediate root causes, and communicate with affected customers where required by law or contractual obligations. We prioritize incidents based on severity, data sensitivity, and operational impact.

Customers who suspect unauthorized activity involving their Nexvo account should contact security@nexvo.sg and support@nexvo.sg immediately so we can investigate and assist with credential rotation or access review.

Responsible Disclosure

We welcome responsible reports of potential vulnerabilities from customers, partners, and security researchers. If you believe you have discovered a security issue affecting Nexvo Commerce, please email security@nexvo.sg with sufficient detail to reproduce the issue. Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to investigate and remediate.

We review good-faith reports promptly and will acknowledge receipt where contact information is provided. We ask that testing be limited to systems you own or have explicit permission to assess, and that you avoid actions that could disrupt merchant operations or compromise third-party data.

Security Contact

For vulnerability reports, security inquiries, or coordination during an incident:

Email: security@nexvo.sg
Company: Nexvo Tech Pte. Ltd.
Privacy requests: privacy@nexvo.sg

Last updated: 30 June 2026