01Our commitment
Protecting the financial and personal data our clients trust us with is central to how NEXGENCA operates. This page summarises the safeguards we use to keep that data confidential, accurate, and available. These practices are aligned with the SOC 2 trust principles.
02Encryption
Data is encrypted in transit using industry-standard TLS as it moves between your browser, our site, and our service providers. Data held by our platforms is encrypted at rest by those providers.
03Access controls
Access to client data is restricted on a least-privilege, need-to-know basis. Team accounts use strong authentication, and access is reviewed and revoked promptly when it is no longer required.
04Trusted infrastructure & vendors
We rely on established providers — such as Google Workspace for scheduling and communications and reputable hosting for this site — that maintain their own recognised security certifications. We review the security posture of the vendors that process client data.
05Monitoring & maintenance
We keep systems and software up to date and monitor for unusual activity so potential issues can be identified and addressed quickly.
06Data minimisation & retention
We collect only the information we need to schedule consultations and deliver services, and we retain it only for as long as necessary before securely deleting or anonymising it. See our Privacy Policy for detail.
07Incident response
We maintain a process to respond to suspected security incidents. If a breach affecting your personal data occurs, we will investigate, take corrective action, and notify affected parties and regulators as required by applicable law.
08Your part in keeping data safe
Security is shared. Please keep any credentials we issue confidential, use secure channels to share sensitive documents, and let us know immediately if you suspect any unauthorised access.
09Report a concern
To report a security concern or vulnerability, contact [security@nexgenca.com]. We take every report seriously and will respond promptly.