Security & compliance

Designed around central bank requirements

Data residency, on-premise deployment, integration standards, and local support are treated as core design constraints — not afterthoughts.

On-prem readyDeploy inside CB infrastructure
ISO 27001 auditFormal audit in progress · target Q4 2026

On-premise capability

Deploy within CB infrastructure where cloud-only models are not acceptable.

Data sovereignty

Keep data residency in the deployment region with local backup and recovery options.

Security standards

Designed against ISO 27001 and ISO 20022. Cyber Essentials is held; the ISO 27001 audit is targeted for Q4 2026.

Strong authentication

Multi-factor authentication and role-based access for CB, IMTO, and admin personas.

Audit trails

Complete logging of data access and modifications for supervisory accountability.

Local partnership

Implementation and support model designed to work with local technical partners.

Standards

Certification status

Nexus is designed against ISO 27001 and ISO 20022. Inject Group Ltd holds Cyber Essentials. The ISO 27001 formal audit is in progress, targeted for Q4 2026.

ISO 27001 and ISO 20022
Information security and financial messaging are built into the architecture — from access control to message handling.
ISO 27001 audit
A formal audit is in progress, targeted for Q4 2026.
Cyber Essentials
Held by Inject Group Ltd.
SOC 2 Type II
Controls are designed to support a Type II programme. A completed SOC 2 report is not yet issued.

Supervisory controls

Compliance operations inside the platform

Automated scoring & alerts

  • Compliance scores based on CB regulations
  • Severity-based risk alerts for supervisors
  • Suspicious activity detection signals
  • IMTO license and profile tracking

Reporting & BI

  • On-demand regulatory report generation
  • Power BI and open BI tool integration
  • Consistent data lineage for audits
  • Historical analysis path for trend review