Skip to content
Nexus
PlatformCapabilitiesComplianceArchitectureDeploymentResourcesHow to buy
Request Briefing
PlatformCapabilitiesComplianceArchitectureDeploymentResourcesHow to buyRequest Briefing
Home/Security Notice

Legal & privacy

Security Notice

How Inject Group Ltd approaches security for the Nexus public site and for licensed deployments: on-premise options, data sovereignty, access control, and standards alignment.

Effective 17 August 2026 · Last updated 18 August 2026

On this page

  1. Purpose
  2. Scope
  3. Security posture
  4. Standards and audits
  5. Deployment and sovereignty
  6. Access control
  7. Data handling
  8. Logging and audit
  9. Incidents
  10. Vulnerability reporting
  11. Contact

1. Purpose

This Security Notice explains the security practices that apply to the Nexus public website and to licensed deployments of the CB IMTO Transparency System. It is intended for central bank, IMTO, and procurement reviewers. It is not a certificate, attestation, or substitute for a contractual security schedule.

2. Scope

  • Public website: informational pages and the inquiry form on this domain
  • Licensed Nexus: the platform when deployed for a central bank, typically inside the customer’s infrastructure or a designated environment, with local operations via authorised integration partners

Customer supervisory data is not processed on this marketing site. Production data residency is determined by the deployment agreement.

3. Security posture

Nexus is designed around constraints typical of central bank buyers:

  • On-premise or in-country deployment where cloud-only models are not acceptable
  • Data residency in the deployment region, with local backup and recovery options
  • Role-based access for CB, IMTO, and administrator personas
  • Multi-factor authentication for privileged access
  • Complete audit trails of data access and modifications
  • API-first integration so IMTO feeds do not depend on manual file drops

4. Standards and audits

Current programme status as of August 2026:

  • ISO 27001 and ISO 20022 — The platform is designed to these information-security and financial-messaging standards.
  • ISO/IEC 27001 — A formal audit is in progress, targeted for Q4 2026. A completed certificate has not been issued.
  • SOC 2 Type II — Controls are designed to support a Type II programme. A completed SOC 2 report has not been issued.
  • Cyber Essentials — Held by Inject Group Ltd.

A confidential security questionnaire can be provided during a formal evaluation. Request the Vendor Security & Data Governance Pack under NDA from Resources.

5. Deployment and sovereignty

Nexus SupTech Ltd licenses the technology. In-country implementation and local operations are conducted via authorised central bank-accredited integration partners. Typical options include:

  • Deployment inside central bank infrastructure
  • Restricted regional hosting where the central bank specifies it
  • Local backup, recovery, and support arrangements through the accredited partner

After go-live, security, regulatory, and functional updates are prepared by Nexus and deployed only after the central bank’s review and formal approval. See change control on Deployment.

6. Access control

  • Named user accounts; shared generic logins are not the intended model
  • Role-based permissions separating CB supervisors, IMTO operators, and system administrators
  • Multi-factor authentication for administrative and supervisory access
  • Time-limited demo credentials issued only after a verified request
  • Least-privilege handling of inquiry emails on the public site

7. Data handling

  • Transport encryption (HTTPS/TLS) for the public site and for API traffic in licensed deployments
  • Separation of marketing inquiry data from any future customer production data
  • No requirement to submit IMTO customer PII through the public inquiry form
  • Retention of inquiry records as described in the Privacy Policy

8. Logging and audit

Licensed deployments are designed to record access and changes to supervisory data so that central bank reviewers can reconstruct who viewed or modified records. Public-site logs are limited to what is needed to operate and protect the website.

9. Incidents

If we become aware of a personal-data breach affecting information we control, we will assess the risk and notify affected individuals and the competent authority where UK GDPR, EU GDPR, or NDPR/NDPA require it. Licensed-deployment incident process, including customer notification SLAs, is defined in the relevant contract.

10. Vulnerability reporting

If you believe you have found a security issue in this website or in Nexus, email governance@injectgroup.com with a factual description and, where possible, steps to reproduce. Please do not access other people’s data or disrupt service. We will acknowledge responsible reports and keep the reporter informed of the outcome where it is appropriate to do so.

11. Contact

Security and privacy: governance@injectgroup.com
Inject Group Ltd, Suite 15, Woodfield Business Centre, Carr Hill, Doncaster, South Yorkshire, DN4 8DE, United Kingdom

Related documents: Privacy Policy · Terms of Service · Compliance

We use cookies

Inject Group Ltd uses essential cookies to make this website work. With your consent, we also use analytics cookies to understand which organisations visit our pages. That identifies the institution and country from your network, not you by name. We do not use cookies for advertising. Privacy Policy.

Rejecting analytics still lets you use the site. Accept if we may record organisation-level visits.