1. Purpose
This Security Notice explains the security practices that apply to the Nexus public website and to licensed deployments of the CB IMTO Transparency System. It is intended for central bank, IMTO, and procurement reviewers. It is not a certificate, attestation, or substitute for a contractual security schedule.
2. Scope
- Public website: informational pages and the inquiry form on this domain
- Licensed Nexus: the platform when deployed for a central bank, typically inside the customer’s infrastructure or a designated environment, with local operations via authorised integration partners
Customer supervisory data is not processed on this marketing site. Production data residency is determined by the deployment agreement.
3. Security posture
Nexus is designed around constraints typical of central bank buyers:
- On-premise or in-country deployment where cloud-only models are not acceptable
- Data residency in the deployment region, with local backup and recovery options
- Role-based access for CB, IMTO, and administrator personas
- Multi-factor authentication for privileged access
- Complete audit trails of data access and modifications
- API-first integration so IMTO feeds do not depend on manual file drops
4. Certification status
We do not display ISO, SOC, PCI, or similar logos or badges for programmes that are incomplete. Scope and target dates:
- Architecture standard — Engineered in accordance with ISO 27001 (Information Security) and ISO 20022 (Financial Messaging) standards.
- ISO/IEC 27001 — Formal audit in progress (target: Q4 2026). This is not a completed certification.
- SOC 2 Type II — The platform is designed to support SOC 2 Type II compliance controls. Inject Group Ltd does not claim a completed SOC 2 Type II report.
- Cyber Essentials — Inject Group Ltd holds Cyber Essentials.
A confidential security questionnaire can be provided during a formal evaluation. Request it through Request Access.
5. Deployment and sovereignty
Inject Group Ltd licenses the technology. In-country implementation and local operations are conducted via authorised central bank-accredited integration partners. Typical options include:
- Deployment inside central bank infrastructure
- Restricted regional hosting where the central bank specifies it
- Local backup, recovery, and support arrangements through the accredited partner
6. Access control
- Named user accounts; shared generic logins are not the intended model
- Role-based permissions separating CB supervisors, IMTO operators, and system administrators
- Multi-factor authentication for administrative and supervisory access
- Time-limited demo credentials issued only after a verified request
- Least-privilege handling of inquiry emails on the public site
7. Data handling
- Transport encryption (HTTPS/TLS) for the public site and for API traffic in licensed deployments
- Separation of marketing inquiry data from any future customer production data
- No requirement to submit IMTO customer PII through the public inquiry form
- Retention of inquiry records as described in the Privacy Policy
8. Logging and audit
Licensed deployments are designed to record access and changes to supervisory data so that central bank reviewers can reconstruct who viewed or modified records. Public-site logs are limited to what is needed to operate and protect the website.
9. Incidents
If we become aware of a personal-data breach affecting information we control, we will assess the risk and notify affected individuals and the competent authority where UK GDPR, EU GDPR, or NDPR/NDPA require it. Licensed-deployment incident process, including customer notification SLAs, is defined in the relevant contract.
10. Vulnerability reporting
If you believe you have found a security issue in this website or in Nexus, email team@injectgroup.com with a factual description and, where possible, steps to reproduce. Please do not access other people’s data or disrupt service. We will acknowledge responsible reports and keep the reporter informed of the outcome where it is appropriate to do so.
11. Contact
Security and privacy: team@injectgroup.com
Inject Group Ltd, Suite 15, Woodfield Business Centre, Carr Hill, Doncaster, South Yorkshire, DN4 8DE, United Kingdom
Related documents: Privacy Policy · Terms of Service · Compliance