1. Purpose
This Security Notice explains the security practices that apply to the Nexus public website and to licensed deployments of the CB IMTO Transparency System. It is intended for central bank, IMTO, and procurement reviewers. It is not a certificate, attestation, or substitute for a contractual security schedule.
2. Scope
- Public website: informational pages and the inquiry form on this domain
- Licensed Nexus: the platform when deployed for a central bank, typically inside the customer’s infrastructure or a designated environment, with local operations via authorised integration partners
Customer supervisory data is not processed on this marketing site. Production data residency is determined by the deployment agreement.
3. Security posture
Nexus is designed around constraints typical of central bank buyers:
- On-premise or in-country deployment where cloud-only models are not acceptable
- Data residency in the deployment region, with local backup and recovery options
- Role-based access for CB, IMTO, and administrator personas
- Multi-factor authentication for privileged access
- Complete audit trails of data access and modifications
- API-first integration so IMTO feeds do not depend on manual file drops
4. Standards and audits
Current programme status as of August 2026:
- ISO 27001 and ISO 20022 — The platform is designed to these information-security and financial-messaging standards.
- ISO/IEC 27001 — A formal audit is in progress, targeted for Q4 2026. A completed certificate has not been issued.
- SOC 2 Type II — Controls are designed to support a Type II programme. A completed SOC 2 report has not been issued.
- Cyber Essentials — Held by Inject Group Ltd.
A confidential security questionnaire can be provided during a formal evaluation. Request the Vendor Security & Data Governance Pack under NDA from Resources.
5. Deployment and sovereignty
Nexus SupTech Ltd licenses the technology. In-country implementation and local operations are conducted via authorised central bank-accredited integration partners. Typical options include:
- Deployment inside central bank infrastructure
- Restricted regional hosting where the central bank specifies it
- Local backup, recovery, and support arrangements through the accredited partner
After go-live, security, regulatory, and functional updates are prepared by Nexus and deployed only after the central bank’s review and formal approval. See change control on Deployment.
6. Access control
- Named user accounts; shared generic logins are not the intended model
- Role-based permissions separating CB supervisors, IMTO operators, and system administrators
- Multi-factor authentication for administrative and supervisory access
- Time-limited demo credentials issued only after a verified request
- Least-privilege handling of inquiry emails on the public site
7. Data handling
- Transport encryption (HTTPS/TLS) for the public site and for API traffic in licensed deployments
- Separation of marketing inquiry data from any future customer production data
- No requirement to submit IMTO customer PII through the public inquiry form
- Retention of inquiry records as described in the Privacy Policy
8. Logging and audit
Licensed deployments are designed to record access and changes to supervisory data so that central bank reviewers can reconstruct who viewed or modified records. Public-site logs are limited to what is needed to operate and protect the website.
9. Incidents
If we become aware of a personal-data breach affecting information we control, we will assess the risk and notify affected individuals and the competent authority where UK GDPR, EU GDPR, or NDPR/NDPA require it. Licensed-deployment incident process, including customer notification SLAs, is defined in the relevant contract.
10. Vulnerability reporting
If you believe you have found a security issue in this website or in Nexus, email governance@injectgroup.com with a factual description and, where possible, steps to reproduce. Please do not access other people’s data or disrupt service. We will acknowledge responsible reports and keep the reporter informed of the outcome where it is appropriate to do so.
11. Contact
Security and privacy: governance@injectgroup.com
Inject Group Ltd, Suite 15, Woodfield Business Centre, Carr Hill, Doncaster, South Yorkshire, DN4 8DE, United Kingdom
Related documents: Privacy Policy · Terms of Service · Compliance