Security is a release gate, not a tier.

Who is responsible for security at Nuclicore

Every release goes through a security gate I own. Audit logs, role-based access and data residency aren't a tier, they're in the code your team can read. If your auditor has a question, they can ask me.

Anel Bejtovic

Chief Technology Officer

Every deployment passes an automated security check, a test environment and a human approval. Your auditor can read the code, the commit history and the audit log.

Security-First Architecture

Every layer is built so your security team can check it rather than take it on trust: your own backend, your own data, your own repository, and a gate in front of every release.

Your own backend, your own data

Every application runs its own Express backend in its own containers. Your subscription gets a managed, encrypted Postgres database per environment, one for Preview, one for Test, one for Production, with each application kept apart by its own table suffix and each deployment label in its own schema with its own secrets. Where your policy asks for more, Enterprise gives you a dedicated database per application, environment or label, your own external database, a dedicated cluster, or a single tenant server.

EU hosting, your cloud, or your own data centre

Azure in the EU as standard. On Enterprise: Hetzner in Germany, your own AWS, Azure or GCP account, on premise, and air gapped delivery.

Encryption and secrets

TLS in transit, encryption at rest. Secrets scoped per environment and per label, never in code, never in prompts.

Monitoring and incidents

Requests, error rate, latency and health per app. Incident history and alerts. Nightly automated scans.

What the security gate actually does

Every release is scanned before it is built, and the gate is built to fail closed.

Static code analysis with Semgrep

Insecure patterns, hard coded credentials and weak configuration are found in your own code before anything is built.

Dependency scanning with Trivy

Known CVEs in frontend and backend packages, checked against a vulnerability database that refreshes continuously.

Fail closed

Critical and high findings stop the release. A scan that cannot complete also stops it, so a crashed scanner never counts as a clean result. A crashed scan is retried automatically.

Fixed for you where it is safe

Upgrades that stay inside the installed major version are applied automatically, several CVEs on one package are closed with a single upgrade, and the change is committed on its own as a security: update commit before the code is scanned again. Anything that needs a judgement call is listed with the reason, and one click turns it into a task for the agents.

Your security team gets the scanner output per release and can run its own scanners against the same repository.

What every release goes through

Security check

Static code analysis with Semgrep and dependency scanning with Trivy. Critical and high findings stop the release, and safe dependency upgrades are applied and committed automatically before the build.

Build

Container images built and pushed to a private registry.

Test

Deployed to an isolated test environment with its own database and secrets.

Approval

A named person approves. Optional mandatory approval per subscription.

Production

Released. Every version stays in the history and can be redeployed. Nightly ZAP scans afterwards.

Every task is one commit, so the git log is the change record. The workspace audit trail records who approved what and when.

Who did what, on the record

Sign in

Sign in with Microsoft Entra ID, Google, GitHub, SSO and SAML, or a six digit code by email. Sign in forms are protected with reCAPTCHA.

Roles

Four roles per subscription: Owner, Admin, Billing Admin and Developer.

Reserved actions

Starting, approving or rejecting a production release, creating or removing deployment targets, and creating or changing skills are reserved for Owners and Admins. Each one is written to the Audit Trail as it happens.

Audit Trail

The workspace Audit Trail records approvals, releases, member changes, secret changes, file actions, skill changes, and every task field change with the value before and after. Together with one commit per task, that is a change record your auditor can read end to end.

The agent that plans does not build, the agent that builds does not sign off, and a named person in your organisation approves the release.

What the platform enforces inside your application

File uploads

SVG files are stripped of scripts, file content is checked against its declared type, files are always served as downloads rather than rendered, and every file action is audited.

Outbound traffic

Every integration call leaves through the Nuclicore integration gateway, which only connects to approved provider addresses. An application cannot use a platform integration to reach an arbitrary host.

Secrets

Stored per environment and per deployment label, never in code, never in prompts, never in container images, exports or backups. At release time deploy credentials are fetched into a temporary folder that is removed when the release ends.

Spend containment

A monthly AI spend cap per application and a monthly budget per integration with a hard limit and email alerts, so a runaway loop is a stopped integration rather than an invoice.

Your code, in your hands, before you ask for it

Standard React, Express, Postgres and Docker in a normal git repository. Export it to GitHub or as a ZIP whenever you want.

Repository backup

Switch on repository backup and every successful release is pushed to your own GitLab: one branch per environment, one commit per release, one way only. The access token is checked for push rights on that exact project and stored encrypted, and no secrets or credential files are included. Your source code is in your own systems continuously, not on request.

This is the answer to a source code escrow requirement, without an escrow agent, without a deposit schedule and without a release condition to argue about.

If Nuclicore disappeared tomorrow, you can keep running the application on your own infrastructure, and any developer picks it up from the repository.

Compliance

What we put in writing for your procurement and audit teams.

GDPR

DPA with every account, EU hosting by default and Germany on request, a published subprocessor list, and your workspace content is not used to train models.

Data residency

EU, Germany, your own cloud account, or your own data centre.

Control frameworks

Nuclicore works to the ISO 27001 and SOC 2 control frameworks, and the controls are built into the platform rather than documented around it.

Security pack on request

Architecture description, penetration test summary, subprocessor list, DPA template, DORA contract addendum and the data sheet for your register of information, so a questionnaire can be answered from one package.

DORA and outsourcing

For financial entities supervised under DORA, and for firms whose risk carriers pass DORA down by contract. You get a contract addendum with the Article 30 provisions, the data for your register of information including our subprocessor chain, audit and access rights, incident notification, and an exit that already works: standard code, a standard database, and every release backed up into your own GitLab.

Card data is handled by Stripe, never stored by Nuclicore.

Talk to our CTO

Ready to discuss security?

Let our experts demonstrate how Nuclicore meets your compliance requirements.