Security is a release gate, not a tier.
Who is responsible for security at Nuclicore
Every release goes through a security gate I own. Audit logs, role-based access and data residency aren't a tier, they're in the code your team can read. If your auditor has a question, they can ask me.
Anel Bejtovic
Chief Technology Officer
Every deployment passes an automated security check, a test environment and a human approval. Your auditor can read the code, the commit history and the audit log.
Security-First Architecture
Every layer is built so your security team can check it rather than take it on trust: your own backend, your own data, your own repository, and a gate in front of every release.
Your own backend, your own data
Every application runs its own Express backend in its own containers. Your subscription gets a managed, encrypted Postgres database per environment, one for Preview, one for Test, one for Production, with each application kept apart by its own table suffix and each deployment label in its own schema with its own secrets. Where your policy asks for more, Enterprise gives you a dedicated database per application, environment or label, your own external database, a dedicated cluster, or a single tenant server.
EU hosting, your cloud, or your own data centre
Azure in the EU as standard. On Enterprise: Hetzner in Germany, your own AWS, Azure or GCP account, on premise, and air gapped delivery.
Encryption and secrets
TLS in transit, encryption at rest. Secrets scoped per environment and per label, never in code, never in prompts.
Monitoring and incidents
Requests, error rate, latency and health per app. Incident history and alerts. Nightly automated scans.
What the security gate actually does
Every release is scanned before it is built, and the gate is built to fail closed.
Static code analysis with Semgrep
Insecure patterns, hard coded credentials and weak configuration are found in your own code before anything is built.
Dependency scanning with Trivy
Known CVEs in frontend and backend packages, checked against a vulnerability database that refreshes continuously.
Fail closed
Critical and high findings stop the release. A scan that cannot complete also stops it, so a crashed scanner never counts as a clean result. A crashed scan is retried automatically.
Fixed for you where it is safe
Upgrades that stay inside the installed major version are applied automatically, several CVEs on one package are closed with a single upgrade, and the change is committed on its own as a security: update commit before the code is scanned again. Anything that needs a judgement call is listed with the reason, and one click turns it into a task for the agents.
Your security team gets the scanner output per release and can run its own scanners against the same repository.
What every release goes through
Security check
Static code analysis with Semgrep and dependency scanning with Trivy. Critical and high findings stop the release, and safe dependency upgrades are applied and committed automatically before the build.
Build
Container images built and pushed to a private registry.
Test
Deployed to an isolated test environment with its own database and secrets.
Approval
A named person approves. Optional mandatory approval per subscription.
Production
Released. Every version stays in the history and can be redeployed. Nightly ZAP scans afterwards.
Every task is one commit, so the git log is the change record. The workspace audit trail records who approved what and when.
Who did what, on the record
Sign in
Sign in with Microsoft Entra ID, Google, GitHub, SSO and SAML, or a six digit code by email. Sign in forms are protected with reCAPTCHA.
Roles
Four roles per subscription: Owner, Admin, Billing Admin and Developer.
Reserved actions
Starting, approving or rejecting a production release, creating or removing deployment targets, and creating or changing skills are reserved for Owners and Admins. Each one is written to the Audit Trail as it happens.
Audit Trail
The workspace Audit Trail records approvals, releases, member changes, secret changes, file actions, skill changes, and every task field change with the value before and after. Together with one commit per task, that is a change record your auditor can read end to end.
The agent that plans does not build, the agent that builds does not sign off, and a named person in your organisation approves the release.
What the platform enforces inside your application
File uploads
SVG files are stripped of scripts, file content is checked against its declared type, files are always served as downloads rather than rendered, and every file action is audited.
Outbound traffic
Every integration call leaves through the Nuclicore integration gateway, which only connects to approved provider addresses. An application cannot use a platform integration to reach an arbitrary host.
Secrets
Stored per environment and per deployment label, never in code, never in prompts, never in container images, exports or backups. At release time deploy credentials are fetched into a temporary folder that is removed when the release ends.
Spend containment
A monthly AI spend cap per application and a monthly budget per integration with a hard limit and email alerts, so a runaway loop is a stopped integration rather than an invoice.
Your code, in your hands, before you ask for it
Standard React, Express, Postgres and Docker in a normal git repository. Export it to GitHub or as a ZIP whenever you want.
Repository backup
Switch on repository backup and every successful release is pushed to your own GitLab: one branch per environment, one commit per release, one way only. The access token is checked for push rights on that exact project and stored encrypted, and no secrets or credential files are included. Your source code is in your own systems continuously, not on request.
This is the answer to a source code escrow requirement, without an escrow agent, without a deposit schedule and without a release condition to argue about.
If Nuclicore disappeared tomorrow, you can keep running the application on your own infrastructure, and any developer picks it up from the repository.
Compliance
What we put in writing for your procurement and audit teams.
GDPR
DPA with every account, EU hosting by default and Germany on request, a published subprocessor list, and your workspace content is not used to train models.
Data residency
EU, Germany, your own cloud account, or your own data centre.
Control frameworks
Nuclicore works to the ISO 27001 and SOC 2 control frameworks, and the controls are built into the platform rather than documented around it.
Security pack on request
Architecture description, penetration test summary, subprocessor list, DPA template, DORA contract addendum and the data sheet for your register of information, so a questionnaire can be answered from one package.
DORA and outsourcing
For financial entities supervised under DORA, and for firms whose risk carriers pass DORA down by contract. You get a contract addendum with the Article 30 provisions, the data for your register of information including our subprocessor chain, audit and access rights, incident notification, and an exit that already works: standard code, a standard database, and every release backed up into your own GitLab.
Card data is handled by Stripe, never stored by Nuclicore.
Talk to our CTO
Ready to discuss security?
Let our experts demonstrate how Nuclicore meets your compliance requirements.