Security
This page describes how NestedCerts protects your data and how to report a security concern. NestedCerts is operated by Nested Technology Group Pty Ltd, ABN 54 698 422 552, Queensland 4113, Australia.
Infrastructure and Encryption
- All traffic is encrypted in transit over HTTPS/TLS
- Data at rest is encrypted with AES-256 via AWS server-side encryption
- Amazon DynamoDB uses server-side encryption
- S3 buckets have public access blocked with CloudFront origin access control
- Secrets and API keys are stored in AWS Secrets Manager
Authentication
- Sign-in managed by AWS Cognito with SRP (Secure Remote Password) protocol
- API requests authenticated with short-lived JSON Web Tokens (JWTs)
- Mobile tokens stored in device secure storage (iOS Keychain / Android Keystore)
Payments
All payment processing is handled by Stripe. Full card numbers never touch our servers. Stripe is PCI DSS Level 1 certified. We do not hold a PCI certification of our own because card data is never within our environment.
Monitoring
- CloudWatch alarms monitor error rates, latency, and email reputation
- Breach notification within 72 hours per Australian Privacy Principles and GDPR Article 33
What We Do Not Claim
We have not undergone SOC 2, ISO 27001, or independent PCI audit. We rely on AWS and Stripe certifications and apply security best practices to components we control.
Reporting a Vulnerability
Email support@nestedcerts.com with subject "Security Report". We aim to acknowledge within 3 business days. We will not take legal action against good-faith researchers who stay in scope.
In Scope
- Authentication or authorisation bypasses
- Exposure of other users' data
- Injection vulnerabilities
- Server-side request forgery
- Significant misconfigurations
Out of Scope
- Denial-of-service attacks
- Social engineering or phishing
- Physical security testing
- Automated scanning that degrades service
- Accessing other users' data
- Vulnerabilities in third-party services
Last updated: July 30, 2026
JavaScript is required to use this application.
Please enable JavaScript in your browser to access the full NestedCerts platform.
Contact: support@nestedcerts.com