POL-05

Information security policy

The technical and organisational measures that protect the NextX platform and its data.

Code
POL-05
Version
1.0
Effective from
28 Sep 2026
Last reviewed
28 Sep 2026

01Access control

Individual accounts with five roles: administrator, dispatcher, technician, management and system operator. Technicians see only their own team's tickets. Deactivating an account ends its web sessions immediately and revokes its mobile-app tokens, which expire after 30 days anyway.

02Authentication

Passwords of at least 12 characters, checked against public breached-password databases, and a limited number of sign-in attempts. The web panel offers two-step sign-in with an authenticator app (TOTP) and recovery codes.

03Encryption

All connections use HTTPS. Passwords are stored only as a hash (bcrypt), and two-step sign-in secrets are encrypted in the database. In the mobile app, the access token is kept in the phone's secure storage and local data is deleted on sign-out.

04Infrastructure and changes

The platform runs on Laravel Cloud in the Frankfurt region (Germany), with separate test and production environments. Every change passes automated tests before release, and production is updated only through tagged versions.

05Traceability

The platform records who assigned, recorded and completed each ticket, intervention and inspection, and every document sent to clients.

06Incidents

Incidents affecting personal data are notified to Next M under the data processing agreement (POL-04).

07Vulnerability reporting

Report vulnerabilities to security@nextx.ro with a description and steps to reproduce. Please do not access data that isn't yours or disrupt the service. We will acknowledge your report and let you know when the issue is fixed.

Version history

v1.0
28 Sep 2026
First verified version, based on how the platform actually works.
Questions about this document: security@nextx.ro