TrustedSite security certification is active for the production website. The live TrustedSite trustmark is rendered on NEXUS and provides third-party verification of the certification status.
A consolidated record of third-party security verification and independently measured controls for NEXUS PROJECT. Results are presented according to the terminology used by each provider and are not represented as equivalent forms of certification.
TrustedSite security certification is active for the production website. The live TrustedSite trustmark is rendered on NEXUS and provides third-party verification of the certification status.
Independent public assessment of the NEXUS TLS endpoint returned an A+ overall rating, with TLS 1.3 support and long-duration HTTP Strict Transport Security observed at the time of testing.
MDN HTTP Observatory measured the production HTTP security configuration at A+ with a score of 105/100 and 11 of 12 tests passed after CSP hardening and browser security controls were deployed.
SecurityHeaders.com returned an A+ grade for the production origin, observing the deployed Content-Security-Policy, Permissions-Policy, Referrer-Policy, HSTS, X-Content-Type-Options and X-Frame-Options controls.
TrustedSite is shown as a certification because that is the provider's certification product. Qualys SSL Labs, MDN HTTP Observatory and SecurityHeaders.com are shown as independent security assessments and grades, not certifications. Results describe the tested public configuration at the time of assessment and do not replace penetration testing, ISO/IEC 27001 certification, SOC 2 attestation, or continuous security monitoring.
Good-faith security reports can be submitted through the NEXUS responsible disclosure channel. Scope and contact details are published in security.txt.
Review operational controls, privacy, editorial standards, domain verification and open assurance items in the NEXUS Trust Center.