Trust
Security
How we approach security on this website, and how to report a vulnerability.
Last updated: 1 October 2026
Our approach
We use reasonable technical and organisational measures designed to protect personal data. In practice that means granting the least access needed, keeping data separated by default, and reviewing changes before they ship.
The controls listed below are the ones that apply to this website. We do not claim any certification or external audit, and no system is perfectly secure — anyone who tells you otherwise is selling something.
How we protect data
- Encryption in transit using HTTPS/TLS, with HSTS enabled.
- Authentication and session management, where required, handled by a dedicated identity provider that supports multi-factor authentication.
- Hardened HTTP response headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy).
- The public project-enquiry flow does not accept submissions through a website form; an enquiry is composed and sent from your own email application.
- Request logging by our hosting provider, and error monitoring, so faults can be detected and investigated.
- Marketing subscription records, including unsubscribe instructions, are stored on our own servers and are not left for a third-party provider to be the authority on.
Staying safe with us
- Be alert to phishing: we will never ask for a password, one-time code, or payment details by email.
- Check that you are on nexusinnov8.com before sharing anything with us.
- If something looks wrong, contact us before acting on it.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you have found a security vulnerability, email security@nexusinnov8.com with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable opportunity to address it. We aim to acknowledge legitimate security reports as promptly as reasonably practicable.
Please act in good faith: do not access or modify other people’s data, degrade our services, or run automated scans that could cause harm.
Data protection
Nexus Innov8 Africa Limited handles personal data in line with the Ghana Data Protection Act 2012 (Act 843). For what we collect and why, see our Privacy Policy, or email privacy@nexusinnov8.com.
Questions about this page? Email hello@nexusinnov8.com or visit our contact page.