Nexco builds AI agents for executive search. We handle sensitive candidate data on behalf of our search firm customers, and security is a first-order design concern: enterprise SSO via WorkOS, UK and EU data residency, encryption in transit and at rest, continuous dependency monitoring, and a documented incident response programme aligned to ISO 27001.
Our full Security FAQ, covering business controls, application design, GDPR, and operational controls, is available to customers and prospects under NDA on request.
If you've found a security issue in Nexco's services, we'd like to hear from you.
Contact: [email protected]
We will acknowledge receipt within 2 business days, send a preliminary assessment within 5 business days, and keep you updated on remediation. We commit to:
Not pursuing legal action against good-faith security researchers who comply with the scope and rules of engagement below.
Crediting researchers in a public acknowledgements section (where the reporter consents) once a vulnerability is remediated.
In scope
Applications served from *.nexco.ai, including the marketing site and any production application subdomains.
Nexco's public APIs.
Authentication and session-management flows.
Out of scope
Third-party services Nexco uses but does not operate (e.g. Microsoft Azure, Vercel, WorkOS; report to those vendors directly).
Denial-of-service testing, social engineering, physical security, or any testing that could disrupt production for our customers.
Reports based solely on outdated browsers or unsupported configurations.
Volumetric scanning that doesn't demonstrate a vulnerability.
Rules of engagement
Do not access, modify, or exfiltrate any data that is not your own.
Do not degrade service for our customers.
Give us a reasonable window to remediate before any public disclosure.
Provide enough detail in your report for us to reproduce the finding.
A paid bug bounty programme is not currently offered; recognition and a written acknowledgement are what we can offer at this stage.
Real-time availability of Nexco production services: status.nexco.ai.
For any security-related question, vulnerability report, or security questionnaire response: