This document describes how the platform works and is provided for transparency. It is not legal advice. If any term here conflicts with a signed agreement between your organization and Nomaxion Inc., that signed agreement governs.

Legal

Security & Trust

Version 1.0 — Effective September 21, 2026

This page describes the security controls that are actually implemented in the Nomaxion platform (the "Platform") today. We keep it deliberately factual: every control listed here is built into the product. Where something is part of our roadmap rather than in place today, we say so plainly.

Nomaxion is a digital record-keeping, workflow, and verification tool. It is a record-keeping tool only — it does not approve work, authorize anyone to work, monitor field conditions in real time, or certify any site, person, or activity as safe or compliant. Security controls protect the integrity and confidentiality of your records; they do not replace the judgment of a qualified supervisor.

Authentication & sign-in

Access to the Platform is protected by layered, standards-based authentication. You can strengthen your account with any combination of the options below.

  • Passwords are never stored in readable form. They are stored only as a bcrypt hash with a unique per-password salt, so the original password cannot be recovered from our records.
  • Optional multi-factor authentication (MFA) using time-based one-time passwords (TOTP) compatible with standard authenticator apps. MFA recovery codes are themselves stored only as hashes.
  • Optional passkeys / WebAuthn (FIDO2) and biometric unlock (Face ID / fingerprint), so a device can sign in without a shared secret ever leaving it.
  • New and changed passwords are screened against known-breached-password datasets using a k-anonymity method — only a short, partial fingerprint of the password is ever used for the check, never the password itself.
  • Authentication is protected by per-request rate limiting to blunt automated brute-force attempts. By deliberate policy, accounts are never permanently time-locked, so a legitimate field worker can never be walled out of safety-critical records with the correct credentials.

Access control & separation

Records are visible only to the people and organizations they belong to. Access is enforced on the server for every request, not just hidden in the interface.

  • Role-based access control determines what each user can view, create, sign, and administer.
  • Project- and company-based scoping keeps every document, permit, and record segregated to the specific project and organization it belongs to — records are not shared across unrelated projects or companies.
  • Signing PINs used to authorize documents are stored only as a hash, never in plaintext.

Tamper-evident record integrity

Safety records exist to be trusted after the fact. The Platform is built so that key records cannot be quietly altered.

  • Key actions — record creation, signatures, acknowledgements, and legal acceptances — are written to a cryptographically chained audit trail.
  • Each entry is hashed with SHA-256 over a canonical payload that includes the previous entry’s hash, so the entries form a chain. Altering or removing any earlier entry breaks every hash that follows it.
  • The chain can be independently re-computed and verified, making undetected tampering evident rather than silent.
  • Legal acceptances are recorded with the agreement version, a timestamp, and the IP address and device/browser used.

Data transport & platform

The Platform is delivered as a progressive web app (PWA) so field crews can keep working where connectivity is poor.

  • All traffic between your device and the Platform is encrypted in transit using HTTPS/TLS.
  • The app can be installed to the home screen and caches data locally so it remains usable during limited or intermittent connectivity, syncing when a connection returns.
  • The Platform runs on managed cloud infrastructure.

Data residency

Platform data is hosted on managed cloud infrastructure. Depending on the hosting region, information may be stored or processed in Canada and/or the United States and handled by our infrastructure and sub-processors. If your organization has specific data-residency requirements, contact us for current deployment-specific information before onboarding.

For full detail on what we collect and how it is handled, see our Privacy Policy.

Independent attestations

We believe in describing our security honestly. The controls above are implemented in the Platform today. Formal third-party attestations such as SOC 2 or ISO 27001, and independent penetration testing, are part of our maturity roadmap rather than something we claim to hold today. If your procurement process requires a security review, questionnaire, or specific attestation, contact us and we will work with you directly.

Contact

Questions about our security posture, or need to run a procurement or vendor-security review? Reach us at [email protected].