Trust & Security Posture
DeSouza Strategic Systems LLC · DSS Advisory Group · DSS Nexus™ · Last updated July 14, 2026
DSS Nexus is built to enterprise security standards - tenant isolation at the database and application layers, MFA enforced on every enrolled account, encryption in transit and at rest, audited access, and a no-training data posture. We do not claim certifications we have not achieved.
In place today
HTTPS/HSTS, a strict Content-Security-Policy and modern security headers, per-IP API rate limiting, hashed credentials, signed session cookies, server-side role-based access control with default-deny, database-layer tenant isolation (row-level security), append-only intelligence records, and audit logging.
Assurance path
Formal SOC 2 Type II is part of our planned assurance program; FedRAMP authorization will be pursued in step with federal customer demand. DSS Nexus does not represent either certification as completed. We publish status as each milestone is reached and will not represent any certification as achieved until independently verified.
How your data is handled
Your organization's data is isolated at the database layer with row-level security, so only your organization can access it. We do not use your data to train shared or third-party models. You can export or delete your data from Account & Settings, and we honor the published retention schedule. Every AI output is cited to its source and recorded in an append-only audit trail.
Controlled Unclassified Information (CUI): DSS Nexus does not currently represent a CUI-authorized boundary. Submission-time controls block CUI, FCI, classified, source-selection sensitive, procurement-sensitive, and export-controlled technical data from AI/report workflows. If your workload requires CUI handling, contact us before use so we can scope the appropriate authorized environment rather than assume one.
Subprocessors
We run the service on a small set of vetted subprocessors: Vercel (application hosting), Stripe (payments), Resend (transactional email), OpenAI (model inference), a managed PostgreSQL provider (primary datastore), and Sentry (error monitoring). We publish material changes to this list. Live AI-quality and system status are on our status page.
Responsible disclosure
If you believe you have found a security issue, contact info@dssadvisorygroup.com. We will acknowledge and investigate promptly.
Data & AI
See our Data Use Notice and AI & Data Use Disclosure for how information and AI outputs are handled.