In final testing

NexGuard isn’t on Google Play yet. Join early access and we’ll send the install link the day it opens.

Home Security

Security

Security you can
actually reason about

We describe only what NexGuard actually does — no “military-grade” slogans, no claims of being unhackable, and no certifications we don’t hold. Here is how the product protects your data, in concrete terms.

Device-encrypted vault · AES-256-GCM · TOTP 2FA · Entitlements enforced server-side

Passport.pdfOn your phone
Readable
encrypted on device
a3f8·9c2e·…·e21bAES-256-GCM ciphertext
Sealed
Our server stores this — and can’t decrypt it
Key stays on device Encrypted on device

Practices

How the rest is protected

Account security

Passwords are hashed with a modern algorithm and never stored or logged in the clear. Optional two-factor uses TOTP authenticator codes plus one-time recovery codes; enabling or changing it ends every other active session.

Session handling

Access is a short-lived token; the refresh token is opaque, single-use and stored only as a SHA-256 hash, rotated on every use. A failed refresh clears the session — no long-lived secret sits in the clear.

Entitlements on the backend

What your plan unlocks is decided and enforced on our servers, never trusted from the app UI. Purchases are verified server-side against Google Play before any plan is granted.

API hardening

The API runs behind standard hardening: security headers, strict CORS, and rate limits — with tighter per-route limits on login and account-recovery endpoints to slow brute-force and enumeration.

Safe data handling

All database access is parameterized. We record the fact that a sensitive action happened for audit — never its secret contents. Encrypted backups are sealed on your phone with your passphrase, which we never receive.

No hidden monitoring

NexGuard never silently reads your messages, calls, contacts, microphone, camera or screen. Scam and link analysis run only on content you choose to paste in.

Our threat posture

What NexGuard will never do

The strongest privacy guarantee is the data we never touch. These aren’t settings you toggle off — they’re boundaries built into the product.

Read your SMS, calls, contacts, notifications, mic, camera or screen in the background
Run silent surveillance — scam & link checks happen only on content you paste in
Ask for restricted Android permissions a shipped feature doesn’t genuinely need
Process or store your payment card — Google Play handles every purchase
Invent a score, a breach, or a threat when a signal isn’t available
Sell your data or use your content to train AI models
Boundariesenforced
Background message access
NEVER
Hidden location tracking
NEVER
Card-on-file storage
NEVER
Fabricated results
NEVER
Data resale
NEVER

Shared responsibility

Using NexGuard responsibly

Security is a partnership. We build the product to be honest and private by design; a few things stay in your hands — because only you hold the keys.

Your responsibilities

Keep your device lock, credentials and recovery codes safe, and turn on two-factor. Because the vault is encrypted on your device, only you can open it — if you lose your device access and recovery codes, we cannot recover your vault contents for you.

For households & organizations

If you set NexGuard up for family members or a team, you remain responsible for configuring access, accounts, permissions and internal security practices appropriate to your people — including who can view a shared dashboard and how accounts are managed.

Lawful, appropriate use

You are responsible for using NexGuard lawfully and for determining whether your intended use is permitted in your jurisdiction. See our Acceptable Use Policy. Information here is about the product — it is not legal or compliance advice.

Payments

We never handle your card

NexGuard doesn’t process or store payment cards. Paid plans are purchased through Google Play, which handles the sensitive payment information end to end. Our backend only receives a purchase token, which it verifies with Google before unlocking a plan.

Security FAQ

Straight answers about your data

Can Nexonix staff read my vault?
Not your passwords, logins or authenticator secrets — those are encrypted with a key held in your phone’s Android Keystore that we never receive, so there is nothing here to decrypt them with. Photos, documents and notes you choose to make web-accessible are a different answer: we hold that key, because it is what opens them in your browser. We don’t read them, every web decryption is written to your audit log, and leaving the option off keeps them device-only.
Do you use my data to train AI models?
No. NexGuard’s scores and verdicts come from deterministic engines, and the AI only explains an already-computed result. We don’t sell your data and we don’t feed content you paste in into model training.
What data do you actually store on the server?
Your account record, your device’s computed score and events, encrypted vault items, and audit entries recording that a sensitive action happened — never its secret contents. For password items we hold no key; for web-accessible media we hold a per-account key, kept encrypted at rest under a separate one. Our primary database is the source of truth; account passwords are only ever stored hashed.
What happens to my data if I delete my account?
Your account and its associated records are removed, including the per-account key that opens any web-accessible vault items and the ciphertext behind it. Anything under your device key was never readable here in the first place.
Do you claim to be “unhackable” or “military-grade”?
No. We describe only what the product actually does and hold no certifications we haven’t earned. Security is a set of concrete, verifiable practices — not a slogan.
Read the Privacy Policy

Get early access

Security is a habit, not a headline

That’s why NexGuard scores it, explains it, and keeps your data encrypted on your device. Get started free to try it.