Security
Security you can
actually reason about
We describe only what NexGuard actually does — no “military-grade” slogans, no claims of being unhackable, and no certifications we don’t hold. Here is how the product protects your data, in concrete terms.
Device-encrypted vault · AES-256-GCM · TOTP 2FA · Entitlements enforced server-side
Go deeper
Two topics, in full detail
The headline practices are below. These two have their own page if you want the whole picture.
Practices
How the rest is protected
Account security
Passwords are hashed with a modern algorithm and never stored or logged in the clear. Optional two-factor uses TOTP authenticator codes plus one-time recovery codes; enabling or changing it ends every other active session.
Session handling
Access is a short-lived token; the refresh token is opaque, single-use and stored only as a SHA-256 hash, rotated on every use. A failed refresh clears the session — no long-lived secret sits in the clear.
Entitlements on the backend
What your plan unlocks is decided and enforced on our servers, never trusted from the app UI. Purchases are verified server-side against Google Play before any plan is granted.
API hardening
The API runs behind standard hardening: security headers, strict CORS, and rate limits — with tighter per-route limits on login and account-recovery endpoints to slow brute-force and enumeration.
Safe data handling
All database access is parameterized. We record the fact that a sensitive action happened for audit — never its secret contents. Encrypted backups are sealed on your phone with your passphrase, which we never receive.
No hidden monitoring
NexGuard never silently reads your messages, calls, contacts, microphone, camera or screen. Scam and link analysis run only on content you choose to paste in.
Our threat posture
What NexGuard will never do
The strongest privacy guarantee is the data we never touch. These aren’t settings you toggle off — they’re boundaries built into the product.
Shared responsibility
Using NexGuard responsibly
Security is a partnership. We build the product to be honest and private by design; a few things stay in your hands — because only you hold the keys.
Your responsibilities
Keep your device lock, credentials and recovery codes safe, and turn on two-factor. Because the vault is encrypted on your device, only you can open it — if you lose your device access and recovery codes, we cannot recover your vault contents for you.
For households & organizations
If you set NexGuard up for family members or a team, you remain responsible for configuring access, accounts, permissions and internal security practices appropriate to your people — including who can view a shared dashboard and how accounts are managed.
Lawful, appropriate use
You are responsible for using NexGuard lawfully and for determining whether your intended use is permitted in your jurisdiction. See our Acceptable Use Policy. Information here is about the product — it is not legal or compliance advice.
We never handle your card
NexGuard doesn’t process or store payment cards. Paid plans are purchased through Google Play, which handles the sensitive payment information end to end. Our backend only receives a purchase token, which it verifies with Google before unlocking a plan.
Security FAQ
Straight answers about your data
Can Nexonix staff read my vault?
Do you use my data to train AI models?
What data do you actually store on the server?
What happens to my data if I delete my account?
Do you claim to be “unhackable” or “military-grade”?
Get early access
Security is a habit, not a headline
That’s why NexGuard scores it, explains it, and keeps your data encrypted on your device. Get started free to try it.