Brand logo of nubesti
  • Home
  • AI Red Team
    • Autonomous Agents

      After KYC and authorization, agents can run scheduled assessments on assets you designate.

    • MITRE ATT&CK mapping

      Testing workflows mapped to MITRE ATT&CK techniques. Mapping is not a claim that every technique ran.

    • OWASP mapping

      Checks mapped to OWASP risk classes, with evidence a reviewer can accept or reject.

    • Integration

      Connect seamlessly with your existing tools and workflows.

    Experience AI Red Team Testing

    See how our autonomous AI agents identify vulnerabilities in your systems.

    Book a Demo
  • Resources
    • Trust Center
    • Methodology
    • Pricing
    • FAQ
    • Blog
  • Contact
    • french
    • spanish
    • portuguese
  • Sign in
  • french
  • spanish
  • portuguese
Sign in
  1. Home
  2. /
  3. Legal
  4. /
  5. Security Overview

Security Overview

How Nubesti approaches platform security, access control, data protection, and vulnerability reporting.

Last updated: September 21, 2026

Nubesti

1111B S Governors Ave STE 23840
Dover, DE 19904, USA

[email protected]

On this page

  1. 1. Our commitment
  2. 2. Infrastructure
  3. 3. Application and product security
  4. 4. Customer responsibilities
  5. 5. Backups and resilience
  6. 6. Vulnerability disclosure
  7. 7. Compliance posture
  8. 8. Contact

Security is the product. This overview describes how Nubesti LLC protects the platform and the data entrusted to us. It is not a substitute for a customer’s own security program.

1. Our commitment

We design the platform so that authorized testing of your systems does not become unauthorized access to anyone else’s. Tenant isolation, least privilege, and auditability are baseline requirements.

2. Infrastructure

  • Production web properties are served through Cloudflare with TLS 1.2+ and modern security headers
  • Data in transit is encrypted with TLS
  • Data at rest is encrypted using industry-standard algorithms (AES-256 where we control the store)
  • Administrative access uses unique identities and multi-factor authentication

3. Application and product security

  • Secure development practices, code review, and dependency monitoring
  • Role-based access in the product so you can limit who launches tests or sees reports
  • Logging of security-relevant events for investigation
  • Separation between marketing site, application, and customer-designated targets

4. Customer responsibilities

You must keep portal credentials safe, authorize only in-scope assets, configure integrations carefully, and treat findings as confidential. You decide what evidence leaves the platform.

5. Backups and resilience

We maintain backups of platform configuration and customer workspace data sufficient to recover from infrastructure failure. Backup copies are access-restricted and retained for a limited rotation period.

6. Vulnerability disclosure

Report issues in Nubesti systems (not customer targets) under the dedicated Vulnerability Disclosure Policy. Email [email protected]. We aim to acknowledge within 24 hours. The canonical researcher file is /.well-known/security.txt.

7. Compliance posture

We align controls with common enterprise expectations (including GDPR/CCPA handling described in the Privacy Policy and DPA). Formal certifications may be provided to enterprise customers under NDA when available.

8. Contact

[email protected] · [email protected]

Back to legal center ↗

Brand logo of nubesti

Nubesti LLC provides continuous autonomous security testing against customer-authorized assets. Tests require paid KYC.

  • linkedin

Product

  • Platform
  • Methodology
  • Pricing
  • Demo

Trust

  • Trust Center
  • Platform security
  • Customers
  • Vulnerability disclosure

Legal

  • Legal center
  • Privacy
  • DPA
  • Subprocessors
  • Legal notice
  • About
  • Legal
  • Privacy Policy
  • Legal Notice
  • © 2026 Nubesti LLC
  • All rights reserved