Compliance & Data Privacy

Local-first evidence software designed to reduce data exposure.

Nexus Forensics products are built around a zero-cloud deployment model, visible-screen evidence preservation, and a compliance-oriented capture mode for investigators who need to avoid platform scraping. The software records and organizes what the authorized user can view, rather than scraping hidden platform data.

Zero vendor custody of evidence data Policy-gated visible-capture workflows Encrypted repositories and retention controls

Privacy Architecture

A closed-loop model for sensitive investigative material.

Nexus Forensics Inc. does not collect, process, host, or access the evidence analyzed by the software. The platform is designed so case data remains on the user's workstation or on infrastructure controlled by the client organization, and so captures are based on visible, user-selected content.

Zero-cloud evidence handling

Evidence files, local indexes, metadata, reports, and review material are handled locally or within a client-controlled private network, without vendor cloud persistence.

No vendor access

Nexus Forensics Inc. has no custody of investigative or consumer data analyzed by the software, reducing third-party data exposure and vendor access risk.

Encrypted local repositories

Captured media, databases, metadata, and local team indexes are designed to be encrypted at rest using AES-256 encryption.

Retention boundaries

User-configured retention utilities and audit logs support case file deletion cycles defined by the agency or organization operating the software.

Visible-screen capture

The software is designed to preserve what the authorized user can see on screen or in a selected local file. It is not designed to bypass platform controls, scrape hidden data, or access non-visible account content.

Nexus Social Recon Compliance

A visible-capture mode for platform ToS-conscious investigations.

The new Nexus Social Recon Compliance configuration is designed to make visible-screen capture the default evidence path. It uses a feature policy gate to allow low-risk preservation tools while disabling workflows that would scrape platform content, download media streams, or collect hidden structured data.

Green: allowed by default

Visible screenshots, visible screen recordings, manual platform navigation, local OCR on preserved evidence, and local report generation remain available as the core workflow.

Yellow: authorization required

Approved platform API use, local biometric or profiling analysis, and other sensitive workflows require documented authorization, scope, retention rules, and customer-controlled governance.

Red: disabled in compliance mode

Structured DOM scraping, hidden-window collection, bulk relationship capture, CDN/media download, network interception, live page automation, and non-visible platform data collection are blocked by policy.

Policy-gated actions

Restricted capture commands are checked before they run. If a workflow does not meet the visible-capture policy, the software returns a compliance-blocked result and points the investigator to the approved visible-capture replacement.

Visible-capture provenance

Selected-region captures can be paired with a local metadata record that notes the capture method, source URL, timestamp, SHA-256 hash, selected region, platform, and a provenance note confirming that no platform DOM, private API, cookies, hidden metadata, or media source URLs were queried for that artifact.

Compliance Control Website Position
Visible evidence preservation Investigators preserve what is visible on screen through screenshots, selected-region capture, and visible playback recording.
No platform scraping in compliance mode Automated DOM extraction, hidden account data collection, bulk relationship capture, and direct media-source downloads are disabled in the compliance configuration.
Local processing OCR, indexes, reports, manifests, hashes, and audit records are generated from already preserved local evidence artifacts.
Documented exceptions Higher-risk workflows require customer authorization, approved platform access where applicable, defined scope, retention rules, and customer-controlled review.

Canadian Alignment

Built to support PIPEDA privacy principles.

The local-first architecture is designed around data minimization, limiting collection, limiting use, limiting disclosure, limiting retention, and safeguards proportionate to sensitive evidence material.

PIPEDA Requirement Nexus Forensics Compliance Step
Principle 4: Limiting Collection Evidence data is recorded from visible, user-selected content and processed locally or on client-controlled infrastructure, reducing unnecessary vendor collection of investigative or personal information.
Principle 5: Limiting Use, Disclosure, and Retention Nexus Forensics does not transmit evidence to vendor cloud systems for processing. User-configured retention utilities support agency-defined case deletion cycles.
Principle 7: Safeguards Captured media, databases, metadata, and local indexes are designed to be encrypted at rest using AES-256 encryption on the workstation or private agency network.
Accountability support Audit logs, local case records, hashes, and controlled deployment boundaries help agencies document how evidence was stored, reviewed, retained, and protected.

United States Alignment

A privacy posture shaped for CCPA, CPRA, and state privacy laws.

The software does not use external public APIs or cloud databases to process evidence. With no external transmission of analyzed evidence to Nexus Forensics, the product is structured to avoid selling or sharing personal information for advertising or third-party data purposes.

CCPA / CPRA Requirement Nexus Forensics Compliance Step
Consumer data control and access rights Nexus Forensics does not host or control customer evidence data. Agencies retain custody of case data on their workstation or private infrastructure and manage access through their own policies.
No selling or sharing of personal information The software does not transmit analyzed evidence to Nexus Forensics for advertising, resale, cross-context behavioral advertising, or third-party data sharing.
Data minimization and purpose limitation Processing is limited to visible, user-selected evidence inside the investigative workflow controlled by the client organization, with no vendor cloud processing or unrelated secondary use by Nexus Forensics.
Sensitive personal information protection Local repositories, media, metadata, and indexes are designed for encrypted storage at rest and private-network deployment boundaries.
Automated analysis and profiling risk controls Face, image, and cross-case matching operate on locally preserved case material inside the client's local or agency-controlled environment rather than a public, centralized, or multi-tenant cloud database.

For organizations using shared analysis or image-matching workflows, Nexus Forensics supports local or private-network indexes controlled by the client agency. Team members can match faces or case images previously preserved from visible, authorized case material inside their own organization without connecting to a centralized, public, or multi-tenant cloud database.

This keeps cross-case analysis inside the agency's defined access boundaries, infrastructure, and retention rules.

Deployment boundary

Shared indexing is an enterprise-controlled, localized database model hosted on the client agency's secure internal network infrastructure.

Compliance Matrix

Key requirements mapped to technical implementation.

This matrix summarizes the privacy and security controls described in the Nexus Forensics compliance position paper.

Regulatory Requirement Nexus Forensics Technical Implementation Status
Data minimization and sovereign control Zero cloud dependencies. Visible, user-selected evidence is processed, indexed, and stored on the client's local host or private agency network. Compliant by design
Data security and protection Repository data and local team indexes are encrypted at rest using AES-256 encryption. Compliant
Retention boundaries Built-in audit logs and user-configured case file deletion cycles support agency-defined retention schedules. Compliant
Third-party data risk No external evidence telemetry, no vendor cloud persistence, no scraping of hidden platform data, and no vendor custody of analyzed evidence data. Zero vendor custody

Position Summary

Evidence control stays with the organization responsible for the case.

By enforcing local or on-premise storage, encryption, configurable retention schedules, and a strict zero-cloud evidence footprint, Nexus Forensics helps legal and investigative professionals reduce the data liabilities normally associated with forensic and analysis software.

Need compliance details for procurement or review?

Contact Nexus Forensics for product-specific privacy, security, deployment, and data access documentation.

Contact sales