Zero-cloud evidence handling
Evidence files, local indexes, metadata, reports, and review material are handled locally or within a client-controlled private network, without vendor cloud persistence.
Compliance & Data Privacy
Nexus Forensics products are built around a zero-cloud deployment model, visible-screen evidence preservation, and a compliance-oriented capture mode for investigators who need to avoid platform scraping. The software records and organizes what the authorized user can view, rather than scraping hidden platform data.
Privacy Architecture
Nexus Forensics Inc. does not collect, process, host, or access the evidence analyzed by the software. The platform is designed so case data remains on the user's workstation or on infrastructure controlled by the client organization, and so captures are based on visible, user-selected content.
Evidence files, local indexes, metadata, reports, and review material are handled locally or within a client-controlled private network, without vendor cloud persistence.
Nexus Forensics Inc. has no custody of investigative or consumer data analyzed by the software, reducing third-party data exposure and vendor access risk.
Captured media, databases, metadata, and local team indexes are designed to be encrypted at rest using AES-256 encryption.
User-configured retention utilities and audit logs support case file deletion cycles defined by the agency or organization operating the software.
The software is designed to preserve what the authorized user can see on screen or in a selected local file. It is not designed to bypass platform controls, scrape hidden data, or access non-visible account content.
Nexus Social Recon Compliance
The new Nexus Social Recon Compliance configuration is designed to make visible-screen capture the default evidence path. It uses a feature policy gate to allow low-risk preservation tools while disabling workflows that would scrape platform content, download media streams, or collect hidden structured data.
Visible screenshots, visible screen recordings, manual platform navigation, local OCR on preserved evidence, and local report generation remain available as the core workflow.
Approved platform API use, local biometric or profiling analysis, and other sensitive workflows require documented authorization, scope, retention rules, and customer-controlled governance.
Structured DOM scraping, hidden-window collection, bulk relationship capture, CDN/media download, network interception, live page automation, and non-visible platform data collection are blocked by policy.
Restricted capture commands are checked before they run. If a workflow does not meet the visible-capture policy, the software returns a compliance-blocked result and points the investigator to the approved visible-capture replacement.
Selected-region captures can be paired with a local metadata record that notes the capture method, source URL, timestamp, SHA-256 hash, selected region, platform, and a provenance note confirming that no platform DOM, private API, cookies, hidden metadata, or media source URLs were queried for that artifact.
| Compliance Control | Website Position |
|---|---|
| Visible evidence preservation | Investigators preserve what is visible on screen through screenshots, selected-region capture, and visible playback recording. |
| No platform scraping in compliance mode | Automated DOM extraction, hidden account data collection, bulk relationship capture, and direct media-source downloads are disabled in the compliance configuration. |
| Local processing | OCR, indexes, reports, manifests, hashes, and audit records are generated from already preserved local evidence artifacts. |
| Documented exceptions | Higher-risk workflows require customer authorization, approved platform access where applicable, defined scope, retention rules, and customer-controlled review. |
Canadian Alignment
The local-first architecture is designed around data minimization, limiting collection, limiting use, limiting disclosure, limiting retention, and safeguards proportionate to sensitive evidence material.
PIPEDA means the Personal Information Protection and Electronic Documents Act, Canada's federal private-sector privacy law. Learn more from the Office of the Privacy Commissioner of Canada.
| PIPEDA Requirement | Nexus Forensics Compliance Step |
|---|---|
| Principle 4: Limiting Collection | Evidence data is recorded from visible, user-selected content and processed locally or on client-controlled infrastructure, reducing unnecessary vendor collection of investigative or personal information. |
| Principle 5: Limiting Use, Disclosure, and Retention | Nexus Forensics does not transmit evidence to vendor cloud systems for processing. User-configured retention utilities support agency-defined case deletion cycles. |
| Principle 7: Safeguards | Captured media, databases, metadata, and local indexes are designed to be encrypted at rest using AES-256 encryption on the workstation or private agency network. |
| Accountability support | Audit logs, local case records, hashes, and controlled deployment boundaries help agencies document how evidence was stored, reviewed, retained, and protected. |
United States Alignment
The software does not use external public APIs or cloud databases to process evidence. With no external transmission of analyzed evidence to Nexus Forensics, the product is structured to avoid selling or sharing personal information for advertising or third-party data purposes.
CCPA means the California Consumer Privacy Act, which gives California residents rights over personal information collected by covered businesses. CPRA means the California Privacy Rights Act, which amended and expanded California's privacy framework. Learn more from the California Attorney General and the California Privacy Protection Agency.
| CCPA / CPRA Requirement | Nexus Forensics Compliance Step |
|---|---|
| Consumer data control and access rights | Nexus Forensics does not host or control customer evidence data. Agencies retain custody of case data on their workstation or private infrastructure and manage access through their own policies. |
| No selling or sharing of personal information | The software does not transmit analyzed evidence to Nexus Forensics for advertising, resale, cross-context behavioral advertising, or third-party data sharing. |
| Data minimization and purpose limitation | Processing is limited to visible, user-selected evidence inside the investigative workflow controlled by the client organization, with no vendor cloud processing or unrelated secondary use by Nexus Forensics. |
| Sensitive personal information protection | Local repositories, media, metadata, and indexes are designed for encrypted storage at rest and private-network deployment boundaries. |
| Automated analysis and profiling risk controls | Face, image, and cross-case matching operate on locally preserved case material inside the client's local or agency-controlled environment rather than a public, centralized, or multi-tenant cloud database. |
For organizations using shared analysis or image-matching workflows, Nexus Forensics supports local or private-network indexes controlled by the client agency. Team members can match faces or case images previously preserved from visible, authorized case material inside their own organization without connecting to a centralized, public, or multi-tenant cloud database.
This keeps cross-case analysis inside the agency's defined access boundaries, infrastructure, and retention rules.
Shared indexing is an enterprise-controlled, localized database model hosted on the client agency's secure internal network infrastructure.
Compliance Matrix
This matrix summarizes the privacy and security controls described in the Nexus Forensics compliance position paper.
| Regulatory Requirement | Nexus Forensics Technical Implementation | Status |
|---|---|---|
| Data minimization and sovereign control | Zero cloud dependencies. Visible, user-selected evidence is processed, indexed, and stored on the client's local host or private agency network. | Compliant by design |
| Data security and protection | Repository data and local team indexes are encrypted at rest using AES-256 encryption. | Compliant |
| Retention boundaries | Built-in audit logs and user-configured case file deletion cycles support agency-defined retention schedules. | Compliant |
| Third-party data risk | No external evidence telemetry, no vendor cloud persistence, no scraping of hidden platform data, and no vendor custody of analyzed evidence data. | Zero vendor custody |
Position Summary
By enforcing local or on-premise storage, encryption, configurable retention schedules, and a strict zero-cloud evidence footprint, Nexus Forensics helps legal and investigative professionals reduce the data liabilities normally associated with forensic and analysis software.
Contact Nexus Forensics for product-specific privacy, security, deployment, and data access documentation.