Last updated: 13 May 2026Versiunea în română
This page is a draft of the Nodex legal text; final drafting is under legal review. The contractual final version will be published at V1.5 launch.
Security Practices
Note: Operational practices, NOT a binding contractual commitment (that lives in DPA Annex II).
Defense-in-depth. Summary (informational — the Romanian original controls):
- Encryption — TLS 1.3 in transit (nginx, Cloudflare, HSTS preload, strict CSP). AES-256 at rest (Supabase + R2 SSE). R2 Object Lock Indefinite for anti-malicious-deletion. Encrypted backups.
- Access controls — RLS in PostgreSQL + OrgScopeGuard defense-in-depth. Roles: owner / admin / member / accountant. Supabase Auth + ES256 JWT. Optional MFA (TOTP) on V1; passkey (WebAuthn) on V1.5 Pro+; default V2.
- Audit log — Append-only PostgreSQL trigger (UPDATE + DELETE blocked except for the retention cron). 19+ instrumented actions. 5-year retention per Law 82/1991 art. 25.
- Incident response — 72h breach notification to ANSPDCP (Art. 33); 48h to controllers. Quarterly tabletop (V1.5+). Responsible disclosure at security@nodera.studio, 5-business-day response.
- Payments — Stripe Payments Europe (PCI DSS Level 1). Nodex stores last 4 + brand + expiry only — never PAN/CVV.
- ANAF & e-Factura — V1.5 uses integrated cloud providers (certSIGN, DigiSign). V2+ adds cloud certificates (paperLESS) and hardware tokens (SafeNet) via the Tauri 2 desktop shell. Certificates encrypted at rest, never logged in cleartext.
- Monitoring — Pino structured logs + cron heartbeat. V1.5 uptime target 99.5% (not a contractual SLA). Daily backups, 30-day retention, 24h restore. DR active-passive Supabase Pro (RTO 4h, RPO 1h) at V1.5.
- Roadmap — SOC 2 Type I Q3 2027 → annual thereafter. ISO 27001 2028. Annual external pentest from V2. Bug bounty V3.
For the full canonical text, see the Romanian original.