Skip to main content

Security features of the Nexam platform

Nexam includes essential mechanisms to ensure the confidentiality, security, and reliability of your evaluation environment.

Updated over 2 weeks ago

Cloud-based SaaS solution

Nexam is an online platform offered as a SaaS (Software as a Service) solution. It requires no installation or programming and is continuously updated through regular feature releases, made available to all clients according to a planned development schedule.

Access control and authentication

User permissions are managed according to assigned roles. Secure access to the platform includes:

  • Turnstile verification to confirm human interaction

  • TLS 1.3 encryption protocol to ensure data confidentiality and integrity

  • Two-factor authentication (2FA) for high-privilege accounts

  • OAuth 2.0 login support for Google and Microsoft accounts

Session and connection protection

User sessions are automatically disconnected after seven days of inactivity. Upon logout or session expiration, the session token is invalidated, preventing access through the browser’s back button.

Data hosting and security

Data is primarily hosted in Canada. Regular backups are performed, and an automated data deletion schedule is enforced depending on the data type. The platform also includes protections against DoS and DDoS attacks.

Nexam follows a strict incident management process and applies its information security policy in accordance with ISO/IEC 27001:2022 certification.

Logging and monitoring

All user actions, events, and navigation behaviours are logged. These logs can be viewed and downloaded by authorized administrators.

Real-time interface updates

The user interface refreshes automatically when changes are made to the structure of an evaluation, session settings, copy status, or exam duration.

Did this answer your question?