1. Nature of this page
This page is a general, informational overview of controls in place or designed into the Service as of the date above. Some controls depend on the features enabled and on Customer configuration. It does not create any warranty, representation, or contractual obligation. A signed agreement or security addendum controls where applicable. CultureNest may change its controls at any time, provided changes are consistent with any signed commitments.
2. Current approach (design and current controls)
- Invitation-only access with no public self-registration.
- Role-based permissions, with organization data separated by row-level authorization rules enforced in the database.
- Deny-by-default access design for sensitive modules such as Benefits, with restricted fields returned only through server-side projections.
- Audit logging of many security-relevant and administrative actions, and access logging for certain restricted benefits information.
- Private storage for benefits documents, accessed through server-side authorization and short-lived links.
- Encrypted transport (HTTPS) for connections to the Service.
- Least-privilege principles for operational access.
3. Shared responsibility
Security is shared. Customers and users are responsible for managing user access and roles, promptly removing departed personnel, protecting credentials and devices, using available security controls, configuring integrations appropriately, submitting only authorized data, reviewing exports before sharing them, and reporting suspected incidents promptly.
4. No guarantee; no certification
No system is completely secure. CultureNest does not claim that the Service is free of vulnerabilities or that incidents will never occur, and does not claim any third-party security certification or attestation.
5. Reporting a vulnerability or incident
Email hello@culturenest.io with a description, reproduction steps, and supporting information. Please do not access, modify, or retain data that is not yours; degrade the Service; use social engineering or physical attacks; or test beyond your own accounts, and please allow a reasonable time to remediate before any disclosure. CultureNest appreciates good-faith reports and will consider a reporter’s good faith and adherence to these guidelines in deciding how to respond. This page does not authorize any testing or access, does not grant immunity or a release, and does not waive any right or remedy of CultureNest or any third party.
