Data Security Protocols | Nexus
Security Protocols Last Updated: August 4, 2026

Data Security Protocols

Courseflow Inc., also known as Nexus AI, and based in Knoxville, TN, is committed to the data security of our products. This document outlines the security measures and protocols in place to protect the integrity, confidentiality, and availability of user and student data managed by Nexus, a product of Courseflow, Inc.

1. Data Encryption

  • In Transit: All data transmitted between Nexus clients and servers is encrypted using TLS 1.2 or higher, ensuring that data remains secure and private during transmission. This protects your data as it moves between Microsoft Azure services and users.
  • At Rest: Data is protected at rest using Transparent Data Encryption (TDE) in Microsoft Azure SQL Database, which encrypts and decrypts databases, associated backups, and transaction log files in real-time. Microsoft also provides standard AES-256 encryption for all file storage with Storage Accounts. Both services are protected by a firewall which blocks unauthorized access.
  • Key Management: Azure Key Vault is used to manage and control sensitive information including client credentials or API keys. This service allows for key rotation, setting permissions, and logging key usage for auditing purposes.
In Transit
TLS 1.2 or higher
At Rest
TDE (Azure SQL) + AES-256
Key Management
Azure Key Vault, with rotation

2. Access Controls

  • Authentication: Nexus enforces strong password policies and utilizes multi-factor authentication (MFA) for accessing any sensitive systems or data repositories. Nexus also supports single sign-on (SSO) integrations, allowing users to authenticate using existing credentials from trusted providers like Google Workspace and Microsoft Entra ID (formerly Azure Active Directory). This ensures seamless and secure access for organizations leveraging third-party identity providers.
  • Authorization: Role-based access control (RBAC) is employed to ensure that users are granted access only to data necessary for their role. Access permissions are regularly reviewed and adjusted in response to role changes.
  • Audit Trails: All access to sensitive data is logged and monitored. Regular audits are conducted to ensure compliance with our security policies and procedures.

3. Network Security

  • Firewalls
    • Azure Firewall: A managed, cloud-based network security service that protects Azure Virtual Network resources. It's a stateful firewall as a service with built-in high availability and unrestricted cloud scalability.
    • Application Gateway Web Application Firewall (WAF): Provides centralized, inbound protection against common web vulnerabilities and exploits. It operates at Layer 7 (HTTP/HTTPS layer) and is designed to integrate with Azure's load balancing features.
  • Network Security Groups (NSGs): NSGs are used to filter network traffic to and from Azure resources in an Azure Virtual Network. They can contain multiple inbound and outbound security rules that enable filtering traffic by source and destination IP address, port, and protocol.
  • Virtual Network (VNet) Peering: Securely connects Azure virtual networks to each other. It allows traffic to be routed directly between VNets via Microsoft's backbone infrastructure, avoiding public internet exposure.
  • VPN Gateway: For secure connections from on-prem networks to the Azure environment, Azure VPN Gateway enables encrypted traffic movement. It supports industry-standard protocols like IKEv2 and SSTP.

4. Compliance

  • Regulatory Compliance: Nexus supports districts' obligations under the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA). Nexus acts as a school official under FERPA's school official exception (34 CFR 99.31(a)(1)), accessing education records only to perform the services the district has authorized and only under the district's direction.
  • Standards Compliance: Nexus's security program is designed and operated in alignment with recognized industry frameworks, including ISO 27001 and SOC 2. Our internal processes and security controls are structured around the requirements these standards define and are maintained through rigorous, ongoing internal review. Nexus also conforms to the Ed-Fi Data Standard v4.0 and Ed-Fi ODS / API Suite 3 as a registered Ed-Fi API Consumer.

5. Incident Response

  • Detection and Analysis: We utilize advanced monitoring tools to detect anomalies and potential security incidents.
  • Response and Mitigation: In the event of a security breach, our incident response team is mobilized to contain and mitigate the impact, following a well-defined incident response plan.
  • Notification: Affected districts are notified without undue delay in accordance with legal obligations, the terms of the applicable district agreement, and our commitment to transparency. We cooperate with districts in meeting their own notification obligations.

6. Data Integrity

  • Data Accuracy: Nexus implements checks and balances such as checksums and data validation techniques to ensure the accuracy and consistency of stored data.
  • Backup and Recovery: Automated backups are performed continuously and support point-in-time restore, with backup storage replicated across Microsoft Azure infrastructure for recoverability in case of disaster.

7. End-User Security

  • Security Best Practices: Users are educated on best practices for data security, including the creation of strong, unique passwords and recognizing phishing attempts. Nexus also enforces minimum password requirements based on the NIST Authenticator and Verifier Requirements (NIST SP 800-63B).
  • Secure Settings: Recommendations are provided for securing user devices and browsers when accessing Nexus.

8. Conclusion

Courseflow, Inc. is committed to the security of all data entrusted to us by our users and their institutions. We continuously improve our security measures to address emerging threats and ensure that our products remain a safe, reliable platform for educational data management. For questions or concerns about our privacy practices, please contact us at support@asknexus.ai.

Courseflow Inc, dba Nexus AI
900 South Gay Street, Suite 1904, Knoxville, TN 37902
support@asknexus.ai