EU-hosted · Built in NL · Audited by CI-Audit

Boring infrastructure.
Quiet trust.

NEXERA PXM runs on European infrastructure, designed and operated in the Netherlands. Strict tenant isolation at the database row level. Audited annually by CI-Audit. Governed by DEED. Used by serious retailers running serious catalogs.

Audited by CI-Audit
Governed by DEED Vision · Herten, NL
Data residency European Union · only
Trusted by Retailers running 12k+ SKUs

Operating across the Netherlands, Germany, France and the UK on production catalogs

Kampeerwinkel Rehall NORTHWAVE Stoer Outdoor Boréal /ATLAS
How trust is built

Five things we did
on day one,
so you don't have to ask.

01

European hosting · only

All product data, assets and AI logs live on European infrastructure. PostgreSQL clusters in EU-Central. Cloudflare R2 buckets pinned to EU regions. Never replicated outside the EU, ever, not for analytics, not for backups, not for support.

  • Database Postgres 16 · EU-Central
  • Object storage Cloudflare R2 · EU region pinning
  • CDN edge Amsterdam · Frankfurt · Paris · London
02

Row-level tenant isolation

Multi-tenancy that isn't a polite suggestion. Every row in 109 database tables carries a tenant_id with a PostgreSQL Row-Level Security policy enforced at the database layer. The application layer can't bypass it, only a narrowly-scoped admin client can, and only for auth.

  • 40+ RLS policies across the schema
  • Dual Prisma client RLS-bound by default
  • SET app.current_tenant_id before every request
03

Authentication you can't replay

Passwordless OTP login. JWT access tokens expire in 15 minutes. Refresh tokens rotate; if an old one is reused, the entire family is revoked and the user is logged out everywhere. Tokens hashed with SHA-256, never stored in plaintext.

  • JWT 15-minute access, 7-day refresh, rotated
  • Family-based theft detection, reuse = revoke
  • API keys bcrypt-hashed, 8-char prefix lookup
04

Audit every destructive thing

Every create, update, delete, role change, module toggle, plan change, import, export, sync, and impersonation event lands in the audit log. Filterable by user, action, date range. Exportable on demand. Kept for the lifetime of the tenant.

  • 14 action types tracked end-to-end
  • Filterable per-user, per-action, per-window
  • Exportable CSV / JSON on request
05

Secrets out of code · always

Shopify access tokens encrypted at rest. Webhook payloads verified by HMAC against per-store secrets. Claude calls go through a circuit breaker. Sentry catches errors with PII scrubbing. Health endpoints are public, detailed health is SUPER_ADMIN only.

  • HMAC-verified Shopify webhooks · per-store secret
  • Encrypted Shopify tokens · at-rest
  • Circuit breakers on Claude & Shopify API
06

Roles & least privilege

Eight roles from SUPER_ADMIN down to VIEWER plus supplier-side roles. Module-gated features, tenants only see modules their plan enables. Permission matrix enforced at the API layer; SUPER_ADMIN impersonation always emits an audit event.

  • 8 roles + supplier portal subset
  • Module gates tenant-level on/off
  • Impersonation audited start & end
Hosted & designed in Europe

Your data crosses
fewer borders
than you do.

NEXERA PXM is operated from the Netherlands, on EU infrastructure. We do not replicate, mirror or back up customer data outside the European Union. Period. The team building it is in Herten; the auditor signing off is CI-Audit; the legal entity is DEED B.V.

NLEngineering, operations, support
EU-CentralPostgres clusters, R2 buckets
AMS · FRA · CDG · LONCDN edges
0data leaves the EU
Audit & governance

Audited by CI-Audit.
Governed by DEED.

NEXERA undergoes annual security audits with CI-Audit covering tenant isolation, authentication, key management and data residency. DEED Vision, the studio that designed and built NEXERA, governs the platform's roadmap, security posture and incident response.

Audit partner

CI-Audit

Annual penetration test and code review against the OWASP Application Security Verification Standard. Findings tracked to closure in a public-to-customers register. Latest report available on request under NDA.

Annual external pen-test
Source-code security review
OWASP ASVS-aligned
Public closure register
Operator & governance

DEED Vision

Designed, built and operated by DEED Vision, a Dutch studio based in Herten. The same team that ships features handles incident response. Roadmap and security posture governed by DEED leadership.

Boven de Wolfskuil 20, 6049 LZ Herten
KVK · 73419583
One ops team · 24-hour incident response
Engineering & security · same room
A request, end to end

Every call passes
through these checks.

A signed-in user clicks "update product." Here is everything that happens before a single row gets written.

01EdgeHTTPS, HSTS, CDN cache
02JWT verifySignature, expiry, family
03Rate limitPer-user · per-route
04Tenant contextSET app.current_tenant_id
05Module gatePlan-level access check
06RBAC8 roles · permission matrix
07ValidationZod schema · type-strict
08RLS-bound DBPostgres enforces isolation
09Audit logAction recorded · forever
10SnapshotPre-change version stored
11WebSocket emitTenant-scoped event
12Response200 OK · < 80 ms
Compliance & documents

Things you can ask for.
We have them.

In effect

GDPR

Operator and processor under EU 2016/679. Standard Contractual Clauses where needed; DEED is the data controller for marketing and processor for tenant content.

Privacy notice ↓
In effect

DPA · Data Processing Agreement

Standard DPA covering processing purposes, sub-processors, retention, deletion, and the audit clause. Custom DPAs on Enterprise.

Download template ↓
In effect

CI-Audit annual review

External penetration test and source-code review. Findings tracked in our customer-visible register. Latest letter from CI-Audit on request under NDA.

Request audit letter →
In progress

SOC 2 Type II

Type II report covering Security, Availability and Confidentiality. Observation period started Q1 2026. Letter of intent available; full report mid-2026.

Roadmap status →
In progress

ISO 27001

ISMS scope drafted around platform engineering and operations. Internal audit complete; external certification scheduled for late 2026.

Roadmap status →
In effect

Subprocessors list

Current sub-processors: Cloudflare (R2 + edge), Anthropic (Claude), Stripe (billing), Resend (email), Sentry (errors). Versioned and dated.

Subprocessor register →

We picked NEXERA over an enterprise PIM because they didn't need an architect to explain how isolation worked. The Dutch ops team is in the same Slack channel as us, and a sub-€100/month tier doesn't make us a rounding error.

Operations Lead Multi-brand outdoor retailer · NL · 12k SKUs
When something goes wrong

Disclosure within
72 hours.
By the people
who built it.

Material incidents are disclosed to affected tenants within 72 hours of confirmation. The same engineers who shipped the affected feature handle response. No offshore Tier-1 triage queue. No incident-management PR firm.

A redacted post-mortem is published to the customer-visible status site, with the underlying root cause, timeline, and the change shipped to prevent recurrence. Severe incidents trigger a written letter from DEED leadership.

72hdisclosure SLA · material incidents
24hfirst response SLA · all severity
NLresponse team timezone

A serious platform.
For serious catalogs.

Want the audit letter, the DPA template, the subprocessors list, or a chat with the operator about tenancy? Send a note, same team responds within a working day.