Security

How we protect this site

As a cyber security training provider, we hold this site to the standards we teach.

Transport & headers

HTTPS enforced via HSTS, with a strict Content-Security-Policy, X-Frame-Options and related headers set on every response.

Application hardening

Parameterised database queries, CSRF tokens on every form, server-side validation, and rate limiting on public endpoints.

Session & access control

HttpOnly, Secure, SameSite session cookies with periodic rotation, and least-privilege service accounts for OTRS, billing and SugarCRM integrations.

Found a vulnerability? Please report it responsibly to info@neximsolutions.com rather than disclosing it publicly. We'll acknowledge reports promptly.