A security model where the customer holds the keys
Nexus inverts the SaaS trust model. Because the platform runs inside your tenant, your existing Azure governance, identity, and network controls apply directly to it.
Deployment architecture
Nexus is an Azure Marketplace managed application. The application tier (Azure Container Apps), database, storage account, and Key Vault are provisioned into a resource group inside your own subscription.
Customer-owned infrastructure
Every Nexus resource lives in your subscription and resource group. You own and operate the entire stack.
Data flow
Customer business data is read, transformed, and stored entirely within your tenant. It does not transit or persist on Stingray-owned infrastructure.
What Stingray can and cannot access
Stingray publishes signed image updates through the managed-application contract. Stingray has no standing access to your data plane, database, or Key Vault.
Azure Key Vault
All secrets and encryption keys are stored in the Key Vault in your tenant, accessed by Nexus through Azure managed identity. Stingray has no access to them.
Customer-controlled secrets
Connector credentials, tokens, and keys are managed and rotated by you, on your own schedule. Secret values are never returned through the API or written to logs.
Authentication
Users sign in through Microsoft Entra ID (OAuth2 with PKCE), with support for conditional access. Automation uses API keys or client-credentials applications.
Role-based access control
Granular RBAC governs every adapter, query, pipeline, report, and admin action, with per-resource scoped grants and execution roles for least-privilege automation.
Audit logging
Append-only audit logs and version-controlled authoring history are retained within your tenant for review.
Network boundaries
Outbound traffic is checked against a default-deny egress allowlist, and your private endpoints and network controls apply directly to the deployment.
Backup & retention
Backups, retention, and disaster recovery follow the policies you configure on the Azure resources in your own subscription.
Incident response
Report suspected security issues to support@stingraytechnologysolutions.com. Fixes are delivered as signed image updates that you pull on your own schedule.
Data residency
Because data never leaves your tenant, residency is defined entirely by your Azure region and policy.
Compliance
Nexus runs inside your tenant, so it inherits your existing Azure compliance controls and data-residency posture. Contact us for our current certification status.
Deploy Nexus into your own tenant
Your governance, identity, and network controls apply from the first deployment.