Nexus
Security

A security model where the customer holds the keys

Nexus inverts the SaaS trust model. Because the platform runs inside your tenant, your existing Azure governance, identity, and network controls apply directly to it.

ERPSQLSaaSReportsPipelinesAgents Nexus governed layer

Deployment architecture

Nexus is an Azure Marketplace managed application. The application tier (Azure Container Apps), database, storage account, and Key Vault are provisioned into a resource group inside your own subscription.

Customer-owned infrastructure

Every Nexus resource lives in your subscription and resource group. You own and operate the entire stack.

Data flow

Customer business data is read, transformed, and stored entirely within your tenant. It does not transit or persist on Stingray-owned infrastructure.

What Stingray can and cannot access

Stingray publishes signed image updates through the managed-application contract. Stingray has no standing access to your data plane, database, or Key Vault.

Azure Key Vault

All secrets and encryption keys are stored in the Key Vault in your tenant, accessed by Nexus through Azure managed identity. Stingray has no access to them.

Customer-controlled secrets

Connector credentials, tokens, and keys are managed and rotated by you, on your own schedule. Secret values are never returned through the API or written to logs.

Authentication

Users sign in through Microsoft Entra ID (OAuth2 with PKCE), with support for conditional access. Automation uses API keys or client-credentials applications.

Role-based access control

Granular RBAC governs every adapter, query, pipeline, report, and admin action, with per-resource scoped grants and execution roles for least-privilege automation.

Audit logging

Append-only audit logs and version-controlled authoring history are retained within your tenant for review.

Network boundaries

Outbound traffic is checked against a default-deny egress allowlist, and your private endpoints and network controls apply directly to the deployment.

Backup & retention

Backups, retention, and disaster recovery follow the policies you configure on the Azure resources in your own subscription.

Incident response

Report suspected security issues to support@stingraytechnologysolutions.com. Fixes are delivered as signed image updates that you pull on your own schedule.

Data residency

Because data never leaves your tenant, residency is defined entirely by your Azure region and policy.

Compliance

Nexus runs inside your tenant, so it inherits your existing Azure compliance controls and data-residency posture. Contact us for our current certification status.

Deploy Nexus into your own tenant

Your governance, identity, and network controls apply from the first deployment.