Trust
Security & architecture
DRAFT. Seth and Compliance must approve every line of this page before it is published.
Your FCI stays where it is
NexusIQ records pointers (where an evidence item lives, who owns it, when it was last confirmed) instead of collecting FCI files into the platform. [Seth/Compliance to confirm exact wording]
Separate customer tenants
Each customer’s data is isolated in its own tenant. [Seth to confirm technical wording]
What NexusIQ is not
| NexusIQ does | NexusIQ does not |
|---|---|
| Record pointers: where an evidence item lives, who owns it, when it was last confirmed. | Collect your FCI files into the platform. |
| Prepare the SPRS packet and hand it off to the Affirming Official. | Upload anything to SPRS. The customer uploads it themselves. |
| Help you organize and track your Level 1 work. | Be a certification or an assessor, or a guarantee of compliance. |
| Keep each customer’s data in its own tenant. [Seth to confirm technical wording] | Take CUI. It is not a place to upload CUI. |
Where things live
-
Your own systems
Email, laptops, shared drive, cloud storage, paper. FCI files stay here.
-
NexusIQ
Pointers: where proof lives, who owns it, when it was last confirmed.
-
The packet
Prepared by NexusIQ and handed off.
-
Your Affirming Official
Reviews it, uploads it to SPRS, and makes the annual affirmation.