Security
Where your information goes, and how it is protected
A plain account of how this website handles what you send, written from how it is actually built. It covers the site and its admin; systems we build for clients are agreed project by project.
What we collect
Only what you type into the contact form: your name and work email, and optionally your company, phone number, the service you are interested in, a budget range, a timeline and a description of the project. There are no analytics, advertising pixels or tracking cookies on this site.
Where it is stored
Enquiries are stored in a MongoDB Atlas database hosted on AWS in the Mumbai region (ap-south-1). The website itself runs on Vercel, and the images and video it shows are served through ImageKit.
Encryption
Every page and every form submission travels over HTTPS, and the connection between the website and the database is encrypted with TLS. MongoDB Atlas also encrypts the stored data on disk.
Who can see it
Only signed-in administrators can read enquiries. At the moment that is one person: the founder.
How the admin is protected
Passwords are never stored, only a bcrypt hash of them. A session is a signed token in an httpOnly cookie that scripts on the page cannot read, sent only over HTTPS, and it expires after 12 hours. Every admin request is checked twice: once before it reaches the application, and again by the code that handles it.
Protection against abuse
The contact form turns away automated submissions with a hidden field people never see, slows repeated submissions from a single address, and validates every field against a strict schema, so a submission can only ever write the fields listed above.
Uploads
Only administrators can upload files, and only images and mp4 or webm video up to 25 MB. Files are passed to ImageKit from the server, so the private key that authorises uploads never reaches a browser.
Keeping and deleting
Enquiries are kept for as long as they are relevant to a conversation with you, and deleted on request. Email us and it is removed.
Client projects
The code, infrastructure and documentation of anything we build belong to the client. How project data is handled is agreed in writing for each engagement, before any of it is shared.
What we do not claim yet
NxtFoldS does not currently hold security certifications such as ISO 27001 or SOC 2, and has not commissioned a third-party penetration test. When either changes, this page will say so, with dates.
Last reviewed: 14 September 2026