Encrypted
Project files are protected in transit and at rest.
Project files are protected in transit and at rest.
Projects, drawings and generated data remain scoped to authorized workspaces.
Protected files use authorization controls and time-limited access mechanisms.
Customer project content is processed only through authorized workflows and is not sold or used for third-party advertising.
Construction drawings contain valuable intellectual property, commercial information, and project-sensitive data.
Clash Nexus AI is designed with security across the full lifecycle of your documents — from upload and storage through AI processing, review, findings, and report generation.
Your project data is isolated by workspace, access-controlled, encrypted, protected at the network and application layers, and monitored through our infrastructure and security systems.
Every project, drawing, finding, report, and related record is scoped to its authorized Clash Nexus AI workspace.
API requests are authenticated and checked against workspace access before protected resources are returned or modified.
File and project access is also validated against the requesting user's workspace so that one customer's drawings cannot be accessed through another customer's account or project.
Tenant boundaries are enforced in the application and data-access layers rather than relying only on what is displayed in the user interface.
Access to Clash Nexus AI requires authenticated user sessions.
Protected operations are authorized against the user's account, workspace membership, and applicable permissions.
Administrative and sensitive functions require elevated access, and users can access only the workspaces and projects they are authorized to use.
Authentication tokens and protected credentials are validated server-side before access to protected resources is granted.
Customer drawings and project files are stored using managed cloud object-storage infrastructure with encryption at rest.
Protected files are not exposed through public storage paths in production.
Access to drawings, reports, and other protected files is provided only after authorization checks and through controlled application or signed-URL mechanisms.
Data transmitted between users, Clash Nexus AI, and our infrastructure is protected using encrypted HTTPS/TLS connections.
Where signed URLs are used, access to protected drawings and reports is provided through short-lived URLs generated only after the requesting user and workspace have been authorized.
These links expire automatically.
File paths and project ownership are checked before access is granted, reducing the risk that a user could manipulate a file path to access another workspace's documents.
Uploads are validated server-side before they enter the Clash Nexus AI processing pipeline.
Controls include validation of supported document types, file characteristics, upload limits, and project ownership.
For supported PDF workflows, files are checked using their actual file content and signature rather than relying only on a filename extension.
Committed files are also verified against the authorized project and workspace location.
Malformed, unsupported, or out-of-scope uploads can be rejected before processing.
Clash Nexus AI uses Cloudflare as an additional security layer at the edge of the platform.
Cloudflare helps protect public-facing services before traffic reaches the application infrastructure and provides controls designed to reduce exposure to malicious or abnormal internet traffic.
Depending on the applicable service and configuration, this security layer can include protections against network attacks, abusive requests, malicious traffic patterns, and other common web threats.
This edge layer complements — rather than replaces — the authentication, authorization, validation, and application-level security controls within Clash Nexus AI.
Clash Nexus AI uses Amazon Web Services infrastructure for portions of its production platform and processing architecture.
AWS-managed infrastructure allows us to apply security controls across compute, storage, databases, networking, queues, credentials, and application services.
Our architecture is designed around controlled service access, private application resources where appropriate, encryption, authenticated service-to-service communication, and limited infrastructure permissions.
Production services are configured so that application components receive only the access required for their intended function rather than broad access across the platform.
Sensitive infrastructure credentials, API keys, database credentials, service secrets, and other protected configuration are kept outside of publicly accessible application code.
Production secrets are managed through protected environment and cloud-secret mechanisms and are made available only to the services that require them.
Credentials are not intentionally exposed to users through the frontend or included in public repositories.
Access to sensitive infrastructure configuration is restricted according to operational need.
Clash Nexus AI follows a least-privilege approach for both users and internal services.
Application services receive only the permissions they require to perform their assigned functions.
Sensitive administrative operations require elevated authorization.
Infrastructure, storage, database, and processing permissions are separated where practical so that compromise of one component does not automatically provide unrestricted access to the rest of the platform.
Production API access is restricted to authorized Clash Nexus AI origins.
We do not rely on unrestricted wildcard cross-origin access for credentialed production requests.
Requests originating from unauthorized web origins can be refused before protected application operations are performed.
Clash Nexus AI uses browser and HTTP security controls designed to reduce common web-application attack surfaces.
These include protections such as:
These protections help reduce exposure to threats such as clickjacking, content injection, MIME-type confusion, and unauthorized resource execution.
Security checks are performed server-side rather than relying only on frontend controls.
Protected operations validate authentication, workspace ownership, project relationships, file scope, and expected request data before sensitive actions are allowed.
This helps protect against manipulated client requests and attempts to bypass controls through direct API access.
Important platform and administrative actions are recorded to provide traceability across the system.
Depending on the operation, audit information may include:
Auditable events can include project and file activity, report operations, account or administrative actions, and other security-relevant events.
These records help us investigate unexpected activity and maintain accountability within the platform.
Clash Nexus AI continuously monitors the health and operation of its application and supporting infrastructure.
Application errors, service failures, processing failures, and other operational signals are captured so that our team can identify and investigate issues.
Cloud infrastructure monitoring also provides visibility into service health and operational conditions affecting production workloads.
Security is treated as an operational process rather than a one-time deployment task.
Security review also happens before changes reach customers.
Clash Nexus AI uses Snyk as part of its ongoing code-security process to identify known vulnerabilities and security risks within application dependencies and supported areas of the codebase.
Our engineering process includes repeated security scanning as the platform evolves rather than relying solely on a single security review before release.
Findings identified through security tooling are reviewed and addressed based on their severity, exploitability, and relevance to the production environment.
Automated security scanning complements — but does not replace — engineering review, testing, access controls, and infrastructure security.
Modern software depends on third-party libraries and packages, so application security also includes monitoring dependencies used by Clash Nexus AI.
Our security process includes reviewing dependencies for known vulnerabilities and updating, replacing, or remediating packages where appropriate.
This helps reduce risk from vulnerabilities introduced through the software supply chain.
Drawing information required to perform Clash Nexus AI analysis may be processed through authorized AI, OCR, document-processing, and cloud providers.
Only the information needed to perform the requested processing is sent through those workflows.
Customer drawings and project data are not sold or used for third-party advertising.
We use business/API processing arrangements for AI providers and do not authorize customer project content to be used to train general-purpose AI models except where expressly agreed with the customer.
Generated findings, drawing intelligence, reports, extracted information, and related project data remain associated with the authorized workspace.
Clash Nexus AI does not intentionally expose one customer's coordination information to another customer.
Workspace authorization continues to apply to generated data, not only to the original uploaded drawing.
We design operational monitoring to capture information needed to troubleshoot and secure the Service without unnecessarily exposing customer project content or personal information.
We avoid intentionally sending the substantive contents of customer construction drawings to general analytics systems.
Access to operational information is restricted to personnel and service providers who require it to operate, secure, or support the Service.
Security controls are reviewed as Clash Nexus AI evolves.
Our engineering process includes code review, automated vulnerability scanning, dependency review, infrastructure review, access-control testing, and remediation of identified security issues.
New integrations, infrastructure components, and major platform changes are evaluated for their effect on customer-data security.
We are also building our security and operational controls toward increasing enterprise and SOC 2 readiness as the platform grows.
We take security reports seriously.
If you believe you have discovered a vulnerability affecting Clash Nexus AI, please contact us at:
Please provide enough information for us to reproduce and investigate the issue.
We ask security researchers to avoid accessing, modifying, downloading, or destroying customer data and to provide us a reasonable opportunity to investigate and address reported vulnerabilities.
We continually work to strengthen Clash Nexus AI as the platform, infrastructure, and customer base grow.
Talk with our team about project data, integrations, access controls or enterprise requirements.
Clash Nexus AI is a product of Thelon Technologies Inc.
Registered in Ontario, Canada and Delaware, United States of America