Security
Real data. Real protections.
Nexus runs on real consumer answers and real client information — not synthetic panels. Every layer that touches that data, from infrastructure to access to offboarding, is built to protect it, not added on afterward.


Backed by
Foundation
Built in, not bolted on.
Infrastructure, access control, and data privacy work as one system — not three separate policies stitched together after the fact.
Secure infrastructure
Nexus runs on Google Cloud, with encryption applied by default to data in transit and at rest. Production is isolated from other environments, and access to it is limited to the engineers who need it.
Encrypted data, in transit and at rest
Isolated production environment
Continuously monitored infrastructure
End to end encryption
Consumer and client data is encrypted at rest and in transit by default, on Google Cloud's standard encryption model — no configuration required on your end.
Isolated by design
Production runs separately from development and staging. Cloud Armor and Secret Manager protect the perimeter and credentials.
Ongoing monitoring
Infrastructure is monitored on an ongoing basis, with logging in place to support investigation if something looks wrong.
Product and access security
Access to Nexus is invitation-only — there's no open signup. Every account is scoped to a workspace, and every workspace is scoped to a company, so what one client's team sees never crosses into another's.
Invitation-only access, no self-serve signup
Role-based permissions, per workspace
Per-company data isolation, even for shared users
Role-based access
Permissions are scoped by role and by workspace, so teams see the studies and data relevant to them — and nothing else.
Workspace isolation
Each company's data is isolated at the workspace level. Users who work across multiple client accounts — agency teams, for example — only ever see the workspace they're currently in.
Audited administrative access
When Galaxies support needs to view an account to help with an issue, that access is read-only, time-limited, and logged, with the acting admin identified on every action.
Privacy and compliance
Data handling follows LGPD requirements by default, and Galaxies is ISO 27001 certified — audited by an independent third party against the standard's full set of controls.
LGPD-aligned data handling, by default
ISO 27001 certified
Deactivation, not silent deletion, on offboarding
LGPD by default
Consumer and client data is handled under LGPD requirements as the baseline — not an exception made for Brazilian clients.
ISO 27001 certified
Galaxies holds ISO 27001 certification, verified by an independent third party against the standard's controls for information security management.
Clear offboarding
When an account is deactivated, access is revoked immediately. Data isn't silently deleted — offboarding follows a defined process, in line with LGPD.
FAQ
Security questions answered
The specifics on how consumer and client data is handled, stored, and accessed.
How is consumer and client data handled?
Who inside Galaxies can see our data?
Is our data encrypted?
Is Galaxies certified against any security standard?
What happens to our data if we offboard?
We work with multiple clients — can our team see across their accounts?




