Security
RegNexus Lumen is built by RegNexus, whose software serves regulated financial firms — so security isn’t a page on the website, it’s the way the platform is engineered.
Data is encrypted in transit (TLS) and at rest. Credentials are never stored in plain text.
Every record belongs to one organisation, enforced at the database layer with Row-Level Security — not just in application code.
Owners, admins, teachers and students each see exactly what their role allows. Permissions are enforced on every request.
Learning records, receipts and audit logs are hash-chained (SHA-256) and immutable — no silent edits, no silent deletions.
Significant actions are logged with actor, timestamp and context, and the log itself is verifiable.
Hosted on Supabase (SOC 2 Type II) and Vercel, with the primary database in the EU (eu-west-2, London).
Independently verifiable
Every learning record in RegNexus Lumen is sealed into a hash chain as it is created: each record carries a SHA-256 fingerprint of itself and the record before it. Change anything, anywhere, and the chain breaks visibly. Public verification pages let a parent, employer or inspector confirm a record’s integrity from a link — no account required.
record 47 of 47 · chain intact · sealed 2026-08-07T19:02:11Z
Write to security@reg-nexus.com — security reports are read first and answered fast. Our privacy notice and data processing agreement cover the rest.