Security, deployment and white label

Governed by design. Configured for each broker.

Keep broker audiences, permissions, data and operational evidence inside explicit boundaries, with deployment controls designed for safe broker-by-broker operation.

01UserAn authenticated staff, partner or trader session.
02RoleScoped from a broker-defined role catalogue.
03PermissionChecked per action, not per screen.
04ActionHigh-impact mutations require strong proof and a reason.
05ApprovalFour-eyes where the broker has defined it.
06AuditAppend-only evidence retained against the record.
nexus.demo-broker.com/back-office/approvals
Approvals
Governance
FA
Approval inbox
Four-eyes
RequestSubjectTypeRaised by
Withdrawal · $4,200M. KarlsenSecond approvalA. Novak
Commission plan · Tier 2Vantage PartnersPublishR. Idris
KYC overrideT. LindqvistExceptionC. Marek
Permission grantDesk 3 · refundsRole changeA. Novak
Payout request · $9,800Northline IBSecond approvalF. Adeyemi
Evidence trail
Append-only
  • Requested by A. Novak with reason09:14
  • Strong proof re-authentication passed09:14
  • Policy check withdrawal limit v209:15
  • Awaiting second approvernow

Security themes

Eight controls, in plain language.

Tenant isolation
Every broker request is bound to a tenant context, with database row-level security and crossed-tenant tests.
Audience isolation
Back Office, Trader and Partner hosts use separate credential-bound sessions and API scope catalogues.
Sensitive actions
High-impact mutations require strong proof, an explicit reason and, where defined, separate approval.
Auditability
Policy, approval and lifecycle records are retained as append-only evidence.
Fail-closed behaviour
Live modes show an unavailable state instead of silently substituting demo or fixture data.
Broker-host integration
Manager API connectivity is isolated to explicit broker-host services and controlled ceremonies.
Emergency access
Break-glass and vendor support access are governed, time-bound and audited rather than permanently broad.
Updates
The fleet plan preserves broker databases and brand assets through backup, preflight, migration, smoke and rollback steps.

White-label direction

Your infrastructure. Their brand.

Product images separate interface structure from the broker logo, so an upgrade does not overwrite brand assets.

Runtime brand pack

Logo, colour, typography, favicon and display name published as shared design tokens.

In delivery

Hostnames

Broker-configured labels and domains for the admin, Trader and IB experiences.

Built and tested

Consistent inheritance

Charts, forms, games and system states inherit the broker identity from the same tokens.

In delivery

Sensible defaults

HX Nexus defaults appear only where the broker has not published a brand pack.

Built and tested

Current qualifier. Per-broker runtime branding and fleet rollout remain labelled as in delivery until the relevant phase acceptance is signed off.

Bring your security review early.

We would rather answer the isolation and evidence questions before a pilot than after one.