Trust & Security

This page is maintained by Nexus Systems (Raymond Naylor, ABN 87 716 389 234) to answer common security and privacy questions about the RAY app. It is app-owned editable content, not an independent certification or audit.

Shared responsibility

RAY runs on managed cloud infrastructure. The underlying platform providers operate the servers, network and database engine; Nexus Systems is responsible for the app itself — its access rules, data handling and integrations. You are responsible for keeping your account credentials safe.

Access & authentication

  • Email & password sign-in, with Google sign-in available.
  • Passwords are checked against the Have I Been Pwned database to block known-leaked passwords at sign-up and password change.
  • Sessions are managed by our auth provider; sign out ends the session on this device.
  • Account deletion is available on request via nexus.systems.au@gmail.com.

Data protection

  • All app data is scoped to the signed-in user using row-level security policies on the database.
  • Traffic between your browser and our servers is encrypted in transit (HTTPS / TLS).
  • Payment card details are handled by Stripe — we never see or store full card numbers.
  • We do not sell personal data.

Subprocessors & integrations

RAY uses a small set of trusted providers to deliver the service. The current list and their roles are described in our Privacy Policy. Changes are reflected by updating that page.

AI content

AI responses are generated by third-party models and may be inaccurate. See our AI Disclaimer for details. Do not rely on RAY for medical, legal or financial advice.

Reporting a vulnerability or abuse

If you believe you've found a security issue, please email nexus.systems.au@gmail.com with steps to reproduce. For abuse, harassment, or illegal content, see Report Abuse.

Compliance

RAY is operated from Australia and handles personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). RAY is not currently certified under SOC 2, ISO 27001, HIPAA, or PCI DSS. Stripe handles cardholder data on PCI-compliant infrastructure.

Contact

Security and privacy contact: nexus.systems.au@gmail.com