Security at nextroof
Last updated: 1 April 2025 · nextroof Limited
1. Defence-in-depth architecture
nextroof is built on Microsoft Azure's sovereign, enterprise-grade cloud. Every service runs inside private virtual networks with strictly scoped network security groups, and all inter-service traffic is authenticated and encrypted. Public attack surface is minimised through managed API gateways, Web Application Firewalls and Azure DDoS Protection.
2. Encryption
All data is encrypted with AES-256 at rest and TLS 1.3 in transit. Database credentials, API keys and integration secrets are stored in Azure Key Vault and injected at runtime — never committed to source control. Token signing uses short-lived, rotated keys.
3. Identity & access
Authentication is handled by a dedicated identity service with bcrypt password hashing, multi-factor authentication, device-bound sessions and automatic session revocation. Authorisation is enforced with role-based access control (RBAC) across tenant, landlord, contractor, agent and administrator roles, with per-request tenant isolation.
4. Data residency & compliance
Customer data for each market (UK, Nigeria, Ghana, Kenya, South Africa, UAE) is processed in region-appropriate Azure geography. We operate under UK GDPR, the Data Protection Act 2018 and local data-protection regimes, and maintain records of processing activities for every jurisdiction we serve.
5. Application & AI security
Kiki AI runs on Azure OpenAI with content filtering (RAI) policies, prompt-injection guardrails and bounded tool access. All AI actions are logged with full audit trails. User-supplied content is sanitised and validated before rendering or storage to prevent injection attacks.
6. Operational security
We perform regular automated dependency scanning, static analysis and secrets detection in CI. Infrastructure is defined as code and deployed through a gated pipeline (lint → test → build → approval). Backups are encrypted, tested and retained according to our recovery objectives.
7. Monitoring & response
Centralised logging and Azure Monitor alerting give real-time visibility across the platform. A documented incident-response runbook defines detection, containment, notification and post-mortem steps, with breach notification obligations met within regulatory timeframes.
8. Certifications & audits
We maintain SOC 2 Type II controls and undergo periodic internal and third-party penetration testing. Security findings are tracked to remediation with defined SLAs.
Security concerns? security@nextroof.co.uk