DATA PROTECTION DIRECTIVE // NX-PRIVACY-2026-REV3|CRYPTOGRAPHIC VAULT: AES-256 / SHA-256 ENFORCED
EFFECTIVE DATE: SEPTEMBER 23, 2026
Nex-Trace Defense Emblem
NEX-TRACENX-762
GLOBAL COREDEFENSE AEROSPACE
ZERO-EXPLOITATION DATA DEFENSE

Enterprise Privacy Policy & Data Security Directive

NEX-TRACE GLOBAL, INC. RESPECTS INSTITUTIONAL TRADE PRIVACY AND CLIENT CONFIDENTIALITY. THIS DIRECTIVE GOVERNS HOW SCREENED COUNTERPARTY DATA, BENEFICIAL OWNERSHIP TREES, API TELEMETRY, AND CRYPTOGRAPHIC AUDIT CERTIFICATES ARE INGESTED, PURGED, ENCRYPTED, AND STATUTORILY RETAINED.

CONTEXT ECONOMYAutomated stripping of raw filings, HTML boilerplate, and administrative debris before storage.
AES-256 / TLS 1.3End-to-end data-in-transit and data-at-rest encryption across all persistent volumes.
NO AD-TRACKING / SALEZero data monetization. We never sell, broker, or train third-party public AI on client queries.

1.0 Institutional Privacy Commitment & Scope

Nex-Trace Global, Inc. ("Nex-Trace", "Company", "we", "us") delivers high-assurance, defense-grade corporate graph screening to regulated exporters. Unlike consumer data brokers, Nex-Trace operates under strict business-to-business confidentiality covenants. We do not track users across the public internet, deploy tracking cookies for advertising networks, or monetize search queries.

This Privacy Policy applies to all services provided under the Nex-Trace domain, our FastAPI HTTP endpoints (/api/v1/screen, /api/v1/audit/{id}/pdf, /api/v1/webhooks/erp-pre-check), the FastMCP screening servers, and the Web Dashboard.

2.0 Information We Ingest and Process

In providing export compliance screening, we process the following distinct categories of data:

2.1 Customer Account & Identity Credentials:Enterprise billing contacts, corporate email addresses, IP whitelists, and SHA-256 hashed API authentication tokens.
2.2 Screened Counterparty Queries:Target legal entity names, ISO country codes, provided ECCN codes, and user-supplied ownership matrices submitted for statutory OFAC 50% Rule traversal.
2.3 Public & Sovereign Watchlist Ingests:Public consolidated screening entries mirrored from the U.S. International Trade Administration (ITA CSL), OFAC Specially Designated Nationals (SDN), BIS Entity List, Military End-User (MEU) List, and DDTC Debarred Parties.
2.4 Public Corporate Registry Feeds:Public beneficial ownership graphs, shareholder equity percentages, and registration IDs fetched via commercial registries (e.g. OpenCorporates).

3.0 The Technical "Context Economy" Protocol

In accordance with our internal security directives, the Platform enforces an automated Context Economy Protocol via backend.app.engine.context_cleaner:

✓ Data Minimization: When resolving commercial networks from external APIs, our ingestion pipeline strips all irrelevant administrative noise, annual return boilerplate, scanned filing attachments, and raw HTML descriptions.

✓ Essential Graph Topology Only: We store only the mathematical minimum required for deterministic NetworkX calculations: normalized entity identifier, legal name, jurisdiction ISO, ownership stake percentage (equity_pct), and board control flags.

4.0 Statutory 5-Year Retention (EAR ยง 762 Compliance)

4.1 Mandatory Federal Retention: Under 15 CFR § 762.6, all records relating to export transactions, pre-screening evaluations, and license determinations must be retained for a mandatory statutory period of five (5) years from the date of export or assessment.

4.2 Cryptographic Immutability: Every audit determination executed via POST /api/v1/screen is stored with its microsecond timestamp, full graph topology, and a tamper-evident SHA-256 digital signature in our compliance repository (TrackedCounterparty). Customer may export and archive signed Safe Harbor PDF certificates at any time.

4.3 Ephemeral Caching Lifecycle: External registry lookup caches in Redis operate on a strict 14-day Time-To-Live (TTL). Once expired, cached shareholder trees are purged automatically.

5.0 Data Security Architecture & Multi-Tenant Isolation

Nex-Trace implements physical, administrative, and technical safeguards engineered for high-consequence enterprise environments:

6.0 Law Enforcement, Subpoena, & Regulatory Disclosures

Nex-Trace will not disclose Customer screening logs to third parties except where strictly required by applicable federal law:

In the event Nex-Trace receives a formal subpoena, national security letter, or court order from the U.S. Department of Justice (DOJ), BIS Office of Export Enforcement (OEE), or OFAC, Nex-Trace will notify Customer prior to disclosure unless explicitly prohibited by a federal non-disclosure order (gag order) issued by a court of competent jurisdiction.

7.0 International Data Transfers & Global Compliance

While the Platform is hosted in accredited United States data centers, we maintain compliance protocols for international customers:

8.0 Data Subject Rights & Security Contact

Enterprise customers may request verification of their historical audit volumes, request deletion of expired temporary caches, or report security vulnerabilities by contacting our designated Chief Information Security Officer (CISO) and Data Protection Officer at:

Nex-Trace Global, Inc. — Data Protection & Information Security Directorate
Attn: Chief Information Security Officer (CISO)
Email: security@nextraceglobal.internal
Responsible Disclosure PGP Key: 7F3A 982E BC12 449A D881 FE20 3391 B109