Book a demo

Boring infrastructure.
Quiet trust.

NEXERA PXM runs on European infrastructure, designed and operated in the Netherlands. Strict tenant isolation at the database row level. Governed by DEED B.V. Used by serious retailers running serious catalogs.

Book a demo

Audit partner

CI-Audit

CI-Audit

Governed by

DEED B.V.

Data residency

European Union only

Trusted by

Retailers running 12k+ SKUs

Six things we did on day one, so you don't have to ask.

01

European hosting · only

All product data, assets and AI logs live on European infrastructure. PostgreSQL clusters in EU-Central. Cloudflare R2 buckets pinned to EU regions. Never replicated outside the EU, ever, not for analytics, not for backups, not for support.

02

Row-level tenant isolation

Multi-tenancy that isn't a polite suggestion. Every row in 109 database tables carries a tenant_id with a PostgreSQL Row-Level Security policy enforced at the database layer. The application layer can't bypass it, only a narrowly-scoped admin client can, and only for auth.

03

Authentication you can't replay

Passwordless OTP login. JWT access tokens expire in 15 minutes. Refresh tokens rotate; if an old one is reused, the entire family is revoked and the user is logged out everywhere. Tokens hashed with SHA-256, never stored in plaintext.

04

Audit every destructive thing

Every create, update, delete, role change, module toggle, plan change, import, export, sync, and impersonation event lands in the audit log. Filterable by user, action, date range. Exportable on demand. Kept for the lifetime of the tenant.

05

Secrets out of code · always

Shopify access tokens encrypted at rest. Webhook payloads verified by HMAC against per-store secrets. Claude calls go through a circuit breaker. Sentry catches errors with PII scrubbing. Health endpoints are public, detailed health is SUPER_ADMIN only.

06

Roles & least privilege

Eight roles from SUPER_ADMIN down to VIEWER plus supplier-side roles. Module-gated features: tenants only see modules their plan enables. Permission matrix enforced at the API layer; SUPER_ADMIN impersonation always emits an audit event.

European hosting · only

All product data, assets and AI logs live on European infrastructure. PostgreSQL clusters in EU-Central. Cloudflare R2 buckets pinned to EU regions. Never replicated outside the EU, ever, not for analytics, not for backups, not for support.

01

Row-level tenant isolation

Multi-tenancy that isn't a polite suggestion. Every row in 109 database tables carries a tenant_id with a PostgreSQL Row-Level Security policy enforced at the database layer. The application layer can't bypass it, only a narrowly-scoped admin client can, and only for auth.

02

Authentication you can't replay

Passwordless OTP login. JWT access tokens expire in 15 minutes. Refresh tokens rotate; if an old one is reused, the entire family is revoked and the user is logged out everywhere. Tokens hashed with SHA-256, never stored in plaintext.

03

Audit every destructive thing

Every create, update, delete, role change, module toggle, plan change, import, export, sync, and impersonation event lands in the audit log. Filterable by user, action, date range. Exportable on demand. Kept for the lifetime of the tenant.

04

Secrets out of code · always

Shopify access tokens encrypted at rest. Webhook payloads verified by HMAC against per-store secrets. Claude calls go through a circuit breaker. Sentry catches errors with PII scrubbing. Health endpoints are public, detailed health is SUPER_ADMIN only.

05

Roles & least privilege

Eight roles from SUPER_ADMIN down to VIEWER plus supplier-side roles. Module-gated features, tenants only see modules their plan enables. Permission matrix enforced at the API layer; SUPER_ADMIN impersonation always emits an audit event.

06

Your data crosses
fewer borders than you do.

NEXERA PXM is operated from the Netherlands, on EU infrastructure. We do not replicate, mirror or back up customer data outside the European Union. Period. The team building it is in Herten, and the legal entity is DEED B.V.

NL

Engineering, operations, support

EU-Central

Postgres clusters, R2 buckets

AMS · FRA · CDG

CDN edges

0

data leaves the EU

Governed by DEED B.V. Audit programme under way.

DEED B.V., the studio that designed and built NEXERA, governs the platform's roadmap, security posture and incident response. We are engaging CI-Audit for an annual review covering tenant isolation, authentication, key management and data residency.

Audit partner

CI-Audit

We are scoping an annual penetration test and code review against the OWASP Application Security Verification Standard. Findings will be tracked to closure and shared with customers on request under NDA.

External pen-test · planned

Source-code review · planned

OWASP ASVS-aligned

Findings tracked to closure

Operator & governance

DEED B.V.

Designed, built and operated by DEED B.V., a Dutch studio based in Herten. The same team that ships features handles incident response. Roadmap and security posture governed by DEED B.V. leadership.

Boven de Wolfskuil 20, 6049 LZ Herten

KVK: 73419583

One ops team - 24-hour incident response

Engineering & security - same room

Things you can ask for.
We have them.

Contact

In effect

GDPR

Operator and processor under EU 2016/679. Standard Contractual Clauses where needed; DEED B.V. is the data controller for marketing and processor for tenant content.

In effect

DPA · Data Processing Agreement

Standard DPA covering processing purposes, sub-processors, retention, deletion, and the audit clause. Available to every customer. Custom DPAs on request.

In progress

CI-Audit annual and
ad-hoc review

External penetration test and source-code review. Findings will be tracked to closure and shared with customers on request under NDA.

In progress

SOC 2 Type II

Type II report covering Security, Availability and Confidentiality. Scoping under way. We will publish the observation window once it opens.

In progress

ISO 27001

ISMS scope drafted around platform engineering and operations. Internal readiness work under way. No certification date committed yet.

In effect

Subprocessors list

Current sub-processors: Railway (hosting), Cloudflare (R2 + edge), Anthropic (Claude), OpenAI and fal.ai (image generation), Meshy and Tripo3D (3D generation), Shopify (product sync), Stripe (billing), Resend (email), Sentry (errors). Versioned and dated.

GDPR

Operator and processor under EU 2016/679. Standard Contractual Clauses where needed; DEED B.V. is the data controller for marketing and processor for tenant content.

In effect

DPA · Data Processing Agreement

Standard DPA covering processing purposes, sub-processors, retention, deletion, and the audit clause. Available to every customer. Custom DPAs on request.

In effect

CI-Audit annual review

External penetration test and source-code review. Findings will be tracked to closure and shared with customers on request under NDA.

In progress

SOC 2 Type II

In progress

Type II report covering Security, Availability and Confidentiality. Scoping under way. We will publish the observation window once it opens.

ISO 27001

ISMS scope drafted around platform engineering and operations. Internal readiness work under way. No certification date committed yet.

In progress

Subprocessors list

Current sub-processors: Railway (hosting), Cloudflare (R2 + edge), Anthropic (Claude), OpenAI and fal.ai (image generation), Meshy and Tripo3D (3D generation), Shopify (product sync), Stripe (billing), Resend (email), Sentry (errors). Versioned and dated.

In effect

"We picked NEXERA over an enterprise PIM because they didn't need an architect to explain how isolation worked. The Dutch ops team is in the same Slack channel as us, and a sub-€100/month tier doesn't make us a rounding error."

Operations Lead

Multi-brand outdoor retailer · NL · 12k SKUs

Disclosure within 72 hours.
By the people who built it.

Material incidents are disclosed to affected tenants within 72 hours of confirmation. The same engineers who shipped the affected feature handle response. No offshore Tier-1 triage queue. No incident-management PR firm.

A redacted post-mortem goes to affected tenants, with the underlying root cause, timeline, and the change shipped to prevent recurrence. Severe incidents trigger a written letter from DEED B.V. leadership.

A serious platform.
For serious catalogs.

Want the audit letter, the DPA template, the subprocessors list, or a chat with the operator about tenancy? Send a note, same team responds within a working day.

Contact

Author your product data once. Publish it everywhere, perfectly.

A product of DEED Vision, the studio in Herten.

Author your product data once. Publish it everywhere, perfectly.

A product of DEED Vision, the studio in Herten.

Author your product data once. Publish it everywhere, perfectly.

A product of DEED Vision, the studio in Herten.