Trust center
Companies world‐wide, trust us with their business and their data. Each day we strive to deserve and preserve that trust. The Trust center collects all the latest information on the security, reliability, privacy, and compliance of our products and services.
Our software as a service offerings
When you run Nextway.cloud, you are in capable hands.Everything runs with the Microsoft Azure datacenters in Frankfurt, Amsterdam, and Zurich each backed up by a corresponding datacenter in a distant location. Everyday operation of Next is handled by our own staff with the help of external Azure experts.
Security
We protect your data with strong encryption in transit and at rest. We enforce authentication and support enterprise SSO using SAML, OAuth, and OIDC.
Reliability
We run with Microsoft Azure. We mirror your data continuously, and back them up each night to a separate datacenter. We keep the backups encrypted and in generations.
Compliance
Nextway is SOC 2 certified by Deloitte. Next is certified according to ISAE 3000 and IDW PS880. Microsoft Azure is certified to SOC 2, ISO 27001, ISO 27018, and many more.
Privacy
We are committed to privacy and GDPR. We run everything with European staff. We keep data in Frankfurt and Amsterdam and manage the encryption keys ourselves.
Our support and consultancy
You know it, and we know it. Our support and consultancy efforts are as important as the software products they complement — software with knowledge and experience. To deliver these services efficiently and securely is top of mind at Nextway.
Best practice
We protect your data with strong encryption in transit and at rest. We enforce authentication and support enterprise SSO using SAML, OAuth, and OIDC.
Data processing agreement
Nextway is SOC 2 certified by Deloitte. Next is certified according to ISAE 3000 and IDW PS880. Microsoft Azure is certified to SOC 2, ISO 27001, ISO 27018, and many more.
Confidentiality
We run with Microsoft Azure. We mirror your data continuously, and back them up each night to a separate datacenter. We keep the backups encrypted and in generations.
Privacy
We are committed to privacy and GDPR. We run everything with European staff. We keep data in Frankfurt and Amsterdam and manage the encryption keys ourselves.

Our internal systems and processes
Some may think that our internal processes are none of your business. We respectfully disagree. You have every right to expect that Nextway has systems and processes in place, to secure that we deliver quality software, and take good care of the data we have from you. Our SOC 2 certification addresses every aspect of this.
In the cloud and on prem
We protect your data with strong encryption in transit and at rest. We enforce authentication and support enterprise SSO using SAML, OAuth, and OIDC.
Our privacy policy
Nextway is SOC 2 certified by Deloitte. Next is certified according to ISAE 3000 and IDW PS880. Microsoft Azure is certified to SOC 2, ISO 27001, ISO 27018, and many more.
Continuous delivery
We run with Microsoft Azure. We mirror your data continuously, and back them up each night to a separate datacenter. We keep the backups encrypted and in generations.
Privacy
We are committed to privacy and GDPR. We run everything with European staff. We keep data in Frankfurt and Amsterdam and manage the encryption keys ourselves.

Our work on industry standards
Standards are set by the people who show up. Nextway takes part in the bodies that define how wealth management systems connect, and how financial centers digitalize.
OpenWealth Association
The association defines the open API standard for wealth management. Its members are custody banks, wealth managers, and technology providers. Nextway is one of them.
digital-liechtenstein.li
The platform is Liechtenstein's national initiative for digital innovation. More than 50 companies and organizations back it, under government patronage. Nextway is a member, and our Managing Director Switzerland, SVP Finance sits on the board.
Incidents affecting the security of data
No matter how hard we try, incidents will happen. Besides our ability to avoid incidents, we would like to be measured on our ability to handle these incidents. And on the openness with which we do so.
Report an incident
If you believe that data is at risk, don’t hesitate to contact our helpdesk by phone or email. You’ll find your local contact information below. Learn more
Questions
If you have questions regarding privacy and other issues related to security, feel free to call us. Or send us an email at privacy@nextway.software
Complaints
If you believe that data is at risk, don’t hesitate to contact our helpdesk by phone or email. You’ll find your local contact information below. Learn more
Vulnerabilities
If you believe that data is at risk, don’t hesitate to contact our helpdesk by phone or email. Read more about vulnerabilities here.
Alerts
5-12-25: Next 2.0, Nextway.Cloud™, and Nextway are not affected by the recent React2Shell RCE 0-day vulnerability (CVE-2025-55182 and CVE-2025-66478).
Our routine monitoring of vulnerabilities identified that one of our software components was affected by the vulnerability in RSC. The affected component – Nextway.Cloud™ Admin Console – is currently not in use by customers and users outside Nextway. Still, the Next.js framework in question was updated to the newest version, and the updated solution deployed with the first available security maintenance window. No trace has been found that the vulnerability has been exploited. This incident serves a severe reminder to keep your software – including Next – up to date. Outdated software is inefficient and dangerous.
If you would like to know more, feel free to reach out to your Nextway contact.
01-04-22: Next 2.0, Next as a Service, and Nextway are not affected by the recent Spring4Shell RCE 0-day vulnerability (CVE-2022-22965).
This incident however serves a severe reminder to keep your software – including Next – up to date. Outdated software is inefficient and dangerous.
If you would like to know more, feel free to reach out to your Nextway contact.
12-12-21: Next 2.0, Next as a Service, and Nextway are not affected by the recent Log4j RCE 0-day vulnerability (CVE-2021-44228).
19-03-21: Investigations show that no data from our mail server was exposed. All affected infrastructure has been replaced.
10-03-21: Nextway infrastructure was compromised by the Hafnium hack. No external data is expected to be exposed in the incident. Update will follow.