Trust center

Companies world‐wide, trust us with their business and their data. Each day we strive to deserve and preserve that trust. The Trust center collects all the latest information on the security, reliability, privacy, and compliance of our products and services.

Our software as a service offerings

When you run Nextway.cloud, you are in capable hands.Everything runs with the Microsoft Azure datacenters in Frankfurt, Amsterdam, and Zurich each backed up by a corresponding datacenter in a distant location. Everyday operation of Next is handled by our own staff with the help of external Azure experts.

Security

We protect your data with strong encryption in transit and at rest. We enforce authentication and support enterprise SSO using SAML, OAuth, and OIDC.

Reliability

We run with Microsoft Azure. We mirror your data continuously, and back them up each night to a separate datacenter. We keep the backups encrypted and in generations.

Compliance

Nextway is SOC 2 certified by Deloitte. Next is certified according to ISAE 3000 and IDW PS880. Microsoft Azure is certified to SOC 2, ISO 27001, ISO 27018, and many more.

Privacy

We are committed to privacy and GDPR. We run everything with European staff. We keep data in Frankfurt and Amsterdam and manage the encryption keys ourselves.

Our support and consultancy

You know it, and we know it. Our support and consultancy efforts are as important as the software products they complement — software with knowledge and experience. To deliver these services efficiently and securely is top of mind at Nextway.

Best practice

We protect your data with strong encryption in transit and at rest. We enforce authentication and support enterprise SSO using SAML, OAuth, and OIDC.

Data processing agreement

Nextway is SOC 2 certified by Deloitte. Next is certified according to ISAE 3000 and IDW PS880. Microsoft Azure is certified to SOC 2, ISO 27001, ISO 27018, and many more.

Confidentiality

We run with Microsoft Azure. We mirror your data continuously, and back them up each night to a separate datacenter. We keep the backups encrypted and in generations.

Privacy

We are committed to privacy and GDPR. We run everything with European staff. We keep data in Frankfurt and Amsterdam and manage the encryption keys ourselves.

Our internal systems and processes

Some may think that our internal processes are none of your business. We respectfully disagree. You have every right to expect that Nextway has systems and processes in place, to secure that we deliver quality software, and take good care of the data we have from you. Our SOC 2 certification addresses every aspect of this.

In the cloud and on prem

We protect your data with strong encryption in transit and at rest. We enforce authentication and support enterprise SSO using SAML, OAuth, and OIDC.

Our privacy policy

Nextway is SOC 2 certified by Deloitte. Next is certified according to ISAE 3000 and IDW PS880. Microsoft Azure is certified to SOC 2, ISO 27001, ISO 27018, and many more.

Continuous delivery

We run with Microsoft Azure. We mirror your data continuously, and back them up each night to a separate datacenter. We keep the backups encrypted and in generations.

Privacy

We are committed to privacy and GDPR. We run everything with European staff. We keep data in Frankfurt and Amsterdam and manage the encryption keys ourselves.

Our work on industry standards

Standards are set by the people who show up. Nextway takes part in the bodies that define how wealth management systems connect, and how financial centers digitalize.

OpenWealth Association

The association defines the open API standard for wealth management. Its members are custody banks, wealth managers, and technology providers. Nextway is one of them.

digital-liechtenstein.li

The platform is Liechtenstein's national initiative for digital innovation. More than 50 companies and organizations back it, under government patronage. Nextway is a member, and our Managing Director Switzerland, SVP Finance sits on the board.

Incidents affecting the security of data

No matter how hard we try, incidents will happen. Besides our ability to avoid incidents, we would like to be measured on our ability to handle these incidents. And on the openness with which we do so.

Report an incident

If you believe that data is at risk, don’t hesitate to contact our helpdesk by phone or email. You’ll find your local contact information below. Learn more

Questions

If you have questions regarding privacy and other issues related to security, feel free to call us. Or send us an email at privacy@nextway.software

Complaints

If you believe that data is at risk, don’t hesitate to contact our helpdesk by phone or email. You’ll find your local contact information below. Learn more

Vulnerabilities

If you believe that data is at risk, don’t hesitate to contact our helpdesk by phone or email. Read more about vulnerabilities here.

Alerts

5-12-25: Next 2.0, Nextway.Cloud™, and Nextway are not affected by the recent React2Shell RCE 0-day vulnerability (CVE-2025-55182 and CVE-2025-66478).

Our routine monitoring of vulnerabilities identified that one of our software components was affected by the vulnerability in RSC. The affected component – Nextway.Cloud™ Admin Console – is currently not in use by customers and users outside Nextway. Still, the Next.js framework in question was updated to the newest version, and the updated solution deployed with the first available security maintenance window. No trace has been found that the vulnerability has been exploited. This incident serves a severe reminder to keep your software – including Next – up to date. Outdated software is inefficient and dangerous.

If you would like to know more, feel free to reach out to your Nextway contact.

01-04-22: Next 2.0, Next as a Service, and Nextway are not affected by the recent Spring4Shell RCE 0-day vulnerability (CVE-2022-22965).

This incident however serves a severe reminder to keep your software – including Next – up to date. Outdated software is inefficient and dangerous.

If you would like to know more, feel free to reach out to your Nextway contact.

12-12-21: Next 2.0, Next as a Service, and Nextway are not affected by the recent Log4j RCE 0-day vulnerability (CVE-2021-44228).

19-03-21: Investigations show that no data from our mail server was exposed. All affected infrastructure has been replaced.

10-03-21: Nextway infrastructure was compromised by the Hafnium hack. No external data is expected to be exposed in the incident. Update will follow.