Security
NEXORA runs on a deliberately small, auditable stack: one database, no analytics, hashed secrets, and every integration off by default. Here’s exactly how it behaves.
Before NEXORA analyzes any site, the target URL is normalized and validated. Hostnames are resolved and every resulting IP is rejected if it falls into private, loopback, link-local, CGNAT or cloud-metadata ranges. The same validation runs on every redirect hop (max 5), robots.txt and sitemap fetches. You can’t point the auditor at your internal network or localhost metadata.
url-guard.tsCredentials are hashed with Node’s built-in scrypt using a random per-user salt. Verification uses constant-time comparison. Password resets use one-time tokens hashed (SHA-256) at rest and expire in 60 minutes.
crypto.scryptWhen you sign in, NEXORA issues a high-entropy random token in an HttpOnly, SameSite=Lax cookie (Secure in production). Only the SHA-256 hash of that token is stored — a database leak never exposes usable sessions. Signing out and password resets invalidate sessions.
nexora_session cookieSignup, login, password resets, contacts and analysis are each independently rate-limited per IP/viewer. Anonymous audits are capped per six-hour window so the public analyzer can’t be milked into a DoS tool.
rate-limit.tsAI, email and Stripe are all optional. Each reports its own configured/not-configured state at runtime, and the UI surfaces that state instead of impersonating a working integration. No analytics, no trackers, no third-party scripts in the customer dashboard.
features mapAudits are private and visible only to their owner. Shareable reports exist only because you create them with an unguessable slug. Automated site analysis is run for the purpose it claims: producing your report.
visibility: privateNEXORA lives in its own nexora/ project with its own package.json, lockfile and SQLite database. Next.js is pinned to its project root via turbopack.root so the unrelated app in the same repository is never compiled or traced into NEXORA. Real credentials belonging to the other app are never read here.
The database stays in nexora/data and is excluded by .gitignore.
Found a weakness?
Contact us directly — we’d rather hear it than patch it later. The environment has no bug-bounty program, but reports are acknowledged and fixed.