Besimi & Siguria
Trust & Security
NEXVIO është ndërtuar si një shtresë identiteti me privatësi në thelb. Të dhënat tuaja janë tuajat — ne nuk i mbajmë kurrë peng dhe nuk i shesim kurrë.
NEXVIO is built as a privacy-native identity layer. Your data is yours — we never hold it hostage and we never sell it.
Shtresë Identiteti me Privatësi-Native Privacy-Native Identity Layer Pre-launch · posture e vetëdeklaruar ~4/5 Pre-launch · self-declared ~4/5 posturePrivatësia para së gjithash
Privacy first
Të dhënat sensitive mbrohen — edhe nga vetë administratori. Aksesi kërkon miratim dhe lë gjurmë.
Sensitive data is protected — even from the administrator. Access requires consent and leaves an audit trail.
Pa vendor lock-in
No vendor lock-in
Eksporto kurdo, largohu pa pengesa. Asnjë kurth kontraktual. Të dhënat mbijetojnë edhe pa ne.
Export anytime, leave with no friction. No contractual trap. Your data survives even without us.
Përputhje me ligjin BE
EU-law aligned
GDPR + Ligji 124/2024, EU AI Act, ESPR. E regjistruar në BE, dygjuhëshe AL-EN.
GDPR + Albanian Law 124/2024, EU AI Act, ESPR. EU-registered, bilingual AL-EN.
Siguri me shtresa
Defense in depth
Enkriptim AES-256, 2FA, auth me cookie, backup të enkriptuar 3-2-1, monitorim 24/7.
AES-256 encryption, 2FA, cookie-based auth, encrypted 3-2-1 backups, 24/7 monitoring.
Publik ≠ i publikuar
Public ≠ published
Profili yt hapet nga kushdo që ka linkun — por nuk indeksohet nga Google si parazgjedhje (noindex). Del në kërkim vetëm nëse ti e zgjedh, me një çelës te paneli.
Your profile opens for anyone with the link — but it is not indexed by Google by default (noindex). It appears in search only if you choose, with a toggle in your dashboard.
1Privatësia në thelb (Neni 1)Privacy at the core (Article 1)
Parimi ynë i parë, i palëkundur: të dhënat tuaja sensitive janë private edhe nga ne. Paneli i administratorit nuk i sheh ato pa një miratim të qartë nga ju, dhe çdo akses i tillë regjistrohet në një gjurmë të pandryshueshme.
Our first, unwavering principle: your sensitive data is private even from us. The admin panel does not see it without your explicit consent, and every such access is recorded in an immutable audit trail.
- Enkriptim në nivel fushe (AES-256-GCM) për të dhënat personale të ndjeshme — jo vetëm "në disk".Field-level encryption (AES-256-GCM) for sensitive personal data — not just "at rest".
- Akses me miratim (consent-gated): operatori jep leje, ne s'shkojmë "rrugës së pasme".Consent-gated access: the operator grants permission; there is no back door.
- Minimizim & afat ruajtjeje: mbledhim vetëm ç'duhet dhe e fshijmë kur s'duhet më.Minimization & retention: we collect only what's needed and delete it when it's no longer needed.
2Të dhënat janë tuajat — pa lock-inYour data is yours — no lock-in
Ju zotëroni të dhënat tuaja dhe mund të largoheni kurdo, pa pengesa — për çdo arsye, përfshirë çdo gjë jashtë kontrollit që mund t'i ndodhë NEXVIO-s.
You own your data and can leave anytime, with no obstacles — for any reason, including anything beyond our control that could happen to NEXVIO.
- Format të hapur + eksport në çdo kohë përmes API/Dashboard.Open formats + export anytime via API/Dashboard.
- Pa kurth kontraktual: klauzolë daljeje te Kushtet e Shërbimit / DPA.No contractual trap: an exit clause in the Terms of Service / DPA.
- Për Pasaportën Dixhitale të Produktit (DPP): backup-provider i pavarur + escrow + identifikues te Regjistri BE + resolver i ri-drejtueshëm + plan vazhdimësie 10–15 vjet → të dhënat mbijetojnë edhe nëse NEXVIO pushon.For the Digital Product Passport (DPP): independent backup provider + escrow + EU-registry identifier + re-pointable resolver + 10–15 year continuity plan → data survives even if NEXVIO ceases.
3Përputhshmëria ligjoreLegal compliance
- GDPR + Ligji 124/2024 (Shqipëri): të drejtat e subjektit (akses, eksport, fshirje) të integruara në produkt.GDPR + Law 124/2024 (Albania): data-subject rights (access, export, deletion) built into the product.
- EU AI Act (Reg. 2024/1689): jemi deployer me rrezik të ulët — pa biometrikë, pa social-scoring, pa vendime automatike mbi punëtorë; përmbajtja e gjeneruar nga AI etiketohet (Neni 50).EU AI Act (Reg. 2024/1689): we are a low-risk deployer — no biometrics, no social scoring, no automated decisions over workers; AI-generated content is labeled (Art. 50).
- ESPR-ready: DPP-ja jonë është ndërtuar mbi standardet e hapura të BE-së për 2027+.ESPR-ready: our DPP is built on the EU open standards for 2027+.
- Rezidencë e të dhënave në BE (Frankfurt) + materiale të jashtme dygjuhëshe AL-EN.EU data residency (Frankfurt) + bilingual AL-EN external materials.
4Siguria teknikeTechnical security
- Autentikim me cookie httpOnly (token-i s'ekspozohet te JavaScript) + 2FA për llogaritë administrative.httpOnly cookie auth (token never exposed to JavaScript) + 2FA for administrative accounts.
- Mbrojtje nga sulmet: rate-limit, bllokim llogarie pas tentativave të dështuara, fjalëkalime me bcrypt.Attack mitigation: rate-limiting, account lockout after failed attempts, bcrypt-hashed passwords.
- Enkriptim AES-256 i fushave personale + rotacion çelësash.AES-256 encryption of personal fields + key rotation.
- Backup i enkriptuar 3-2-1 (ditor, off-site, AES-256) → rikuperim i shpejtë.Encrypted 3-2-1 backups (daily, off-site, AES-256) → fast recovery.
- Monitorim i jashtëm 24/7 + watchdog vetë-shërues në server.24/7 external monitoring + self-healing watchdog on the server.
- HSTS, header-a sigurie, CSP + TLS (Let's Encrypt) + WAF (Cloudflare).HSTS, security headers, CSP + TLS (Let's Encrypt) + WAF (Cloudflare).
- Gjurmë auditi e pandryshueshme për veprime të ndjeshme.Immutable audit log for sensitive actions.
5TransparencaTransparency
Asgjë e fshehur. Kur bëjmë një gabim, e korrigjojmë me një shënim të dukshëm — nuk e fshijmë historinë. Ky është një nga tre parimet tona morale, mbi çdo veçori.
Nothing hidden. When we make a mistake, we correct it with a visible note — we don't erase history. This is one of our three moral principles, above any feature.
6Raporto një dobësi (Zbulim i Përgjegjshëm)Report a vulnerability (Responsible Disclosure)
Nëse zbuloni një dobësi sigurie te NEXVIO, duam ta dëgjojmë. Kërkuesit që veprojnë me mirëbesim dhe respektojnë rregullat më poshtë janë të mirëpritur — dhe nuk do të përballen me veprime ligjore nga ana jonë.
If you discover a security vulnerability in NEXVIO, we want to hear about it. Researchers acting in good faith and following the rules below are welcome — and will not face legal action from us.
Si të raportoniHow to report
- Email te
[email protected]ose[email protected]me temën "SIGURI" — të dyja janë zyrtare dhe arrijnë te i njëjti person.Email[email protected]or[email protected]with the subject "SECURITY" — both are official and reach the same person. - Kontaktet zyrtare gjenden edhe te
/.well-known/security.txt(RFC 9116).The official contacts are also published at/.well-known/security.txt(RFC 9116). - Përfshini: URL-në/endpoint-in, hapat e riprodhimit, ndikimin e mundshëm dhe (nëse ka) një dëshmi konceptuale.Include: the URL/endpoint, reproduction steps, potential impact and (if any) a proof of concept.
Çfarë premtojmë neWhat we commit to
- Konfirmim marrjeje brenda 5 ditësh pune.Acknowledgement within 5 business days.
- Vlerësim fillestar brenda 10 ditësh pune — a e pranojmë, si e klasifikojmë, çfarë vijon.Initial assessment within 10 business days — whether we accept it, how we classify it, what comes next.
- Ju mbajmë të informuar deri në zgjidhje, dhe ju njoftojmë kur rregullimi është live.We keep you updated until resolution, and notify you when the fix is live.
- Kredit publik këtu, nëse e dëshironi.Public credit on this page, if you want it.
SkopiScope
Brenda skopit: getnexvio.com dhe nëndomenet që zotërojmë ne.
In scope: getnexvio.com and subdomains we own.
Jashtë skopit: sulme DoS/DDoS · spam ose përmbytje emaili · inxhinieri sociale ndaj stafit apo klientëve · akses fizik · raporte të papërpunuara nga skanerë automatikë pa ndikim të provuar · mungesa "best-practice" pa shfrytëzim real · shërbime të palëve të treta që s'i kontrollojmë ne (Cloudflare, MongoDB Atlas, ofruesi i serverit).
Out of scope: DoS/DDoS attacks · spam or email flooding · social engineering of staff or customers · physical access · raw automated-scanner output without demonstrated impact · missing "best practice" without a real exploit · third-party services we do not control (Cloudflare, MongoDB Atlas, our hosting provider).
RregullatRules
- Mos aksesoni, ndryshoni apo fshini të dhëna që s'ju përkasin. Përdorni llogari testuese tuajat.Do not access, modify or delete data that isn't yours. Use your own test accounts.
- Nëse ndesheni pa dashje me të dhëna personale — ndaloni menjëherë, mos i ruani, dhe njoftonani.If you unintentionally encounter personal data — stop immediately, do not retain it, and tell us.
- Mos degradoni shërbimin dhe mos prekni disponueshmërinë për përdoruesit realë.Do not degrade the service or affect availability for real users.
- Zbulim i koordinuar: na jepni kohë të arsyeshme (deri 90 ditë) për rregullimin përpara publikimit.Coordinated disclosure: give us reasonable time (up to 90 days) to fix before publishing.