Security and continuity

A DPP must remain available, verifiable and transferable over time.

The Trust Center separates what is defined in the architecture, what must be implemented and tested in the MVP, and what belongs to the enterprise roadmap. No certification is claimed before the corresponding verification.

Architecture definedTo implement and test in the MVPEnterprise roadmap
Architecture defined

Identity and access

Organisations, users, roles, delegations and public or restricted levels are separated in the NexusDPP model.

  • Roles for manufacturer, importer, supplier and verifier.
  • Permissions connected to cases, data, documents and actions.
  • Traceability of author, source, status and approval.
Architecture defined

Integrity and audit

Versions, logs, evidence and publication gates are distinct parts of the flow.

  • Audit trail of changes.
  • Checks before publication and activation.
  • Link between identifier, product and physical carrier.
MVP

Application security

Technical compliance requires implementation and testing, not only an architectural description.

  • Strong authentication and session management.
  • Encryption in transit and at rest.
  • Tenant segregation and data-level authorisation.
  • Key, revocation and vulnerability management.
MVP

Backup and recovery

The project must include copies, verified recovery and protection against dataset loss.

  • Encrypted, versioned backups.
  • Periodic restore tests.
  • Defined RPO/RTO objectives.
  • Documented disaster recovery.
MVP

Portability and exit

Freedom from lock-in must be demonstrated through complete exports and transfer procedures.

  • Export of data, attachments, versions and audit trail.
  • Structured formats and documented mapping.
  • Migration procedure to another provider.
  • Continuity of resolver and identifiers.
Enterprise roadmap

Independent continuity

For regulated and high-criticality scenarios, the roadmap includes further measures to contract and verify.

  • Backup copy with an independent party.
  • SLA, monitoring and availability reporting.
  • Penetration testing and third-party audit.
  • Path towards applicable security certifications.
Verification matrix

Every requirement must produce a test and evidence.

The NexusDPP technical roadmap should connect requirement, component, control, owner, result and supporting document.

RequirementData integrity
ComponentDPP Core + Audit
TestChange, version and rollback
EvidenceSigned log and report