Lewati ke konten utama

Dokumen ini hanya tersedia dalam bahasa Inggris.

Security Overview

This page summarizes the security measures protecting nextbasket.com and the data submitted through it. It is a public overview by Next Basket Platform B.V. (NEXT BASKET AI), not a contractual commitment or a warranty; platform customers should refer to their agreement and the Data Processing Addendum for binding terms.

Effective date: 23 July 2026

Document version: Version 1.0 — effective 23 July 2026

1. Scope of this overview

This overview covers the nextbasket.com marketing website — the pages you browse and the enquiry, demo-request, and newsletter forms you may submit. The NEXT BASKET AI merchant platform has its own security architecture; binding security commitments for platform customers live in their agreements, not on this page (see section 9).

2. Encryption in transit

All traffic to and from this website is encrypted in transit using TLS (HTTPS) — both between your browser and our edge, and between the edge and our backend services.

3. Edge protections (Cloudflare)

  • The website frontend runs on Cloudflare Workers, behind Cloudflare’s global edge network, which provides DDoS mitigation and traffic filtering in front of our infrastructure.
  • Form submissions are protected by Cloudflare Turnstile, an anti-bot challenge that verifies a human is submitting the form.
  • Submissions are additionally protected by per-IP rate limiting, abuse detection, and honeypot fields to deter automated abuse.

For security reasons we describe these controls without publishing their exact thresholds, windows, or configuration. Those values are security-sensitive, may change, and are maintained internally.

4. Backend and data storage

  • The backend that receives form submissions is a containerized service hosted on Fly.io, separate from the frontend edge.
  • Submitted data is stored in a Postgres database.
  • Access to submitted lead data is limited to the people and systems that need it to respond to you.

Data is encrypted in transit using TLS, and backups and recovery procedures are maintained under our internal operating controls.

5. Payment security

We do not store full payment-card numbers. Payments for the platform are processed by Stripe, a PCI DSS Level 1 certified payment processor — card data is handled by Stripe, not by our systems.

6. Privacy-preserving analytics

Website analytics (Google Analytics 4, when enabled for a build) runs in a cookieless mode: it stores nothing on your device, anonymizes IP addresses, has all advertising features disabled, and its events never carry personal information from our forms.

7. Certifications and independent testing

We publish only measures we can evidence. This website does not currently claim SOC 2 or ISO/IEC 27001 certification, a completed third-party penetration test, or a public bug-bounty program, and this page should not be read as making any of those claims. Certification pages published under earlier NEXT BASKET websites do not apply to this website and are not relied upon here.

If we obtain any such certification or report, we will state it on this page together with its scope and date.

8. Reporting a vulnerability

We welcome good-faith reports of security vulnerabilities in this website. Please report privately (not via public channels) and give us reasonable time to investigate and remediate before any public disclosure.

Reporting email
security@nextbasket.com — a monitored security alias.
Disclosure policy file
A /.well-known/security.txt (RFC 9116) file — listing our security-contact address, preferred languages, policy URL, and an expiry date — is published alongside this Security Overview at https://nextbasket.com/.well-known/security.txt.
Good-faith testing
We will not pursue or support legal action against you for lawful, good-faith security testing that avoids privacy violations, data destruction, and service disruption, and that you report privately to us. A fuller safe-harbour statement will be added here once its wording is finalized with counsel.

9. Platform security and B2B due diligence

This overview covers the public website. Security commitments for the NEXT BASKET platform are contractual: they are set out in the Master Subscription Agreement (Platform Terms) and its incorporated documents, including the Data Processing Addendum (/data-processing-addendum/) and our list of subprocessors (/subprocessors/).

Qualified B2B prospects who need more detailed information about our platform security can request it under a non-disclosure agreement. We provide that detail through the due-diligence process rather than publishing sensitive architecture details on this public page.

10. Questions

General questions about this overview: office@nextbasket.com. To report a security vulnerability, use security@nextbasket.com (section 8). For how we handle personal data, see our Privacy Policy.