Defensive automation for owned infrastructure.
Nexus is a private AI operations control plane used to coordinate memory, approvals, audit trails, infrastructure checks, and controlled defensive security workflows for systems we own or are explicitly authorized to assess.
Who we are
SmartAccs / Nexus is an early private infrastructure project operated by Artiom Ceban. The current system combines a public product landing page, private cloud infrastructure, AI agent workflows, task and memory APIs, approval gates, audit events, and isolated self-hosted execution nodes for authorized internal security learning and defensive validation.
This page describes the intended security use of Nexus honestly. It does not claim enterprise certification, third-party penetration testing services, government work, or independent compliance attestation.
Kali Hermes is a separate lab-worker project. It is not part of the SmartAccs / Nexus public product, legal positioning, or customer-facing offer.
Approved defensive use cases
Owned infrastructure
- Asset inventory for owned VPS, cloud, containers, repositories, and domains.
- Configuration review for Linux, Docker, reverse proxies, SSH, and private dashboards.
- Patch validation, service health checks, and backup/restore verification.
Software security
- Secure code review for SmartAccs/Nexus repositories.
- Dependency scanning, secret scanning, and static analysis.
- Vulnerability triage and remediation planning for owned code.
Controlled security lab
- Local lab testing on deliberately deployed targets.
- Authorized bug bounty research within published program scope.
- Rate-limited validation, evidence collection, reporting, and retesting.
Detection and reporting
- Log analysis, incident notes, and defensive runbooks.
- Threat intelligence summaries for protective decision-making.
- Clear remediation steps and operator approval before risky changes.
Explicitly prohibited use
Nexus is not intended to support offensive or harmful activity.
- No unauthorized access, scanning, exploitation, or testing of third-party systems.
- No phishing, credential theft, token harvesting, session theft, or social engineering.
- No malware deployment, persistence, stealth, evasion, destructive actions, or exfiltration.
- No resale, proxying, or external customer access to restricted model capabilities.
- No public, paid, destructive, account-level, or sensitive action without explicit operator approval.
Authorization and scope
Security testing must be limited to assets we own, operate, or have explicit written authorization to assess. For bug bounty work, the published program scope and rules are treated as the authorization boundary.
When scope is unclear, Nexus workflows are expected to stop at planning, passive review, or local lab reproduction until authorization is confirmed.
Privacy and data handling
Sensitive data, API keys, passwords, private keys, tokens, session cookies, and raw secret material must not be stored in public pages, prompts, screenshots, repository commits, or reports. Defensive reviews should prefer metadata, redacted evidence, and minimum necessary logs.
The current Nexus MVP uses private infrastructure and approval-gated workflows. Broader external access, customer-facing security services, or regulated-data processing would require additional controls and documentation before use.
Responsible reporting
If you believe you found a security issue affecting SmartAccs / Nexus, contact us with a concise report, affected asset, impact, reproduction steps, and non-destructive evidence.
Contact: contact@smartaccs.sbs