Built for public discovery without losing control.
Nexez is open where agents need discovery and closed where owners need control. Separate hosts, deliberate public projections, row-level access, encrypted credentials, and verified runtime paths protect that boundary.
3
Separated domains
RLS
Database access model
AES
Recoverable secret encryption
Three separated surfaces
nexez.ai
Public education + discovery
app.nexez.ai
Authenticated creation + billing
nexez.app
Crawlable agent listings + APIs
Platform boundaries
The public listing is not the private dashboard.
The public runtime reads a restricted projection of published records. Drafts, account data, billing, credentials, private trust evidence, analytics, and owner controls remain behind authenticated access.
Row-level ownership
Owner and collaborator policies constrain workspace data at the database boundary.
Public projection
Published surfaces read an allowlisted record instead of exposing the private base table.
Host-aware routing
Marketing, authenticated control, and agent runtime traffic resolve to deliberate domains.
Payments and integrations
Credentials and transactions stay scoped.
Recoverable integration credentials and buyer-access tokens are server-only and encrypted at rest. Signed webhooks, dry runs, idempotency, and immutable purchase economics constrain consequential actions.
Encrypted recovery
Calendly, Shopify, Square, Acuity, checkout, and negotiation secrets use narrow server-side recovery paths.
Verified events
Stripe, Shopify, and Calendly deliveries are signature-checked before state changes.
Money provenance
Price, fee rate, commission source, refunds, and settlement state remain attributable to the transaction.
Operations and recourse
Critical paths are checked after they ship.
Release certification, reconciliation jobs, launch-health checks, status paths, refunds, disputes, and support escalation cover the period after a request leaves the interface.
Release certification
Static checks, tests, end-to-end flows, SDK parity, and production probes guard releases.
Reconciliation
Billing, escrow, settlements, resources, freshness, and negotiations have repair-oriented jobs.
User recourse
Owners and buyers retain order, refund, dispute, review, status, and support paths.
Questions
FAQ
Will unpublished listings be crawled?
No. The public runtime is built around published records and explicit public artifacts.
Can users verify custom domains?
Yes. Custom domains use verification checks before they are marked live.
Where do my API keys and secrets live?
Private credentials stay server-side; recoverable secrets are encrypted and excluded from public listings, client bundles, and crawlable artifacts.
Public to agents. Private where it should be.
Nexez gives businesses a discoverable public surface without turning the dashboard into a public target.