
Nexus
The business card that never goes out of date
An NFC and digital business card platform that runs a whole company's cards from one console, in five languages, across the UK, Europe and the Gulf.
How HexaFlow designed and built SCORA: a platform that measures an organisation against nine security frameworks, turns every gap into owned work, checks and reads the evidence that closes it, and hands an auditor the record — in English and Arabic.
“Do you encrypt sensitive data at rest?” Data-protection-policy.pdf, 38 pages.
The policy requires encryption. Nothing shows it is enforced on a single device.
“Encryption at Rest” → IT & Infrastructure → Omar Haddad, due in 30 days.
bitlocker-compliance.pdf: type verified, malware-scanned clean, read in full.
Not by the person who did the work. Separation of duties, recorded.
What was found, what fixed it, who checked — and the file’s SHA-256.
Most organisations can't answer a simple question — how secure are we, actually? — so they pay a consultant to run a workbook once a year and leave a report. The report lists the gaps. Then nothing structured happens to them.
Nobody owns the findings. Nobody checks that a fix was really made. And when an auditor asks eighteen months later whether encryption was enforced, the answer is a policy document that says it should be — which is exactly the kind of evidence that proves nothing.
SCORA was built to close that loop: measure, assign, fix, prove, and keep the proof. The rest of this page follows one finding all the way round it.
Control language assumes you already know the answer. SCORA asks each question the way the person answering would describe their own systems, with context on what is being asked and why it matters — so an IT manager can complete it, not just an assessor.
Encrypting stored data protects it if physical devices or storage systems are compromised.
| Section | Held by | Answered |
|---|---|---|
| Governance | Governance & Risk | 14 / 14 |
| Data Protection | Omar Haddad | 9 / 11 |
| Identity & Access | IT & Infrastructure | 6 / 12 |
| Incident Response | Maya Fares | 0 / 8 |
A team slice can be answered by anyone in it — or claimed, so two people never answer the same question.
Our example answered Yes and attached a 38-page data-protection policy. A policy that says data should be encrypted is not evidence that it is. SCORA reads the document and says so — and the finding stands despite the “Yes”.
Every page, in as many chunks as it takes — with the task's acceptance criteria in hand, so the one relevant screenshot on page 212 is noticed rather than summarised away.
The criteria and those observations, weighed against each other: satisfied, falls short, or cannot assess — with what the evidence showed and what it didn't.
The verdict advises; it never decides. A contributor is warned before submitting weak evidence, and the manager sees the verdict beside the Verify button. If they accept anyway, the report says so.
The contributor is warned before submitting and must acknowledge it — it never blocks, but going ahead is recorded. The manager sees it before verifying.
Domain-level maturity rolls up into an overall score and a readiness level, weighted per framework. That score is the dated record, and it never changes.
Beside it sits a second: the same answers re-scored as if every verified fix had been in place. The gap between the bars is work that has been proved — not promised.
When the assessment is submitted, each finding becomes a task named for the work, not the question: “Encryption at Rest”, not “Do you encrypt sensitive data?”. It arrives with acceptance criteria, a reason it matters, implementation steps and a due date drawn from the recommended timeframe.
| Task | Routed to | Owner | Status |
|---|---|---|---|
Encryption at Rest Data Protection | IT & Infrastructure | Omar Haddadsuggested · 1 open | Unassigned |
Endpoint Protection (EPP/EDR) Endpoint Security | IT & Infrastructure | Lina Salehsuggested · 1 open | Unassigned |
Multi-Factor Authentication Identity & Access | IT & Infrastructure | Tariq Nabilsuggested · 1 open | Unassigned |
Incident Response Plan Incident Response | Security Operations | Maya Faressuggested · 2 open | Unassigned |
Information Security Policy Governance | Governance & Risk | Noor Abbassuggested · 0 open | Unassigned |
Tested Backup Restores Business Continuity | No department | — | Unassigned |
No department covers Business Continuity. Give it to a team and the backlog re-routes itself.
Suggestions go to whoever in the owning team carries the fewest open tasks.
Evidence arrives from people outside the security team, as PDFs and Office documents. That is precisely how malware gets into organisations — so no file is opened by anyone until it has passed seven checks.
A task moves through six states — unassigned, in progress, done, submitted, verified, returned — and the line between done and submitted is deliberate: finishing the work and asking for it to be checked are two different acts.
The closure report is the record of what was found, what fixed it and who checked it. Its first job is honesty: a finding closed with nothing attached, signed off by the person who did it, or accepted after the evidence was judged short — each is legitimate, and each is weak. So each is flagged, on an index page, and counted on page one.
| Finding | Domain | Status | Flags |
|---|---|---|---|
| Encryption at Rest | Data Protection | Verified | — |
| Endpoint Protection (EPP/EDR) | Endpoint Security | Verified | Accepted despite gaps |
| Security Awareness Program | Security Awareness | Verified | No evidence · Self-attested |
| Perimeter Firewall | Network Security | Verified | — |
| Tested Backup Restores | Business Continuity | No longer applicable | No longer applicable |
Every screen, email, notification and generated report exists in English and Arabic. The layout mirrors; the question, the task, its criteria and its reasoning are all authored in Arabic — and the PDFs are set in an Arabic face, not a Latin fallback.
Mixed text is handled line by line, so an Arabic sentence carrying BitLocker, TPM or LUKS reads correctly instead of breaking apart.
شفّر البيانات أثناء السكون — على الأجهزة الطرفية والخوادم وقواعد البيانات — بحيث لا يتحوّل فقدان الجهاز أو الوصول المادي غير المصرّح به إلى فقدان بيانات.
هل تشفرون البيانات الحساسة المخزنة في قواعد البيانات أو أنظمة الملفات؟
International baselines alongside the regional regulation Gulf organisations actually answer to. Content is authored separately from the product and imported, so a new framework is a publishing task, not a release.
Organisational baseline — 170 questions, 89 branching rules
SME Cyber Health Check — 30 questions
ISMS readiness — 123 questions
Readiness for schools and universities — 141 questions
Harmonised with GDPR and ADHICS — 140 questions
Essential Cybersecurity Controls — 176 questions
Cloud Cybersecurity Controls — six tiered assessments
Data management and personal data protection — 190 questions
School digital policy readiness — 155 questions
A SCORA account is, by definition, a list of exactly where an organisation is exposed. It is built to be treated that way.
Names, emails and every assessment answer are encrypted individually with AES-256-GCM — not just the disk they sit on.
Accounts are found by a keyed blind index, so an email can be matched without being stored or searched in the clear.
A health check finds any record left under a retired key, and the interface never shows ciphertext if one exists.
Every query is scoped to the company. A contributor sees their own part of an assessment, not the whole organisation's gaps.
Managers, contributors and department members each see and do only what their role allows — including who may divide an assessment.
Bot protection on sign-in, TLS enforced whenever mail is sent with credentials, and signed, expiring URLs for every file.
Services: Cybersecurity · AI & Machine Learning · Web Application Development · Business Process Automation
Security assessment becomes something a team runs itself, against recognised frameworks rather than opinion
Every gap has an owner, a due date and a record of who did what
A “Yes” has to be backed by evidence that is actually read, not just attached
No evidence file reaches a person until it has passed structural and malware checks
Auditors get a closure record that states its own weaknesses instead of hiding them
Gulf organisations work in Arabic, against the regional regulation they answer to

The business card that never goes out of date
An NFC and digital business card platform that runs a whole company's cards from one console, in five languages, across the UK, Europe and the Gulf.

Three modules that read a feasibility study, judge it, and write a new one from scratch
Three modules: one reads a feasibility and fills the whole Excel model, one benchmarks it against world standards and returns a gap analysis, and one generates an entirely new professional feasibility from historical data.

A walkthrough video in, a removals quote in seconds
The customer films their own home. Computer vision identifies and counts every object, estimates dismantling, handling and transport time, and returns a priced quote.