Nexika

VERSION 1.0

Terms of use.

In short: the self-signed certificate encrypts the link but proves no identity, a private network is only private while it really is, and the server backs nothing up for you. Installing Nexika means becoming its administrator.

This text adds to the general ResonLab terms.

1. What Nexika is

Nexika is the multi-workstation server for the ResonLab applications. It holds the accounts, the permissions and the access log, and it serves the data of Ohmnia and Scenika to several workstations at once. It knows no business operation of its own: each application brings its own.

It runs on a machine that is yours, on a network that is yours. There is no cloud, no subscription, no account with a publisher: your data goes nowhere because nobody else has a server to put it on.

That is also what shifts the responsibility. Installing a server means becoming its administrator — of its updates, its backups, its exposure on the network, and the retention of what it holds.

2. The self-signed certificate encrypts the link, it proves no identity

This is the most important point in this document. Nexika builds a certificate itself, with no external tool, and refuses to listen on the network without encryption. That certificate encrypts the link between a workstation and the server perfectly well.

What it does not do is prove to a workstation that it is talking to the right server. No authority vouches for it: you built it, and you are the one asking each workstation to accept it once. Anyone able to sit between the two could present their own.

Accepting a certificate warning is therefore something to do once, knowingly, on a network you answer for. Getting into the habit of accepting it everywhere is precisely the habit such warnings exist to prevent.

The private key written next to the certificate is the secret that protects every connection. Keep it as you would a password: never copied into a shared folder, never emailed, never backed up somewhere everyone can read it.

3. A private network is only private while it really is

Nexika is designed for the local network of a small business: a few workstations, one machine holding the data, nothing going out. Within that perimeter, a self-signed certificate and internal accounts are a proportionate answer.

That perimeter is more porous than it looks. Guest Wi-Fi, a port forward left on the router, remote access set up one evening to fix something, an infected laptop plugged back in at the office: each of these puts the server within reach of someone who was not meant to have it.

Exposing Nexika directly to the internet is neither intended nor advised. If outside access is needed, it goes through a virtual private network or a reverse proxy with a recognised certificate, set up by someone who does this for a living.

4. Accounts and passwords are your first lock

Nexika refuses to listen anywhere but on the machine itself until an administrator exists, and the failed-login message is the same whether an account exists or not. These refusals are guard rails, not a security policy: that part is yours.

A weak administrator password, shared among colleagues or reused elsewhere, cancels out everything else. The administrator account can read and change the entire accounts and create further accounts: it is the most interesting account in the company for anyone who gets in.

Give each person their own account and the narrowest role that lets them work. One account per person is what makes the access log readable; a shared account makes it silent.

Remove the accounts of people who leave on the day they leave. A forgotten account stays valid indefinitely, and nobody notices an absence of activity.

5. The server backs nothing up for you

Nexika performs no automatic backup. The application data and the accounts database live as files, in the folder you named at commissioning, on a single machine.

Centralising data multiplies what is lost at once. While everyone worked on their own machine, a disk failure cost one person their work; with a server it costs the whole company theirs. That is the price of sharing, and backups are the only thing that buys it back.

Copy the data folder elsewhere regularly, onto media that is not permanently connected, and check now and then that a copy opens. A backup never restored is not a backup: it is an assumption.

6. The access log records, it does not prove

Nexika records who logged in and which operations were requested. That is useful for understanding what happened, and that is what it is for.

That log lives in a file on the machine, and anyone with control of the machine can alter it. It is not evidence that can be relied on in a dispute, and it replaces neither a certified audit trail nor any retention obligations your business may be under.

It contains personal data within the meaning of the law: account names and working hours. If you employ people, informing them and deciding how long this log is kept is on you.

7. No warranty

Nexika is provided as is, with no warranty of uninterrupted operation, of availability, or of freedom from error. Software can contain defects, including in a permission check or in an authentication.

Do not take a server that starts for a server that is secure. The security of an installation rests as much on the machine, the network, the passwords and the backups as on the program running on it.

8. Limitation of liability

To the extent permitted by law, the publisher is not liable for damages arising from the use of Nexika: loss or disclosure of data, business interruption, unauthorised access, or damage to property.

This limitation does not apply in cases of gross negligence or intent, nor where the law imposes liability that cannot be excluded. Depending on your country, some of these exclusions may have no effect on you.

9. Acceptance

By installing Nexika you acknowledge that you have read these terms and accepted that the security of the machine, the network, the accounts and the backups is your responsibility alone.

If you do not accept these terms, do not install the server. All the applications in the house work without it, each on its own machine.