Your invoice data is sensitive. We treat it that way — security-first architecture, hosted in India on Google Cloud, designed for enterprise compliance requirements.
Data at rest
Data in transit
Data residency
Your data stays yours
Multiple layers of security keep your financial data confidential and protected at every stage.
All invoice data, extracted fields and documents are encrypted with AES-256. Even if storage were compromised, data remains unreadable without keys.
All transmission uses TLS 1.3 — API calls, file uploads and dashboard access are encrypted end-to-end.
Encryption keys are managed through Google Cloud KMS with automatic rotation, never stored alongside encrypted data.
Documents and data live in Google Cloud Storage with redundancy across multiple availability zones within India.
Every access is logged with timestamp, user and action. Audit logs are retained 12 months and available on request.
Google Cloud's enterprise firewall, DDoS protection and 24/7 intrusion detection protect the infrastructure.
Complete transparency on what happens at each step — every step a durable, audited Temporal workflow activity.
TLS 1.3 encrypted
AES-256 encrypted
Isolated environment
GSTIN, 2B, duplicates
Encrypted transfer
Built to meet the compliance standards Indian enterprises and their auditors expect.
The NexumFlow application, database and primary customer storage are hosted in Google Cloud's Mumbai (asia-south1) region. AI-processing locations and controls are configured according to the selected enterprise model endpoint and customer requirements.
Real-time GSTIN validation against the government portal, HSN verification, tax calculation checks, continuous GSTR-2A monitoring with invoice-level 2B/IMS reconciliation.
Complete trail for every invoice — upload, extraction, validation, approval, export — meeting statutory audit requirements.
Configurable retention policies. Delete on request. Export your data anytime in standard formats.
Clear policies on how we handle your data. No hidden terms.
| Policy | Our commitment |
|---|---|
| Data ownership | You own your data. We process it on your behalf. Export or delete it anytime. |
| AI training | Your invoice data is never used to train our AI models or any third-party models. |
| Third-party sharing | Never sold. Processed only by approved cloud and AI sub-processors under enterprise agreements, or as required by law. |
| Sub-processors | Google Cloud (infrastructure), Google Gemini via Vertex AI (document intelligence), Anthropic Claude (AI reasoning), Temporal (workflow orchestration). All bound by DPAs. |
| Data retention | Default 7 years for statutory compliance, configurable per customer. Deleted data purged within 30 days. |
| Data export | Export everything in JSON/CSV anytime. No lock-in. |
| Breach notification | Affected customers notified within 72 hours. |
| Employee access | NexumFlow staff can only access customer data with explicit permission for support. All access is logged. |
Application, database and primary customer storage in GCP asia-south1 — aligned with India's data-localization expectations for financial data.
Multi-zone deployment, automatic failover, 99.9% uptime SLA, backups every 6 hours with point-in-time recovery.
Admin, Approver, Viewer roles with granular permissions. Users only see what they need.
Multi-factor authentication for all accounts; SAML 2.0 SSO for enterprise identity providers.
Restrict access by IP range. API access via rotating secure tokens with rate limiting.
Complete audit log of user actions — who did what, when — exportable for compliance reporting.
We're happy to walk through our security practices, complete vendor security reviews, or address specific compliance requirements for your organization.