🔒

Enterprise-Grade Security & Compliance

Your invoice data is sensitive. We treat it that way. Built with security-first architecture, hosted in India, and designed for enterprise compliance requirements.

🔐

AES-256 Encryption

Data at rest

🌐

TLS 1.3

Data in transit

🇮🇳

GCP India Region

Data residency

🚫

No AI Training

Your data stays yours

How we protect your data

Multiple layers of security ensure your financial data remains confidential and protected at every stage.

🔐

Encryption at Rest

All invoice data, extracted fields, and documents are encrypted using AES-256 encryption. Even if storage is compromised, data remains unreadable without encryption keys.

🌐

Encryption in Transit

All data transmission uses TLS 1.3, the latest encryption protocol. API calls, file uploads, and dashboard access are all encrypted end-to-end.

🔑

Key Management

Encryption keys are managed through Google Cloud KMS with automatic rotation. Keys are never stored alongside encrypted data.

🗄️

Secure Storage

Invoice documents and extracted data are stored in Google Cloud Storage with redundancy across multiple availability zones within India.

🔍

Access Logging

Every access to your data is logged with timestamp, user ID, and action performed. Audit logs are retained for 12 months and available on request.

🛡️

Network Security

Infrastructure is protected by Google Cloud's enterprise firewall, DDoS protection, and intrusion detection systems monitoring 24/7.

How your invoice data flows through Nexum

Complete transparency on what happens to your data at each step.

📥

Invoice Upload

TLS 1.3 encrypted

🔒

Secure Storage

AES-256 encrypted

🤖

AI Processing

Isolated environment

Validation

GSTIN, duplicates

📤

ERP Export

Encrypted transfer

Compliance & certifications roadmap

We're building Nexum to meet the highest compliance standards for enterprise customers.

🏛️

Data Localization

All customer data is stored exclusively in Google Cloud's Mumbai (asia-south1) region. Data never leaves India.

📋

GST Compliance

Real-time GSTIN validation against government portal. HSN code verification. Tax calculation checks.

📊

Audit Trail

Complete audit trail for every invoice — upload, extraction, validation, approval, export. Meets statutory audit requirements.

🗑️

Data Retention

Configurable retention policies. Delete data on request. Export your data anytime in standard formats.

Certification Status

Active GCP SOC 1/2/3 Certified Infrastructure
Active TLS 1.3 & AES-256 Encryption
Active India Data Residency
In Progress ISO 27001 Certification
In Progress SOC 2 Type II Audit
Q3 2026 GDPR Compliance (for EU expansion)

Your data, your control

Clear policies on how we handle your data. No hidden terms.

Policy Our Commitment
Data Ownership You own your data. We process it on your behalf. You can export or delete it anytime.
AI Training Your invoice data is never used to train our AI models or any third-party models.
Third-Party Sharing Your data is never sold, shared, or disclosed to third parties except as required by law.
Sub-Processors We use Google Cloud (infrastructure), Google Document AI (OCR), and Anthropic Claude (AI reasoning). All bound by DPAs.
Data Retention Default 7 years (for statutory compliance). Configurable per customer. Deleted data is purged within 30 days.
Data Export Export all your data in JSON/CSV format anytime. No lock-in.
Data Deletion Request deletion anytime. Data is permanently removed from all systems within 30 days.
Breach Notification In the unlikely event of a data breach, we notify affected customers within 72 hours.
Employee Access Nexum employees can only access customer data with explicit permission for support purposes. All access is logged.

Built on Google Cloud Platform

We leverage Google Cloud's enterprise-grade infrastructure for reliability, security, and compliance.

🇮🇳

India Region (Mumbai)

All data stored in GCP's asia-south1 region. Compliant with India's data localization requirements for financial data.

High Availability

Multi-zone deployment with automatic failover. 99.9% uptime SLA. Regular backups with point-in-time recovery.

🔄

Disaster Recovery

Automated backups every 6 hours. Cross-region backup replication. Recovery time objective (RTO) under 4 hours.

📈

Scalability

Auto-scaling infrastructure handles traffic spikes seamlessly. Process thousands of invoices without performance degradation.

🔍

Monitoring

24/7 infrastructure monitoring. Real-time alerts for anomalies. Performance metrics tracked and optimized continuously.

🛡️

GCP Security

Inherits Google Cloud's SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, and PCI DSS certifications.

Who can access your data

Strict access controls ensure only authorized personnel can access your data.

👤

Role-Based Access

Define roles (Admin, Approver, Viewer) with granular permissions. Users only see what they need to see.

🔑

Multi-Factor Authentication

MFA available for all accounts. Enforce MFA for admin accounts. Supports authenticator apps and SMS.

🔒

Session Management

Automatic session timeout after inactivity. View active sessions. Remote logout from all devices.

📝

Activity Logs

Complete audit log of all user actions. Who did what, when. Export logs for compliance reporting.

🏢

SSO Integration

SAML 2.0 SSO integration available for enterprise customers. Connect with your existing identity provider.

🌐

IP Whitelisting

Restrict access to specific IP addresses or ranges. Ideal for enterprises with fixed office networks.

🔐

API Security

API access via secure tokens. Token rotation supported. Rate limiting prevents abuse.

👥

Nexum Staff Access

Our team cannot access your data without explicit permission. All support access is logged and auditable.

Have security questions?

We're happy to discuss our security practices in detail, conduct security reviews, or address specific compliance requirements for your organization.