🔒

Enterprise-grade security & compliance

Your invoice data is sensitive. We treat it that way — security-first architecture, hosted in India on Google Cloud, designed for enterprise compliance requirements.

🔐

AES-256 Encryption

Data at rest

🌐

TLS 1.3

Data in transit

🇮🇳

GCP India Region

Data residency

🚫

No AI Training

Your data stays yours

How we protect your data

Multiple layers of security keep your financial data confidential and protected at every stage.

🔐

Encryption at rest

All invoice data, extracted fields and documents are encrypted with AES-256. Even if storage were compromised, data remains unreadable without keys.

🌐

Encryption in transit

All transmission uses TLS 1.3 — API calls, file uploads and dashboard access are encrypted end-to-end.

🔑

Key management

Encryption keys are managed through Google Cloud KMS with automatic rotation, never stored alongside encrypted data.

🗄️

Secure storage

Documents and data live in Google Cloud Storage with redundancy across multiple availability zones within India.

🔍

Access logging

Every access is logged with timestamp, user and action. Audit logs are retained 12 months and available on request.

🛡️

Network security

Google Cloud's enterprise firewall, DDoS protection and 24/7 intrusion detection protect the infrastructure.

How your invoice data flows through NexumFlow

Complete transparency on what happens at each step — every step a durable, audited Temporal workflow activity.

📥

Invoice Upload

TLS 1.3 encrypted

🔒

Secure Storage

AES-256 encrypted

🤖

AI Processing

Isolated environment

Validation

GSTIN, 2B, duplicates

📤

ERP Export

Encrypted transfer

Compliance & certifications

Built to meet the compliance standards Indian enterprises and their auditors expect.

🏛️

Data localization

The NexumFlow application, database and primary customer storage are hosted in Google Cloud's Mumbai (asia-south1) region. AI-processing locations and controls are configured according to the selected enterprise model endpoint and customer requirements.

📋

GST compliance

Real-time GSTIN validation against the government portal, HSN verification, tax calculation checks, continuous GSTR-2A monitoring with invoice-level 2B/IMS reconciliation.

📊

Audit trail

Complete trail for every invoice — upload, extraction, validation, approval, export — meeting statutory audit requirements.

🗑️

Data retention

Configurable retention policies. Delete on request. Export your data anytime in standard formats.

Certification status

ActiveGCP SOC 1/2/3 certified infrastructure
ActiveTLS 1.3 & AES-256 encryption
ActiveIndia data residency (asia-south1)
In ProgressISO 27001 certification
In ProgressSOC 2 Type II audit
PlannedGDPR compliance (EU expansion)

Your data, your control

Clear policies on how we handle your data. No hidden terms.

PolicyOur commitment
Data ownershipYou own your data. We process it on your behalf. Export or delete it anytime.
AI trainingYour invoice data is never used to train our AI models or any third-party models.
Third-party sharingNever sold. Processed only by approved cloud and AI sub-processors under enterprise agreements, or as required by law.
Sub-processorsGoogle Cloud (infrastructure), Google Gemini via Vertex AI (document intelligence), Anthropic Claude (AI reasoning), Temporal (workflow orchestration). All bound by DPAs.
Data retentionDefault 7 years for statutory compliance, configurable per customer. Deleted data purged within 30 days.
Data exportExport everything in JSON/CSV anytime. No lock-in.
Breach notificationAffected customers notified within 72 hours.
Employee accessNexumFlow staff can only access customer data with explicit permission for support. All access is logged.

Built on Google Cloud, controlled by you

🇮🇳

India region (Mumbai)

Application, database and primary customer storage in GCP asia-south1 — aligned with India's data-localization expectations for financial data.

High availability

Multi-zone deployment, automatic failover, 99.9% uptime SLA, backups every 6 hours with point-in-time recovery.

👤

Role-based access

Admin, Approver, Viewer roles with granular permissions. Users only see what they need.

🔑

MFA & SSO

Multi-factor authentication for all accounts; SAML 2.0 SSO for enterprise identity providers.

🌐

IP allowlisting & API security

Restrict access by IP range. API access via rotating secure tokens with rate limiting.

📝

Activity logs

Complete audit log of user actions — who did what, when — exportable for compliance reporting.

Have security questions?

We're happy to walk through our security practices, complete vendor security reviews, or address specific compliance requirements for your organization.