Security & Compliance
Overview
NEXOS is built on enterprise-grade infrastructure with security at every layer. Your financial documents contain sensitive business data — we treat them accordingly.
Infrastructure
- Hosting — tier-1 cloud provider, US region
- Database — managed relational database with encryption at rest
- CDN — edge content delivery network with strict transport security
- Cache — managed in-memory cache with encrypted transit
- Email — managed transactional email with DKIM and SPF
Data Encryption
- All data encrypted at rest using current industry-standard algorithms
- All data in transit encrypted via modern TLS
- Database and integration credentials managed via secure secret storage
- API keys hashed — never stored in plaintext
Multi-Tenant Architecture
NEXOS uses per-tenant database isolation. Every organization's data is fully isolated in its own database namespace. There is no shared data layer between tenants — your data is physically separated from every other account.
Authentication
- Industry-standard session authentication with secure tokens
- Session tokens invalidated on logout
- OAuth 2.0 for QuickBooks and Xero integrations — tokens wiped immediately on disconnect
Monitoring
- Real-time application monitoring
- Error tracking and crash reporting
- Automated alerting for anomalous activity
Data Retention
Document data is retained for the life of your account. Upon account cancellation, data is retained for 30 days before permanent deletion, giving you time to export your records.
Export & Portability
Export all invoices, receipts, and extracted data at any time from Settings → Data Export in CSV or JSON format.