Security

You are about to hand us your client list and your inbox.

That deserves specifics rather than badges. Here is where the data lives, how the sensitive parts are stored, and what we have not built yet.

Canadian residency

Application, database and backups run in AWS ca-central-1 (Montreal). Data is not replicated to another region.

Encrypted in transit and at rest

HTTPS everywhere, with certificates renewed automatically. Mailbox tokens are sealed with AES-256-GCM under a key held only by the server.

Separated by organisation

Every query is scoped to your organisation, and requests carry that scope from the session rather than from anything the browser sends.

Least mailbox access

Signing in asks only for your name and email address. Gmail and calendar permissions are requested separately, at the moment you connect a mailbox.

Mailbox data

What we do with what is in your inbox.

NexaFlow’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We do

Show your mail against the contact it belongs to, inside your own CRM, for the people in your organisation who already have access to that contact.

We do not

Train models on your mail, sell it, share it with other customers, or let a human read it except with your explicit permission or where the law requires it.

Being honest about the gaps

What is not done yet.

A security page that only lists strengths is not worth reading. These are open, tracked, and being worked through.

Database-level isolation

Tenant separation is enforced in the application today. Moving that enforcement into the database itself, as a second layer behind the first, is in progress.

Google verification

The Gmail permissions we request are restricted scopes, and our verification review with Google, including a third-party security assessment, is under way. Until it completes you will see an unverified-app warning when connecting.

Independent audit

We have no SOC 2 or ISO 27001 report. If your brokerage requires one, tell us before you start rather than after.

Questions we get asked

Plain answers.

Do you read our email?+

Only to show it to you inside your own CRM, once mailbox sync ships. Message content is not used to train any model, is not sold, and is not shared with another customer. Google calls this the Limited Use requirement and we are bound by it.

How is the content of our mail stored?+

In our Canadian database, in the clear, protected by disk encryption, per-organisation row isolation and the residency guarantee — not encrypted a second time at the application layer. That is a deliberate choice: searching your mail and, later, having the assistant summarise a thread both need to read it. Mailbox credentials are a different matter and are encrypted with AES-256-GCM.

What happens when we disconnect a mailbox?+

The stored tokens are deleted immediately, and we ask Google to revoke them. The deletion happens even if that revoke call fails, so our copy is gone either way. Every synced message from that mailbox is deleted with it. You can also revoke access yourself from your Google or Microsoft account page.

Who at NexaFlow can see our records?+

Engineering access to production is limited to the people who operate it, used for support and incidents, and is not a routine part of anyone’s day. We are a small company and would rather say that plainly than imply a bigger process than exists.

Are you SOC 2 certified?+

No. We are a young company and do not hold a SOC 2 report. If that is a requirement for you, say so before you start a trial rather than after — we would rather lose the deal early than surprise you later.

How do we report a security problem?+

Email info@nexaflowsystems.com with "security" in the subject, or call +1 844-482-3336. We will confirm receipt and tell you what we find.

See also the privacy policy, the terms of service, and live system status.