Security

Secure, private, European.

Everything that enters Nodex is treated like an accounting record: encrypted, isolated, kept in the European Union. Because your numbers are nobody else's business.

Data in the EU

Nothing leaves the European Union. The database, your files, document reading and the AI assistant all run on European infrastructure in normal operation.

Database: Ireland

Your firm's data lives in a database hosted in Ireland, in the European Union.

Files: European jurisdiction

Uploaded PDFs and documents sit on storage configured for European jurisdiction.

Documents read in Paris

Scanned invoices are read by a European provider. Processing happens in Paris.

AI on EU cloud regions

The fiscal assistant runs on European cloud regions. Your questions stay on the continent.

Isolation and encryption

Every firm is isolated in the database itself. The app is not the only thing separating your data: every table carries row-level access rules, so one firm's data is invisible to any other at the lowest layer.

Row-level isolation

Access rules live in the database, not just in the app. Another firm's data does not exist for your account.

Encrypted in transit

Every connection is TLS encrypted. Nothing travels in the clear between you and Nodex.

Encrypted at rest

Data is encrypted on disk too, not just on the way.

Sessions with asymmetric keys

Authentication uses modern tokens, signed asymmetrically. The server verifies a signature, not a shared secret.

Roles and permissions

Staff and accountants see exactly what their role allows. Nothing more.

A strict content policy

The app runs with a Content-Security-Policy that only allows declared sources. Foreign code has no way in.

Continuous backups

The database is backed up continuously, with point-in-time restore.

Proof and the law

Built for the day of the audit. Fiscal documents and the history of actions cannot be rewritten. Not by you, not by us. Exactly what an inspector wants to see.

A sealed 10-year archive

Finalized PDFs are stored under object lock: they cannot be modified or deleted, not even by us. Kept for 10 years, as Romanian accounting law requires.

An append-only audit log

Every intentional action is recorded in a log that accepts no edits. Kept for 5 years, per Law 36/2023.

Failures leave a trace too

Failed actions are recorded just like successful ones. A complete history, not a convenient one.

GDPR

Your rights, built into the product. Not a PDF form and a 30-day promise: erasure and personal-data protection are features of the app.

Erasure on request

Scrub a customer's personal data irreversibly, straight from the app. Only what invoicing law requires to stay, stays.

Photos without traces

Uploaded photos are stripped of EXIF metadata and location before storage.

AI that does not learn from your data

The AI providers we work with do not train their models on your data. It is in the contract.

What we do not claim yet

No compliance theater. We prefer a short, true list over a page of badges. What we do not have yet, you can read below.

SOC 2 or ISO 27001 certificationplanned

Not yet. We are a small team, and formal certification comes with scale. Everything this page describes already exists in the product.

A published penetration testplanned

We have not yet published a third-party security audit. When we do, the result will appear here.

An uptime SLAplanned

We do not yet sign contractual percentages. We only promise what we can keep.

Questions about security?

Found a vulnerability? Tell us directly: we answer fast.