Security
Secure, private, European.
Everything that enters Nodex is treated like an accounting record: encrypted, isolated, kept in the European Union. Because your numbers are nobody else's business.
Data in the EU
Nothing leaves the European Union. The database, your files, document reading and the AI assistant all run on European infrastructure in normal operation.
Database: Ireland
Your firm's data lives in a database hosted in Ireland, in the European Union.
Files: European jurisdiction
Uploaded PDFs and documents sit on storage configured for European jurisdiction.
Documents read in Paris
Scanned invoices are read by a European provider. Processing happens in Paris.
AI on EU cloud regions
The fiscal assistant runs on European cloud regions. Your questions stay on the continent.
Isolation and encryption
Every firm is isolated in the database itself. The app is not the only thing separating your data: every table carries row-level access rules, so one firm's data is invisible to any other at the lowest layer.
Row-level isolation
Access rules live in the database, not just in the app. Another firm's data does not exist for your account.
Encrypted in transit
Every connection is TLS encrypted. Nothing travels in the clear between you and Nodex.
Encrypted at rest
Data is encrypted on disk too, not just on the way.
Sessions with asymmetric keys
Authentication uses modern tokens, signed asymmetrically. The server verifies a signature, not a shared secret.
Roles and permissions
Staff and accountants see exactly what their role allows. Nothing more.
A strict content policy
The app runs with a Content-Security-Policy that only allows declared sources. Foreign code has no way in.
Continuous backups
The database is backed up continuously, with point-in-time restore.
Proof and the law
Built for the day of the audit. Fiscal documents and the history of actions cannot be rewritten. Not by you, not by us. Exactly what an inspector wants to see.
A sealed 10-year archive
Finalized PDFs are stored under object lock: they cannot be modified or deleted, not even by us. Kept for 10 years, as Romanian accounting law requires.
An append-only audit log
Every intentional action is recorded in a log that accepts no edits. Kept for 5 years, per Law 36/2023.
Failures leave a trace too
Failed actions are recorded just like successful ones. A complete history, not a convenient one.
GDPR
Your rights, built into the product. Not a PDF form and a 30-day promise: erasure and personal-data protection are features of the app.
Erasure on request
Scrub a customer's personal data irreversibly, straight from the app. Only what invoicing law requires to stay, stays.
Photos without traces
Uploaded photos are stripped of EXIF metadata and location before storage.
AI that does not learn from your data
The AI providers we work with do not train their models on your data. It is in the contract.
What we do not claim yet
No compliance theater. We prefer a short, true list over a page of badges. What we do not have yet, you can read below.
SOC 2 or ISO 27001 certificationplanned
Not yet. We are a small team, and formal certification comes with scale. Everything this page describes already exists in the product.
A published penetration testplanned
We have not yet published a third-party security audit. When we do, the result will appear here.
An uptime SLAplanned
We do not yet sign contractual percentages. We only promise what we can keep.
Questions about security?
Found a vulnerability? Tell us directly: we answer fast.