Trust

Security, compliance, data residency.

One page, no marketing fluff. What we encrypt, what we log, where your data lives, which sub-processors see it. Built for both India and the United States from day one — not retrofitted as an "international add-on."

Secure infrastructure for financial documents

Security

What protects your data today.

  • ▸AES-256-GCM field encryption for tax IDs (PAN, GSTIN), bank accounts, SSNs and connected-mailbox tokens. Aadhaar numbers are never stored in full: only a hash and the last four digits.
  • ▸TLS in transit on every page and API. HSTS enabled for one year, including subdomains.
  • ▸Role-based access (Owner, Admin, Manager, Member, Viewer) with per-module permissions. CA and CPA practitioners work in their own portals.
  • ▸Single sign-on via WorkOS (SAML 2.0, Okta, Azure AD, Google Workspace) and SCIM directory sync. Passkeys and per-device session revocation.
  • ▸Inbound webhooks from payment, e-signature and email providers are signature-checked with HMAC-SHA256 and a constant-time compare.
  • ▸Support impersonation (Ghost Mode) is read-only: writes are blocked at the request layer, and every session is logged with actor, target and IP.

On-chain proof

Signed agreements anchored to Solana, with a public page to verify them.

  • ▸On Pro and Enterprise plans, every completed agreement, and every invoice you seal, has its SHA-256 hash anchored on Solana mainnet in a batched Merkle record.
  • ▸Public verify page: anyone can check a signed agreement without a Nijam login.
  • ▸A circuit breaker and retry queue re-anchor anything a network hiccup delayed.
  • ▸The anchor on Solana is public and permanent. Checking one document against it uses the proof we keep with the anchor record.

Compliance

The rules the product is built around, stated plainly.

  • ▸India: electronic signatures under the Information Technology Act 2000 §5. Aadhaar eSign (§3A) is not available yet. DPDPA 2023 data-subject requests handled through our privacy request flow.
  • ▸United States: E-SIGN Act and UETA consent at signing. A Circular 230 engagement-letter template for CPAs.
  • ▸European Union: access, correction and deletion requests are handled through the same privacy request flow. There is no EU hosting region.

Data residency

One region today: US East. Here is exactly what that means.

  • ▸Every workspace, in every country, is stored in one region: AWS US East (N. Virginia), on Supabase Postgres. That includes workspaces for Indian and UAE businesses.
  • ▸There is no India, UAE or EU hosting region yet. If a contract or regulator requires your data to stay in a particular country, talk to us before you sign up.
  • ▸Solana anchoring is a public-ledger write — only the SHA-256 hash leaves the region, never the underlying document content.

Sub-processors

The third-party services that can touch your data, named.

  • ▸Database, sign-in and file storage: Supabase (AWS us-east-1). Application hosting: Vercel.
  • ▸Email: Resend. SMS and voice: Twilio (US), Exotel (India).
  • ▸AI inference: DeepSeek (primary text model), Google Gemini (documents and images), with Anthropic and OpenAI as fallbacks; Sarvam (Indian-language speech) and Deepgram (transcription).
  • ▸Video interviews and meeting recording: LiveKit, Recall.ai.
  • ▸Payments: Stripe (United States), Razorpay (India). Bank connections: Plaid (US), Setu (India).
  • ▸India tax and identity APIs: Sandbox.co.in (GST, Aadhaar OTP check), AppyFlow (GSTIN lookup).
  • ▸Single sign-on and directory sync: WorkOS. Caching and rate limiting: Upstash. Error monitoring: Sentry.
  • ▸Public records for background checks: CourtListener, PACER, SAM.gov, eCourts India.
  • ▸Blockchain anchoring: a Solana RPC provider (the document hash only).
  • ▸Only if you connect them: Google, Microsoft, QuickBooks Online, Salesforce.

Incident response

What we do when something goes wrong.

  • ▸Live service status: nijam.co/status.
  • ▸Data breach notification: within 72 hours for personal data per DPDPA + GDPR, per IT Act SPDI Rules for sensitive personal data.
  • ▸Backups: daily managed Postgres backups, kept for 7 days.

Need the security questionnaire?

Send us your security questionnaire (CAIQ, SIG or your own format) with your jurisdiction and the framework you're evidencing, and we'll answer it.

Talk to us