How it Works Our Agents Pricing About Us FAQ → Get Started Free
Trust & Safety

Security at NexaForce AI

How we protect your business data, your customers' conversations, and your AI agents.

🔐

Data Isolation

Every client's data is completely isolated using Row-Level Security at the database level. Client A cannot access Client B's data under any circumstances.

🛡️

Encryption

All data in transit is encrypted with TLS 1.3. All data at rest is encrypted with AES-256. API keys and credentials are never stored in plaintext.

🇮🇳

Data Residency

Your data stays in India. All primary storage is in Supabase's Mumbai region (AWS ap-south-1). We do not transfer your business data outside India.

🔑

Access Control

JWT-based authentication with 15-minute access tokens and 7-day refresh tokens. HttpOnly cookies prevent XSS attacks. Rate limiting on all API endpoints.

📊

Monitoring

24/7 uptime monitoring via Uptime Kuma. Real-time error tracking via GlitchTip. All AI generations traced and auditable via LangFuse.

🧪

No Model Training on Your Data

Your conversations and knowledge base documents are never used to train shared AI models. Your data trains only your agent, and only in the way you configure it.

Infrastructure Security

NexaForce AI runs on enterprise-grade infrastructure with multiple layers of security:

Payment Security

All payment processing is handled by Razorpay, a PCI-DSS compliant payment gateway. NexaForce AI never stores, processes, or transmits credit card numbers, UPI credentials, or banking details. Our servers only receive transaction IDs and subscription status from Razorpay after payment completion.

WhatsApp & Voice Security

WhatsApp Business API integration uses official Meta-approved channels via AiSensy. Voice calls through Raj agent use Vapi.ai's encrypted call infrastructure. All call transcripts are stored encrypted and access-controlled to your account only.

Responsible Disclosure

If you discover a security vulnerability in NexaForce AI, please report it responsibly to security@nexaforceai.com. We will acknowledge receipt within 24 hours and work with you to understand and resolve the issue. We appreciate responsible disclosure and will credit researchers who help us improve security.

Please do not publicly disclose vulnerabilities until we have had a reasonable opportunity to address them (typically 90 days).

Contact Security Team

Security issues: security@nexaforceai.com
General security questions: hello@nexaforceai.com
We respond to all security reports within 24 hours.