The security page that tells you what we have not done yet.
Every vendor security page lists encryption and access control. The useful part is the boundary — what is protected, what is not covered, and which claims we are not entitled to make. This page covers all three.
How the platform is built.
Tenant isolation, enforced server-side
The business workspace is the tenant boundary. Every query and command is scoped to it on the server, and the workspace identifier is never read from a request body. A dedicated isolation test suite runs forever after, not once at launch.
Authorization on every operation
Each protected operation checks the authenticated user, business membership, permission and subscription entitlement. Hiding a button in the browser is a UX nicety, never the control.
Encryption in transit and at rest
TLS everywhere with HSTS, and platform encryption on the database, file storage and message queues.
Least-privilege identities
Separate managed identities for the API, the background worker and the migration job, each holding only the permissions it needs. The application identity cannot alter the database schema.
Uploads handled carefully
Logos and attachments are checked on their detected type, size-limited, renamed on the server, stored in private containers and served only through short-lived signed links. SVG is not accepted as a logo, because SVG can carry script.
Secrets never in the repository
Secrets live in Azure Key Vault, reached through managed identity. No secret appears in source control, infrastructure templates or pipeline configuration.
Where your data actually lives.
All application data is pinned to Microsoft Azure’s Canada Central region: the PostgreSQL database, your uploaded logos and attachments, the message queues, the email service and the application telemetry. This is configured in infrastructure, not policy, so it cannot drift.
What sits with Microsoft Entra
Sign-in is delegated to Microsoft Entra External ID, which holds your login identity — your email, display name and the sign-in methods you linked — not your invoices, clients or documents. Our directory is created in Canada Central. If precise residency of identity data matters to your organization, ask us before you sign up.
We do not store your password.
There is no custom authentication system in NextiaInvoices. Authentication is delegated entirely to Microsoft Entra External ID — which means there is no password database here to breach.
Sign in the way you already do
Google, Microsoft, Apple, or email and password with a verification code.
One account for every Nextia product
The same Nextia account signs you in to NextiaInvoices, NextiaTax and NextiaBooking. Sign-in, verification codes and account recovery are run by Microsoft Entra External ID.
Fresh sign-in for sensitive changes
Sensitive account and business changes ask you to have signed in recently.
Staff access is recorded
If Nextia support ever needs to act inside your business, it is with a recorded reason, and every such session is audited.
The link your client opens is the biggest external surface. We treat it that way.
Every invoice and quotation has a public view reached without a login, which makes that token the most exposed thing we operate. Its design reflects that.
At least 256 bits of entropy
Generated with a cryptographically secure random generator. Guessing one is not a practical attack.
Stored hashed
The raw token is shown to you once and never persisted, so a database copy does not hand over anyone’s documents.
Not enumerable
An invalid token and a revoked token return the same response, through a constant-time lookup, rate-limited per token and per address.
Revocable and scoped
Revoke a link any time and issue a new one. The view shows that one document and your branding — never another record, never another client.
A trail that cannot be quietly edited.
Audit rows are written in the same database transaction as the change they describe — an audit write that fails rolls the action back, because an unaudited sensitive change is worse than a failed one. The application has no update or delete path to the audit table, and its database role is not granted those privileges.
- Business created or updated
- Team invitation and role change
- Client, service and tax changes
- Invoice created, finalized, sent or cancelled
- Payment-status change
- Quotation acceptance
- Payment-URL change
- Subscription change
- Support access and impersonation
- Credit notes, refunds and write-offs
What we are entitled to say — and what we are not.
Our own specification forbids claiming a compliance posture we have not achieved. So here is the split, plainly. We would rather lose a deal to a competitor with a certification than win one with an implication.
- Designed around Canadian privacy expectations
- Your invoicing data exportable as CSV at any time
- Application data resident in Azure Canada Central
- Audit logging, tenant isolation and least-privilege access built in from the start
- SOC 2 — not audited (work under way)
- ISO 27001 — not certified
- PIPEDA certification — no such certification is claimed
- Penetration-test report — not yet available to share
Who else touches the data.
A short list, kept short deliberately. Each entry exists because the alternative was building it ourselves worse.
| Sub-processor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Application hosting, database, file storage, queues, telemetry | Canada Central |
| Microsoft Entra External ID | Authentication and identity directory | Canada Central (see the note above) |
| Azure Communication Services | Transactional email delivery to you and your clients | Canada Central |
| Azure OpenAI Service | Optional AI invoice drafting | Canada Central (resource and stored data); prompts may be processed in other Azure regions |
| Stripe | Our own subscription billing — never your clients’ payments | Global (Stripe-controlled) |
| Cloudflare | This marketing website and its content delivery | Global edge network |
Where is my data stored?
Your business data — the database and your files — is stored in Microsoft Azure’s Canada Central region. Sign-in runs on Microsoft Entra External ID; the security page explains what that holds.
Do you store my password?
No. Sign-in is handled by Microsoft Entra External ID — Google, Microsoft, Apple, or email and password. Nextia never sees your password.
Are you SOC 2 or ISO 27001 certified?
No, and we will not imply otherwise. We will claim a certification only when an audit is complete.
Can I export my data?
Yes. Export invoices, lines, payments, credit notes and a tax summary as CSV at any time.
Who at Nextia can see my invoices?
Support staff act inside a business only with a recorded reason, and every such session is audited.
Found something? Tell us before you tell the internet.
If you believe you have found a security vulnerability, email us with enough detail to reproduce it. We will acknowledge you, keep you updated while we fix it, and credit you if you would like to be credited. We will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service disruption.
Report a vulnerability — security@nextiainvoices.comSend your first invoice in under five minutes.
Set up your business, add a service, and bill a client — all before your coffee gets cold.
Free plan, forever · 14-day Pro trial, no credit card · Nothing locked or deleted when it ends