How Nimbill protects your billing data — built for Indian SMBs and enterprise franchise networks.
TLS 1.2+ on all public endpoints (nimbill.io, app, api). HSTS recommended on nginx.
Every API request is scoped by tenantId from JWT. Row-level isolation in PostgreSQL.
Create/update/delete logged per user with IP and timestamp. Super-admin audit for platform ops.
Connector credentials encrypted at rest (INTEGRATION_ENC_KEY). API keys with scopes.
RBAC per screen, optional IP allowlist, separate CA portal and customer portal tokens.
Production API hosted on our VPS with PostgreSQL and Redis. Invoice and tax data stored per tenant. Data export available in-app.
Report security issues: hello@nimbill.io