Security

How Nimbill protects your billing data — built for Indian SMBs and enterprise franchise networks.

Encryption in transit

TLS 1.2+ on all public endpoints (nimbill.io, app, api). HSTS recommended on nginx.

Tenant isolation

Every API request is scoped by tenantId from JWT. Row-level isolation in PostgreSQL.

Audit trail

Create/update/delete logged per user with IP and timestamp. Super-admin audit for platform ops.

Secrets & integrations

Connector credentials encrypted at rest (INTEGRATION_ENC_KEY). API keys with scopes.

Access control

RBAC per screen, optional IP allowlist, separate CA portal and customer portal tokens.

Compliance & data residency

Production API hosted on our VPS with PostgreSQL and Redis. Invoice and tax data stored per tenant. Data export available in-app.

Report security issues: hello@nimbill.io

Privacy policy · Account deletion