Security
Financial data deserves more than a privacy page
NanoFora holds ledgers, statements and forecasts. The controls below are structural, not policies we intend to add later.
Row-level tenant isolation
Every table carries a company reference and is protected by database policies. A query issued for one company physically cannot return another company's rows, regardless of application behaviour.
Role-based access control
Eight roles — owner, admin, CFO, accountant, analyst, manager, employee and viewer — map to an explicit permission matrix that is checked server-side on every action.
Authentication
Email and password with confirmation, plus Google sign-in. Sessions are short-lived and refreshed, and privileged operations re-verify the caller's role.
Document storage
Uploaded documents live in per-company storage paths with access mediated by the same policy layer that governs database access.
Immutable audit trail
Creation, modification, access and deletion events are logged with actor, target and timestamp. Log entries cannot be edited by application users.
Encryption
Data is encrypted in transit with TLS and at rest by the underlying managed infrastructure.
AI safety
How the AI is constrained
The AI never sees another company's data
Every model request is scoped to the requesting company's records. There is no shared context between tenants and your data is not used to train shared models.
Numbers are computed, not generated
Financial figures come from deterministic queries and formulas. Language models interpret the question and explain the result — they never invent the value.
Uncertainty is stated, not hidden
Where data is incomplete or an extraction is low-confidence, NanoFora reports the limitation rather than presenting a confident-looking guess.
You can always check the working
Every figure links back through the transactions to the document page it came from, so any conclusion can be independently verified.
Reporting a vulnerability
If you believe you have found a security issue, contact us before disclosing it publicly. We acknowledge reports within two business days and will keep you updated until the issue is resolved. We do not pursue legal action against researchers who report in good faith and avoid accessing other customers' data.
security@nanofora.com
