Legal
Security
Effective 14 May 2026
Your billing data is sensitive. We treat it that way. This page summarises the technical and organisational controls we use to protect it.
1.Encryption
- All traffic between your browser and DNexus Billing uses HTTPS (TLS 1.2+).
- Database storage is encrypted at rest with AES-256.
- Off-site backups are encrypted before they leave the production network.
- Passwords are hashed with bcrypt; we never store or display plain-text passwords.
2.Access control
- Production database access is limited to a small set of named engineers.
- Engineer access requires SSH keys (no password logins) and is audited.
- Inside your account, role-based permissions (Owner, Admin, Accountant, Sales, Viewer) restrict what each user can see and do.
- Sessions expire on inactivity. You can sign out of all devices from Settings → Account.
3.Hosting and isolation
DNexus Billing runs on hardened Linux servers located in India. Each customer’s data is logically isolated by tenant (businessId) and accessed only via authenticated, authorised application code.
4.Backups
- Full encrypted database backups taken daily.
- Point-in-time recovery available for the last 7 days.
- Retention: 30 days of daily backups, 90 days for full snapshots.
- Restore drills are performed quarterly to verify backups can actually be recovered.
5.Software supply chain
Dependencies are tracked in lockfiles and reviewed before upgrades. Security advisories are monitored and critical patches are deployed within 72 hours of public disclosure.
6.Incident response
We have an internal incident response runbook covering detection, containment, eradication and recovery. Customers affected by a confirmed security incident involving their data will be notified within 72 hours of confirmation, with technical details and recommended actions.
7.Reporting a vulnerability
If you believe you have found a vulnerability in DNexus Billing, please email security@dnexusmedia.com with steps to reproduce. We commit to acknowledging within 2 working days and keeping you updated through resolution. Please give us a reasonable window to address the issue before any public disclosure.
8.What you can do
- Use a strong, unique password and enable browser-level password management.
- Review your team’s roles regularly under Settings → Team and remove members who no longer need access.
- Sign out of shared computers when you’re done.
- Report suspicious account activity to support immediately.
Questions? Email info@dnexusmedia.com or WhatsApp +91 73106 92254.

