Nexora DataEnabler
Home About Solutions Pricing Blog Contact
Tenant Sign inSign in Tenant RegisterRegister Request Demo
Security

Security

How DataEnabler protects every tenant — isolation by design, encryption, RBAC/RLS and full audit.

1. Isolation 2. Encryption 3. Access control 4. Audit 5. Backups 6. Incident response

1. Tenant isolation (RLS)

Every row is scoped to tenant → company with PostgreSQL row-level security (RLS). There is no cross-tenant query path — even Platform super admins cannot read tenant business rows without an explicit, audited grant. All exports and deletes are tenant-scoped.

  • RLS policies on all 138 tables, enforced at the database — not in app filters alone
  • Platform → Tenant → Company hierarchy with immutable tenant_id
  • No shared schema leaks: storage, search and jobs are tenant-isolated

2. Encryption

Data is encrypted in transit and at rest. TLS 1.2+ for every request, AES-256 at rest for database and backups. Secrets (DB creds, signing keys) are stored in a managed vault, never in code or logs.

  • TLS 1.2+ with HSTS, at-rest AES-256 for DB, snapshots and backups
  • Key rotation and vault-managed secrets; no card storage (payments via processor)

3. Access control (RBAC + RLS)

Roles, permissions and RLS policies are per-company. A user only sees modules and rows their role allows. Sessions are short-lived, passwords are hashed, and tenant admins control provisioning/offboarding.

  • Per-company RBAC + RLS — module visibility and row visibility are both enforced
  • Hashed credentials, short-lived sessions, enforced offboarding by tenant admin

4. Audit trail

Finance, Inventory and CRM are fully audited — who changed what, when, from which IP/device. Audit logs are append-only and tenant-isolated, retained per policy and exportable by the tenant admin.

5. Backups & recovery

Automated daily backups, tenant-isolated and encrypted. Point-in-time recovery tested regularly. Retention per plan; tenant admins can export company data anytime from tenant.html.

6. Incident response

We monitor for anomalies, run dependency patching, and maintain an incident runbook. Report security issues to security@dataenabler.com — we acknowledge within one business day and keep the reporting tenant updated until closure.

7. Shared responsibility

You control user provisioning, role assignments and data accuracy of invoices, POs and payroll. We protect the platform, isolation and encryption. Together we keep tenant data accurate and isolated.

8. Contact

Security questions: security@dataenabler.com — Privacy: Privacy Policy — Terms: Terms of Service.

This page is for demo — have your security team review before production.

DataEnabler
Nexora ERP — multi-tenant SaaS for growing companies. Finance, SCM, CRM, Inventory, HR & Commission.
Admin Sign In

Product

Finance SCM CRM HR Commission Inventory Field Force

Company

About Blog Contact Register tenant Tenant Sign in

Legal

Privacy Policy Terms of Service Security Support
© 2026 Nexora / DataEnabler — All rights reserved.