Security & Compliance · UAE

Trust Center

Security, Reliability & Responsible AI — how Ataraxy Solutions Private Limited, a company registered in India, designs, operates, and continuously improves the Nurexify platform for customers in the UAE and worldwide.

Last Updated: September 27, 2026

OUR COMMITMENT

Five principles that guide everything we build

Protect Customer Data

Your data belongs to you. We process it only to deliver the contracted service.

Maintain Availability

Resilient infrastructure designed to support continuous business operations.

Respect Privacy

DPDP Act and GDPR-aligned privacy practices, with UAE PDPL alignment as our UAE operations grow.

Build Responsible AI

AI that assists, never replaces, professional judgment — with full auditability.

Continuously Improve

Our security programme evolves to address emerging threats and customer expectations.

ENTERPRISE SECURITY

Defence-in-depth security architecture

Encryption

  • Data in transit secured with industry-standard TLS protocols
  • Sensitive data encrypted at rest where appropriate
  • Secure management of encryption keys and credentials

Identity & Access

  • Role-Based Access Control (RBAC) with granular permissions
  • Department-based and project-level access scoping
  • Multi-factor authentication (MFA) where enabled
  • Session management, account lockout, and audit trails

Infrastructure

  • Firewalls and network segmentation
  • Continuous security monitoring and logging
  • Vulnerability management and timely remediation
  • Controlled deployment processes

Application Security

  • Secure coding standards and code reviews
  • Dependency management and security testing
  • Configuration management
  • Secure software development lifecycle

Backup & Recovery

  • Regular automated backups of customer data
  • Recovery processes to minimise data loss
  • Disaster recovery planning and testing
  • Operational continuity safeguards

Monitoring & Response

  • 24/7 operational monitoring for anomalies
  • Incident assessment, containment, and recovery
  • Root cause analysis and preventive improvements
  • Customer communication where legally required
RESPONSIBLE AI

AI that earns trust

20 autonomous agents across Sales, CRM, Marketing, MIS, Finance, and Operations — all governed by these principles.

Human Oversight

AI agents — including Lead Responder, Collections Followup, Daily Briefing, Budget Guard, and 16 others — assist users rather than replace professional judgment. All AI-generated outputs should be reviewed before making business, legal, financial, or regulatory decisions.

Transparency

Where practical, users are informed when content has been generated or assisted by AI. Our 20-agent workforce is clearly identified within the platform.

Privacy by Design

AI features are designed to process only the information necessary to perform the requested task, subject to applicable agreements and privacy commitments.

Security

AI services are incorporated into our broader security programme and are subject to appropriate access controls and operational safeguards.

Continuous Improvement

We evaluate and improve AI capabilities over time while seeking to minimise inaccurate or misleading outputs.

COMPLIANCE

Compliant by design, wherever you operate.

Nurexify is designed with privacy and security considerations aligned with regional regulatory requirements and international standards, including for our UAE customers.

DPDP Act (India)

Digital Personal Data Protection Act compliance — data localisation, consent management, and data principal rights.

GDPR (EU)

Where applicable to our services or customers — data minimisation, lawful basis, and data subject rights.

UAE PDPL

As our UAE operations grow, we monitor and work towards alignment with the UAE’s Personal Data Protection Law alongside our existing DPDP Act and GDPR-aligned practices.

RERA / DLD

India RERA and UAE Dubai Land Department (DLD) compliance controls — escrow tracking, milestone reporting, and registration tracking — built into the Construction and Finance modules.

Customer Responsibilities

Security is a shared responsibility. Customers should:

  • Protect account credentials and enable MFA where available
  • Assign user permissions carefully and review access regularly
  • Remove inactive accounts and maintain secure endpoint devices
  • Keep integrated systems (including Tally) up to date
  • Report suspected security issues promptly to [email protected]
COMMON QUESTIONS

Trust & Security FAQ

Who owns my data?

Your organisation retains full ownership of all Customer Data stored within Nurexify. Nothing in our Terms of Service transfers ownership to Ataraxy.

Does Nurexify sell customer information?

No. We do not sell, rent, or trade customer data to any third party.

Is AI mandatory?

No. AI-enabled features are optional where applicable. Customers choose whether and how to use AI capabilities based on their subscription.

How is Tally integration secured?

Our Tally integration uses a read/pull-based sync pipeline. The connection is secured via encrypted API calls and processes only the data necessary for accounting reconciliation.

Does Nurexify support DLD compliance for UAE developers?

Yes. DLD project registration tracking, Oqood unit-registration tracking, and escrow milestone reporting are built into the Construction and Finance modules for UAE clients.

What should I do if I suspect unauthorised access?

Contact [email protected] immediately. Our team will investigate and provide appropriate response guidance.

Responsible Disclosure

If you believe you have discovered a security vulnerability affecting Nurexify, please notify us. Include a description, steps to reproduce, impact assessment, and supporting evidence. We ask that researchers avoid actions that could disrupt services or compromise customer data.

[email protected]

Contact Us

For questions relating to security, privacy, or compliance:

For all security, privacy, compliance, and general enquiries:

[email protected]