Security & Compliance

Trust Center

Security, Reliability & Responsible AI — how Ataraxy Solutions Private Limited designs, operates, and continuously improves the Nurexify platform.

Last Updated: July 25, 2026

OUR COMMITMENT

Five principles that guide everything we build

Protect Customer Data

Your data belongs to you. We process it only to deliver the contracted service.

Maintain Availability

Resilient infrastructure designed to support continuous business operations.

Respect Privacy

DPDP Act and GDPR-aligned privacy practices baked in from day one.

Build Responsible AI

AI that assists, never replaces, professional judgment — with full auditability.

Continuously Improve

Our security programme evolves to address emerging threats and customer expectations.

ENTERPRISE SECURITY

Defence-in-depth security architecture

Encryption

  • Data in transit secured with industry-standard TLS protocols
  • Sensitive data encrypted at rest where appropriate
  • Secure management of encryption keys and credentials

Identity & Access

  • Role-Based Access Control (RBAC) with granular permissions
  • Department-based and project-level access scoping
  • Multi-factor authentication (MFA) where enabled
  • Session management, account lockout, and audit trails

Infrastructure

  • Firewalls and network segmentation
  • Continuous security monitoring and logging
  • Vulnerability management and timely remediation
  • Controlled deployment processes

Application Security

  • Secure coding standards and code reviews
  • Dependency management and security testing
  • Configuration management
  • Secure software development lifecycle

Backup & Recovery

  • Regular automated backups of customer data
  • Recovery processes to minimise data loss
  • Disaster recovery planning and testing
  • Operational continuity safeguards

Monitoring & Response

  • 24/7 operational monitoring for anomalies
  • Incident assessment, containment, and recovery
  • Root cause analysis and preventive improvements
  • Customer communication where legally required
RESPONSIBLE AI

AI that earns trust

20 autonomous agents across Sales, CRM, Marketing, MIS, Finance, and Operations — all governed by these principles.

Human Oversight

AI agents — including Lead Responder, Collections Followup, Daily Briefing, Budget Guard, and 16 others — assist users rather than replace professional judgment. All AI-generated outputs should be reviewed before making business, legal, financial, or regulatory decisions.

Transparency

Where practical, users are informed when content has been generated or assisted by AI. Our 20-agent workforce is clearly identified within the platform.

Privacy by Design

AI features are designed to process only the information necessary to perform the requested task, subject to applicable agreements and privacy commitments.

Security

AI services are incorporated into our broader security programme and are subject to appropriate access controls and operational safeguards.

Continuous Improvement

We evaluate and improve AI capabilities over time while seeking to minimise inaccurate or misleading outputs.

COMPLIANCE

Built for India. Ready for the world.

Nurexify is designed with privacy and security considerations aligned with India's regulatory environment and international standards.

DPDP Act (India)

Digital Personal Data Protection Act compliance — data localisation, consent management, and data principal rights.

GDPR (EU)

Where applicable to our services or customers — data minimisation, lawful basis, and data subject rights.

RERA

Real Estate (Regulation and Development) Act compliance baked into Construction, Finance, and CRM modules.

Customer Responsibilities

Security is a shared responsibility. Customers should:

  • Protect account credentials and enable MFA where available
  • Assign user permissions carefully and review access regularly
  • Remove inactive accounts and maintain secure endpoint devices
  • Keep integrated systems (including Tally) up to date
  • Report suspected security issues promptly to [email protected]
COMMON QUESTIONS

Trust & Security FAQ

Who owns my data?

Your organisation retains full ownership of all Customer Data stored within Nurexify. Nothing in our Terms of Service transfers ownership to Ataraxy.

Does Nurexify sell customer information?

No. We do not sell, rent, or trade customer data to any third party.

Is AI mandatory?

No. AI-enabled features are optional where applicable. Customers choose whether and how to use AI capabilities based on their subscription.

How is Tally integration secured?

Our Tally integration uses a read/pull-based sync pipeline. The connection is secured via encrypted API calls and processes only the data necessary for accounting reconciliation.

Does Nurexify support RERA compliance?

Yes. RERA compliance controls — including escrow tracking, milestone reporting, and penalty alerts — are built into the Construction and Finance modules.

What should I do if I suspect unauthorised access?

Contact [email protected] immediately. Our team will investigate and provide appropriate response guidance.

Responsible Disclosure

If you believe you have discovered a security vulnerability affecting Nurexify, please notify us. Include a description, steps to reproduce, impact assessment, and supporting evidence. We ask that researchers avoid actions that could disrupt services or compromise customer data.

[email protected]

Contact Us

For questions relating to security, privacy, or compliance:

For all security, privacy, compliance, and general enquiries:

[email protected]