Security

Built to earn the trust you're placing in it

You're giving Nexioli access to customer communication — one of the most sensitive parts of your business. Here's exactly how we protect it.

Google OAuth
Encrypted in transit & at rest
Isolated per company
Built on Google Cloud & Firebase

How we protect you

Six layers of protection, working together

Not one feature bolted on — security built into how Nexioli is architected, from the database up.

Strict data isolation

Every business's data — conversations, customers, knowledge, settings — is completely isolated from every other business. There is no shared access path between companies, enforced at the database level, not just in application code.

Secure Gmail connection

Connect through Google's own sign-in. We never see, request, or store your email password.

You're always in control

Choose when Nexioli sends on its own. Emergency Stop pauses everything instantly.

Full audit logging

Every meaningful action — logins, integration changes, AI replies, approvals, Emergency Stop events — is logged. If something happens on your account, you can see exactly what and when.

Built on trusted infrastructure

Nexioli runs on Google Cloud and Firebase infrastructure, the same platforms trusted by companies handling sensitive data at massive scale. We don't run undifferentiated infrastructure ourselves.

Encryption everywhere

Data is encrypted in transit using TLS and at rest using our infrastructure provider's encryption standards. Sensitive credentials are stored in dedicated secret management, never in application databases.

Isolated by design

Your data is never visible to anyone else.

Every business's conversations, customers, and knowledge are completely separated — enforced at the database level, not just in application code. Every connection, token refresh, and Emergency Stop event is logged, so you can always see exactly what happened on your account.

nexioli.com/settings?tab=safety

Company A

Conversations, knowledge, settings

Company B

Conversations, knowledge, settings

No shared access path — enforced at the database level

Connection audit log
  • Gmail connected via Google OAuthAug 12
  • Emergency Stop tested — passedAug 20
  • Access token rotated automaticallyToday

Our approach to compliance

Nexioli is built on infrastructure designed to meet rigorous compliance standards, and we're working toward formal certifications such as SOC 2 as we scale. We believe in being direct about where we are today rather than displaying certifications we haven't earned yet.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Gmail content is processed to sync the connected support inbox, draft replies, and send mail you approve — not to train foundational or generalized AI models. Details: Privacy Policy, Limited Use.

Where we stand today

  • TLS encryption in transit, provider-grade encryption at rest
  • Secrets and access tokens stored in dedicated secret management — never in application databases
  • Full audit logs for every meaningful account action
  • Gmail / Workspace API data is used only to provide the product (sync, draft, send) — not to train generalized AI models. We adhere to Google’s Limited Use requirements
  • Working toward formal certifications such as SOC 2 as we scale

See it for yourself — with your data, your rules

Start free, keep every reply in your Review Queue, and turn on automation only when you trust it.

Questions about our security? Contact us