Security
Built to earn the trust you're placing in it
You're giving Nexioli access to customer communication — one of the most sensitive parts of your business. Here's exactly how we protect it.
How we protect you
Six layers of protection, working together
Not one feature bolted on — security built into how Nexioli is architected, from the database up.
Strict data isolation
Every business's data — conversations, customers, knowledge, settings — is completely isolated from every other business. There is no shared access path between companies, enforced at the database level, not just in application code.
Secure Gmail connection
Connect through Google's own sign-in. We never see, request, or store your email password.
You're always in control
Choose when Nexioli sends on its own. Emergency Stop pauses everything instantly.
Full audit logging
Every meaningful action — logins, integration changes, AI replies, approvals, Emergency Stop events — is logged. If something happens on your account, you can see exactly what and when.
Built on trusted infrastructure
Nexioli runs on Google Cloud and Firebase infrastructure, the same platforms trusted by companies handling sensitive data at massive scale. We don't run undifferentiated infrastructure ourselves.
Encryption everywhere
Data is encrypted in transit using TLS and at rest using our infrastructure provider's encryption standards. Sensitive credentials are stored in dedicated secret management, never in application databases.
Your data is never visible to anyone else.
Every business's conversations, customers, and knowledge are completely separated — enforced at the database level, not just in application code. Every connection, token refresh, and Emergency Stop event is logged, so you can always see exactly what happened on your account.
Company A
Conversations, knowledge, settings
Company B
Conversations, knowledge, settings
No shared access path — enforced at the database level
- Gmail connected via Google OAuthAug 12
- Emergency Stop tested — passedAug 20
- Access token rotated automaticallyToday
Our approach to compliance
Nexioli is built on infrastructure designed to meet rigorous compliance standards, and we're working toward formal certifications such as SOC 2 as we scale. We believe in being direct about where we are today rather than displaying certifications we haven't earned yet.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Gmail content is processed to sync the connected support inbox, draft replies, and send mail you approve — not to train foundational or generalized AI models. Details: Privacy Policy, Limited Use.
Where we stand today
- TLS encryption in transit, provider-grade encryption at rest
- Secrets and access tokens stored in dedicated secret management — never in application databases
- Full audit logs for every meaningful account action
- Gmail / Workspace API data is used only to provide the product (sync, draft, send) — not to train generalized AI models. We adhere to Google’s Limited Use requirements
- Working toward formal certifications such as SOC 2 as we scale
See it for yourself — with your data, your rules
Start free, keep every reply in your Review Queue, and turn on automation only when you trust it.