Legal
Security
How FleekERP protects your production data: hosting, encryption, access control, backups, and how to report a security issue to us.
Last updated
Security is built into every layer of FleekERP, from the infrastructure it runs on to the way operators sign in at the station. This page describes our current practices for the website and the FleekERP platform. For data privacy, see the privacy policy and the GDPR page.
1. Infrastructure and hosting
The FleekERP platform and its data are hosted on Amazon Web Services (AWS), whose infrastructure is certified to ISO 27001 and SOC 2 and is operated to AWS's own security standards. Dedicated hosting is available for enterprise customers.
- Isolated network with private subnets for application and database tiers.
- Web application firewall and DDoS protection at the edge.
- Automated daily backups with 30-day retention.
- Disaster recovery procedures tested periodically.
2. Encryption
- In transit: TLS 1.2 or higher for all traffic. HTTP redirects to HTTPS. HSTS is enforced.
- At rest: database storage and file volumes are encrypted with AES-256.
- Passwords are never stored in plain text. They are hashed with bcrypt.
- API tokens and secrets are stored in a managed secrets service with strict access policies.
3. Access controls
- Least privilege: each team member and system has access only to what its function requires.
- Multi-factor authentication for all internal systems and administrative interfaces.
- Role-based access in the platform: every login has a role (User, or Employee as Supervisor, Operator or QC) that controls what it can see and do. Operators on a shared station phone sign in with a PIN.
- Production system access requires explicit authorisation and is logged.
- Access rights are reviewed quarterly and revoked at offboarding.
4. Application security
- Code is reviewed by a second engineer before it reaches production.
- Automated dependency scanning flags known vulnerabilities in third-party packages.
- We follow OWASP Top 10 guidance. Injection, cross-site scripting and CSRF protections are enforced at the API layer.
- Rate limiting on public endpoints, including the website contact form.
- All inputs are validated and sanitised on the server, independent of the client.
5. Monitoring and incident response
Centralised logging with alerts on anomalous patterns, uptime monitoring with on-call escalation, and a documented incident response plan. In the event of a confirmed breach affecting personal data, we notify the Data Protection Board of India within the required timeframe and, for EU data subjects, the relevant supervisory authority within 72 hours, and inform affected individuals as required by law.
6. People
- Security awareness training at onboarding and annually.
- Confidentiality agreements for all personnel with access to customer data.
- Background verification for roles with access to sensitive systems.
7. Vendors
Vendors that process data on our behalf are assessed before onboarding and covered by data processing agreements. The current sub-processor list is available on request.
8. Compliance posture
We design and operate the platform to align with the Digital Personal Data Protection Act, 2023, the GDPR where applicable, OWASP Top 10 and our cloud provider's well-architected guidance. ISO 27001 certification of Nexfloe's own management system is in progress.
9. Vulnerability disclosure
If you find a potential vulnerability in the website or the platform, email info@fleekerp.com with the subject line "Security vulnerability report". Include a description, steps to reproduce and the potential impact. Do not exploit the issue or access other users' data. We acknowledge valid reports within 5 business days and ask for 90 days to remediate before public disclosure.
10. Contact
Nexfloe Technologies Private Limited, Chennai, Tamil Nadu, India. Email info@fleekerp.com. Phone +91 99411 11019.
Grievance Officer: K. Silambarasan, Grievance Officer and Data Protection Contact. Email grievance@fleekerp.com. We acknowledge within 48 hours and respond within 30 days, as required by the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2021.