Security & trust

Your business runs on this. We treat it that way.

Nuvio holds your customer records, your fees and your team’s data. Here is plainly how we protect it — the measures that are actually in place today, not a wish list.

Encryption in transit

Every connection to Nuvio uses HTTPS/TLS. Traffic between you, the apps and the shared account backbone is encrypted end to end.

Per-tenant isolation

Each customer is a separate tenant. The account backbone checks, on every request, that you may only ever see your own organisation’s data — enforced in code across all five apps.

Secrets & payment tokens encrypted

Passwords are hashed; API keys, mail credentials and gateway references are encrypted at rest. We store only payment tokens and the last four digits of a card — never full card or bank-account numbers.

Daily off-site backups

Databases are backed up daily, encrypted, and copied off the server to separate object storage. Restores are tested, not assumed.

Least-privilege access

Staff access is role-based and limited to what a task needs. Sensitive actions are audit-logged, and money-touching code is reviewed adversarially before it ships.

One secure sign-in

Single sign-on carries your identity across the suite over one-time, short-lived codes — you authenticate once, and each app verifies access independently.

Your data is yours

Ownership, portability and deletion

  • You own the data you put into Nuvio. We process it only to run the service for you — never to sell it, and never to train models.
  • You can export your records, and you can ask us to delete them. On account closure we delete or return your data within a defined window, except where law requires us to keep it.
  • For your contacts’ requests (access, correction, deletion), the product’s own tools let you respond — and we help where you need us.
Payments & messaging

Handled by regulated providers

Card and online payments are processed by our payment gateway (Razorpay), a PCI-DSS-compliant processor — card details go to them, not through us. Messaging runs on established providers (WhatsApp/Meta, Twilio, SendGrid) under your own sender identity, with opt-outs recorded and enforced by the platform.

Compliance posture

Where we are, honestly

Nuvio is operated from India and customer data is hosted in India. Our practices are built around privacy-by-design and the principles of the DPDP Act and GDPR. We do not currently claim a formal certification such as SOC 2 or ISO 27001; when we hold one, it will be named here rather than implied. A signed Data Processing Addendum is available on request.

Related: Privacy Policy · Data Processing Addendum · Service Level Agreement

Responsible disclosure

Found a vulnerability?

We welcome reports from security researchers. Email admin@nuviolearning.com with details and steps to reproduce. Please give us reasonable time to fix an issue before disclosing it, and do not access or alter data that is not yours. We will acknowledge your report and keep you updated.

Questions about security or a DPA?

Talk to us — we are happy to walk your team or your reviewer through how Nuvio protects your data.

Scroll to Top