Nexwin Security
Protecting your business data and your customers' information is a core responsibility we take seriously. This page explains honestly how Nexwin is built, where your data lives, and what we do to keep it secure.
We're a small Australian team and we won't pretend to have a CISO or a dedicated security committee. What we do have is a well-chosen, proven infrastructure stack — Google Cloud Platform — with security built into every layer by default, and a disciplined approach to how we write and deploy code.
Infrastructure & Data Residency
Where Your Data Is Processed
Nexwin's own infrastructure runs on Google Cloud Platform (GCP). We believe you should know exactly where each part of the service runs, so here it is in full:
- Application backend — Firebase App Hosting (Cloud Run) in Google's asia-southeast1 (Singapore) region. Google does not currently offer an Australian region for Firebase App Hosting.
- Customer database — Google Firestore, currently in Google's US multi-region.
- Real-time voice, transcription and AI inference — provided by specialist third parties operating outside Australia, primarily in the United States.
We are planning a migration of the customer database to GCP's australia-southeast1 (Sydney) region. Until that migration is complete we will not claim Australian data residency, and this page will be updated the day it changes.
Firebase App Hosting and Firestore are managed GCP services carrying Google's enterprise-grade physical and logical security — redundant data centres, biometric access controls, and continuous monitoring.
Data Encryption
All data at rest in Firestore and Cloud Storage is encrypted by GCP using AES-256 by default — no configuration required on our part. All data in transit between your browser, the Nexwin backend, and our third-party services is encrypted using TLS 1.2 or higher. Unencrypted connections are not accepted.
High Availability & Backups
Firestore is a fully managed, multi-region replicated database. Google manages replication, failover, and point-in-time backups automatically. In practice, this means your configuration and call history data is highly durable and available even if an individual data centre has an issue.
Authentication & Access Control
Customer Authentication
Nexwin uses Firebase Authentication for all customer logins. Passwords are never stored in plaintext — Firebase Auth handles secure credential storage using industry-standard hashing. All authenticated API requests require a valid Firebase ID token, which is verified server-side on every request.
Account data is strictly scoped — your configuration, call history, and team member data can only be accessed by authenticated users belonging to your account. There is no way for one customer to access another customer's data.
Internal Access
Access to production infrastructure is managed through GCP IAM with least-privilege roles. Only team members who need access for a specific operational reason are granted it. All GCP console access requires Google account two-factor authentication.
No customer data is stored on developer laptops. All production data access goes through GCP's managed services with full audit logging.
API Security
The Nexwin backend API validates authentication on every request and enforces account-level scoping throughout. Sensitive operations — such as account mutations and subscription changes — are read-only from the frontend and can only be triggered through authenticated backend routes. Secret keys (Stripe, Twilio, Resend) are stored in Google Secret Manager and are never exposed to the frontend or included in source code.
Your Data, Your Ownership
We Don't Train on Your Data
Nexwin does not use your business configuration, call transcripts, or customer data to train any AI models. The language models powering N-Voice and N-Chat are supplied by established providers — OpenAI by default, with Anthropic (Claude) models selectable on request. We pass your configuration to them so the assistant can answer as your business, but your customer conversations are not used to train or improve those models on our behalf.
Knowledge Base Documents
When you upload documents (PDF, Word, CSV, etc.) to your knowledge base, they are sent directly and are not stored on Nexwin's servers. Only metadata (file name, type, title) is retained in Firestore.
Data Retention
Call transcripts and chat conversation logs are retained in your dashboard so you can review and follow up on interactions. If you cancel your subscription, your data is retained for 30 days to allow for export, then permanently deleted. You can request earlier deletion by contacting us directly.
Data Segregation
All customer data in Firestore is logically isolated by account ID. Firestore security rules enforce that authenticated users can only read and write documents belonging to their own account. There is no shared data between accounts.
Third-Party Services
Nexwin integrates with a small set of carefully chosen, well-established providers. Each handles only the data necessary for their function:
Stripe
Handles all payment processing. Nexwin never sees or stores your full card number — all billing data is managed directly by Stripe. Stripe is PCI DSS Level 1 certified. Stripe security page →
Twilio
Provisions and manages Australian phone numbers for N-Voice. Call routing metadata passes through Twilio's infrastructure. Twilio trust centre →
Resend
Sends transactional emails (booking confirmations, OTP codes, account notifications). Only the minimum required data — recipient email, name, and booking details — is passed to Resend per email send. Resend security page →
Google Calendar
Used for appointment booking when you connect your calendar via OAuth. Nexwin stores your OAuth refresh token in Firestore (encrypted at rest by GCP) and only requests the minimum calendar scopes needed to check availability and create events. You can revoke access at any time from your Google account settings.
Zoom
Optionally used to create video meeting links for appointments. If you connect your Zoom account, an OAuth token is stored securely in Firestore and used only to create meeting links on your behalf. You can disconnect at any time from the Nexwin dashboard.
Application Security
Secure by Design
The Nexwin backend enforces strict separation between read and write operations — account and billing data can only be mutated through authenticated backend API routes, never directly from the frontend. All user input is validated and sanitised server-side before processing or storage.
We follow OWASP best practices to protect against common web vulnerabilities including SQL injection, XSS, and CSRF. Security HTTP headers and Content Security Policy (CSP) are applied to prevent code injection attacks.
Secret Management
All API keys and secrets (Stripe, Twilio, Resend, Google OAuth) are stored in Google Secret Manager and injected at runtime via Firebase App Hosting environment configuration. They are never hardcoded, committed to source control, or exposed to the client.
Deployment & Code Review
All code changes go through peer review before merging. Deployments to production are handled by Firebase App Hosting's CI/CD pipeline, which runs a full TypeScript build and validation before any release goes live. Production deployments are logged and auditable.
OTP Identity Verification
For sensitive operations such as appointment cancellations, Nexwin supports SMS or email OTP verification to confirm the caller's identity before making changes. This prevents unauthorised cancellations and protects both businesses and their customers.
Australian Privacy Compliance
Nexwin is built and operated in Australia by an Australian team. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Overseas Processing, Disclosed
Nexwin is an Australian company, so the Privacy Act 1988 and the Australian Privacy Principles apply to how we handle your information wherever it is processed. Under APP 8, we disclose that your data is processed overseas — see "Where Your Data Is Processed" above for the specifics, and our Privacy Policy for the full statement. Third-party providers (Stripe, Twilio, Resend, and our voice-AI provider) also process certain data outside Australia under their own global infrastructure; refer to their respective privacy policies.
No Data Selling
Nexwin does not sell, rent, or share your customer data with third parties for marketing or commercial purposes. Data shared with third-party providers (listed above) is strictly limited to what is needed to deliver the service.
Contact Us
If you have a security concern, a privacy request, or believe you've found a vulnerability, please contact us at [email protected]. We take all reports seriously and respond promptly.