SECURITY & DATA TRUST

Financial operating data should be scoped, traceable and protected by default.

This page describes security principles and controls currently reflected in XZMargin. XZ BYTECORE does not claim formal certifications, penetration-test results or compliance attestations unless they have actually been completed and are explicitly identified.

Document status

Effective date: 16 September 2026
Operator: XZ BYTECORE PRIVATE LIMITED
Security controls evolve with the product. Enterprise agreements may include additional commitments.

1. Authenticated customer access

Customer workspaces require authenticated sessions. Users are expected to keep credentials confidential, use password-recovery channels when needed and sign out from shared devices. Workspace access is not intended to be publicly accessible without authentication.

2. Company-scoped workspace design

XZMargin is designed around company/workspace scoping so one customer’s operating data is not intentionally exposed as another customer’s dataset. Data queries and product actions are expected to operate in the context of the selected company and authorised user.

3. Import integrity controls

The import workflow validates supported files, surfaces field mapping and data-quality issues, records failed imports and uses duplicate-protection controls. Cross-format semantic deduplication is intended to prevent the same business transaction from being silently counted twice when equivalent records are uploaded in different supported formats.

4. Deterministic financial calculations

Material profitability calculations are intended to use supplied source fields and deterministic rules. Missing financial evidence should remain visible as missing or data-dependent instead of being silently invented by generative AI. This control is part of financial integrity as well as product trust.

5. Source evidence and auditability

Users can inspect source transactions behind calculated findings. Important ₹ values are intended to be traceable to fields such as transaction date, reference, SKU, quantity, revenue, cost, discount, direct cost and source type where those fields exist. Audit and import history support review of how data entered the workspace.

6. Transport and hosting

Public XZMargin traffic is served over HTTPS. Production web infrastructure and managed database infrastructure are provided through specialised cloud providers. The current provider list is maintained on the Subprocessors page. Data residency is not promised unless specifically agreed in writing.

7. Secrets and server-side integrations

Payment, email, WhatsApp and other privileged provider credentials are intended to be held in server-side environment configuration rather than exposed as public browser values. Webhook or external-request verification should be used where the relevant integration supports it.

8. Billing security boundary

XZMargin integrates with a payment provider for subscription workflows. Customers should not send passwords, private keys or full payment-card credentials through support messages or upload files containing such secrets. Payment-provider security and card-data handling remain subject to the provider’s own infrastructure and terms.

9. Communication integrations

Optional report delivery may use email or WhatsApp providers when configured and enabled. Only information necessary for the requested communication should be sent to the provider. Customers should review report recipients before enabling automated delivery of financial summaries.

10. Data minimisation

Businesses should upload only commercial fields required for the intended analysis. Avoid unnecessary sensitive personal information. Use account labels, SKU references, invoice references, branch identifiers and supplier/customer business identifiers where those are sufficient.

11. Monitoring, logs and incident handling

Operational, authentication, import and error records may be used to diagnose failures, investigate suspected abuse and protect the service. Confirmed incidents involving customer personal data will be handled according to applicable law and the governing customer agreement. Incident details may be updated as an investigation develops.

12. Customer security responsibilities

13. Vulnerability and security reporting

Security concerns should be reported through the Grievance & Rights Requests page or Contact page and identified as a Security Report. Do not test production systems, attempt tenant bypasses or exploit suspected vulnerabilities without written authorisation.

14. Current assurance boundary

XZMargin does not currently represent itself on this page as ISO 27001 certified, SOC 2 attested, PCI DSS certified as a merchant service provider, independently penetration-tested on a recurring schedule, or otherwise certified unless a separate current document explicitly says so. Procurement teams should request current evidence rather than infer certification from product architecture.

15. Related trust documents

Privacy Policy · Data Processing Addendum · Subprocessors · Data Retention & Deletion