Financial operating data should be scoped, traceable and protected by default.
This page describes security principles and controls currently reflected in XZMargin. XZ BYTECORE does not claim formal certifications, penetration-test results or compliance attestations unless they have actually been completed and are explicitly identified.
Document status
Effective date: 16 September 2026
Operator: XZ BYTECORE PRIVATE LIMITED
Security controls evolve with the product. Enterprise agreements may include additional commitments.
1. Authenticated customer access
Customer workspaces require authenticated sessions. Users are expected to keep credentials confidential, use password-recovery channels when needed and sign out from shared devices. Workspace access is not intended to be publicly accessible without authentication.
2. Company-scoped workspace design
XZMargin is designed around company/workspace scoping so one customer’s operating data is not intentionally exposed as another customer’s dataset. Data queries and product actions are expected to operate in the context of the selected company and authorised user.
3. Import integrity controls
The import workflow validates supported files, surfaces field mapping and data-quality issues, records failed imports and uses duplicate-protection controls. Cross-format semantic deduplication is intended to prevent the same business transaction from being silently counted twice when equivalent records are uploaded in different supported formats.
4. Deterministic financial calculations
Material profitability calculations are intended to use supplied source fields and deterministic rules. Missing financial evidence should remain visible as missing or data-dependent instead of being silently invented by generative AI. This control is part of financial integrity as well as product trust.
5. Source evidence and auditability
Users can inspect source transactions behind calculated findings. Important ₹ values are intended to be traceable to fields such as transaction date, reference, SKU, quantity, revenue, cost, discount, direct cost and source type where those fields exist. Audit and import history support review of how data entered the workspace.
6. Transport and hosting
Public XZMargin traffic is served over HTTPS. Production web infrastructure and managed database infrastructure are provided through specialised cloud providers. The current provider list is maintained on the Subprocessors page. Data residency is not promised unless specifically agreed in writing.
7. Secrets and server-side integrations
Payment, email, WhatsApp and other privileged provider credentials are intended to be held in server-side environment configuration rather than exposed as public browser values. Webhook or external-request verification should be used where the relevant integration supports it.
8. Billing security boundary
XZMargin integrates with a payment provider for subscription workflows. Customers should not send passwords, private keys or full payment-card credentials through support messages or upload files containing such secrets. Payment-provider security and card-data handling remain subject to the provider’s own infrastructure and terms.
9. Communication integrations
Optional report delivery may use email or WhatsApp providers when configured and enabled. Only information necessary for the requested communication should be sent to the provider. Customers should review report recipients before enabling automated delivery of financial summaries.
10. Data minimisation
Businesses should upload only commercial fields required for the intended analysis. Avoid unnecessary sensitive personal information. Use account labels, SKU references, invoice references, branch identifiers and supplier/customer business identifiers where those are sufficient.
11. Monitoring, logs and incident handling
Operational, authentication, import and error records may be used to diagnose failures, investigate suspected abuse and protect the service. Confirmed incidents involving customer personal data will be handled according to applicable law and the governing customer agreement. Incident details may be updated as an investigation develops.
12. Customer security responsibilities
- Authorise only users who need workspace access.
- Protect account credentials and connected communication destinations.
- Review uploaded data and field mappings before relying on results.
- Do not upload secrets or data you are not permitted to process.
- Notify XZ BYTECORE promptly if you suspect unauthorised access or a security issue.
13. Vulnerability and security reporting
Security concerns should be reported through the Grievance & Rights Requests page or Contact page and identified as a Security Report. Do not test production systems, attempt tenant bypasses or exploit suspected vulnerabilities without written authorisation.
14. Current assurance boundary
XZMargin does not currently represent itself on this page as ISO 27001 certified, SOC 2 attested, PCI DSS certified as a merchant service provider, independently penetration-tested on a recurring schedule, or otherwise certified unless a separate current document explicitly says so. Procurement teams should request current evidence rather than infer certification from product architecture.
15. Related trust documents
Privacy Policy · Data Processing Addendum · Subprocessors · Data Retention & Deletion