Nityan is under active development. This page describes our security direction and current public-site safeguards; it does not claim a certification or guarantee that no incident can occur.
1. Our principles
- Least access: limit access to the people and systems that need it.
- Purpose limitation: process financial data for requested business workflows.
- Layered controls: use multiple safeguards rather than relying on one barrier.
- Human accountability: keep consequential financial outcomes reviewable.
- Continuous improvement: assess risks and strengthen controls as the service grows.
2. Identity and access
Our intended control model includes unique user access, role-appropriate permissions, protected administrative access, and prompt removal of access that is no longer needed. We do not ask users to provide online-banking credentials directly to Nityan; supported account connections are intended to use providers such as Plaid and institution-hosted authorization flows.
3. Data protection
Nityan is designed to encrypt sensitive information in transit and at rest using capabilities provided by established cloud and connectivity providers. Public website content is served over HTTPS from private origin storage through a content delivery network. We seek to minimize collection, separate environments appropriately, protect secrets, and avoid exposing sensitive records in client-side code or public storage.
4. Secure operations
As the service develops, our operating program is intended to include:
- Logging and review of relevant security and administrative events.
- Dependency, system, and vulnerability maintenance.
- Backups and recovery procedures appropriate to the service.
- Incident assessment, containment, recovery, and required notification.
- Change review and infrastructure managed as code where practical.
5. Service providers
Nityan relies on carefully selected providers for capabilities such as cloud infrastructure and financial connectivity. We evaluate access and security needs based on the service provided and aim to share only what is reasonably necessary. Plaid facilitates supported financial-account connections; banks and Plaid, rather than Nityan, handle institution credentials during those flows.
6. Shared responsibility
Customers help protect their information by authorizing only appropriate users, securing their devices and email accounts, reviewing access regularly, and reporting unusual activity promptly. Users should verify AI-assisted and automated outputs before making accounting, payment, tax, pricing, or inventory decisions.
7. Report a security concern
If you believe you found a security issue involving Nityan, email nityantech@gmail.com with a clear description and steps to reproduce. Please do not access, alter, retain, or disclose other people's data, disrupt service, or use destructive testing. We will acknowledge credible reports and work toward appropriate resolution.