Your data is yours
The records your team keeps in NexFlows belong to you: your leads, customers, documents, messages and notes. We hold them to run the system for you, and we handle them only on your instructions.
We do not sell your data. We do not use it for advertising. We do not use it to train AI models.
Each company's records are kept apart from every other company's. The application reads and writes only the records that belong to the company of the person who is signed in.
You can take your data with you. Where the export is switched on for your account, you can download your leads and customers as an Excel file yourself, and you can ask us for a copy of the rest.
The credit report analyzer on our website
The analyzer on our homepage reads CTOS, eCCRIS and Experian PDF reports inside your browser. The reading program, pdf.js, comes with our website and runs on your own device. The report you choose is never uploaded to us or to anyone else, and the summary PDF you can download is also made in your browser.
We tested this. With a report chosen in the analyzer, we watched every request the page made. The only requests were downloads of the reading program. None carried the file.
This is about the free analyzer on our public website. Inside the Loan Advisory CRM, when your team uploads a customer's credit report, the report is read on our servers and stored in your account's private document storage, because it belongs in that customer's file.
Who can see what
Everyone has their own login, and what a person sees depends on their role. In the Loan Advisory CRM:
- Boss. Sees every record in the company.
- Sales admin. Sees every case, so they can chase documents and key in updates.
- Team leader. Sees their own cases and their team's.
- Sales and freelance agents. See only the records assigned to them.
These limits are enforced on our servers, not only hidden on the screen. Custom builds can have roles of their own.
Sign-in and passwords
- Passwords are stored as bcrypt hashes, a one-way scramble. Nobody at NexFlows can read your password, and we cannot send it to you. A forgotten password is reset, not looked up.
- After 10 wrong passwords for one account within 15 minutes, sign-in for that account is paused. Many failed attempts from one internet address are also stopped.
- After you sign in, your browser keeps a session cookie that scripts on the page cannot read and that is sent only over HTTPS. It lasts up to 14 days, or until you sign out.
When someone leaves
The account owner can have a person's account deactivated, by us, or by the owner where that setting is switched on for the account. From that person's next request on, they are locked out, and they cannot sign in again. Their records and history stay in place.
A record of who did what
NexFlows keeps an audit record of important actions: who moved a case to a new stage, reassigned or pulled back a lead, uploaded a document, or locked a payroll month. The application only adds to this record. It never edits or removes entries.
Encryption, storage and backups
- In transit. Everything between your browser and NexFlows uses HTTPS. Our site tells browsers to use only HTTPS, and plain web addresses are redirected.
- Access tokens. The keys that connect NexFlows to your other services, such as your WhatsApp number, your calendar or Facebook, are stored encrypted with AES-256-GCM.
- Documents. Uploaded documents sit in a private storage bucket that is not open to the public. They are opened through links that expire, usually within an hour.
- Backups. The database is backed up every night, and backups are kept for 14 days. A copy is also kept away from the server, in encrypted form.
Where your data lives
Our web servers and databases run on servers hosted by Hostinger in Kuala Lumpur, Malaysia. Our website is served through Cloudflare. Uploaded documents are stored with Amazon Web Services. The full list of providers is in the privacy policy.
Messages go through Meta's WhatsApp Business Platform, on your own business number, and are stored in your account so that your staff can reply and keep a record. Meta's rules apply, including approved templates for messages sent outside the 24-hour reply window. If a person asks not to be messaged, the business must stop. Where the business has marked the person as do-not-message, the system blocks reminder and campaign messages to them.
AI features
Some features use an AI model, for example to suggest or write a reply in a WhatsApp conversation. Where one is switched on, the text it needs, such as the conversation and the details of the lead, is sent to the AI provider, Anthropic, and the answer comes back. Before a drafted reply goes out, fixed rules check it. For example, it may not promise that a loan will be approved, and it may not contain an IC number.
What we do not claim
We hold no security certification, such as ISO 27001 or SOC 2, and we do not claim one. This page describes what the system does today, and we update it when that changes.
Report a security problem
If you think you have found a weakness, email [email protected] with the subject "Security". Tell us what you saw and how to repeat it. Please do not look at other people's data while you test, and please give us time to fix the problem before you share it.
Questions about this page? Email [email protected].