Skip to content
MSMENXT MICRO
Legal CentrePrivacy PolicyTerms of Use Consent NoticeDPASubprocessors Retention & Security

Zertical Private Limited

MSMENXT MICRO Retention and Security

The current controls, lifecycle approach and explicit pre-production limitation for MSMENXT MICRO.

Effective
20 September 2026
Version
micro-retention-security-2026-09-20-v2

Access and tenant isolation

  • Passwords are salted and hashed with a server-side secret and are never displayed.
  • Identity and company are resolved from the authenticated session; browser-supplied company identifiers are not trusted.
  • Only one active session is allowed, with an eight-hour maximum and a three-minute recovery window after unexpected closure.
  • Company business records are stored in routed tenant D1 databases and queried by authenticated company identity.
  • Uploaded files use private, company-scoped R2 object keys; public bucket access is not enabled.

Operational records

Central D1 stores identity, subscription, routing, lifecycle and security-relevant audit metadata. Tenant business payloads are not copied into Central operational audit views. Passwords and raw business payloads are excluded from logs.

Verification records

Email codes expire after five minutes with at most five verification attempts. A successful code yields a single-use setup proof valid for two minutes. The scheduled cleanup removes expired challenge and rate-limit metadata after a one-day buffer; aggregate sending-budget counters are kept for seven days. Completed setup retry proofs are erased after their 24-hour recovery window. Minimal enrollment and manual access-approval metadata remains with the account and is covered by its approved export/deletion process. Unfinished setup remains inactive pending safe retry or support review. No code or password is stored in browser storage by the signup page.

Retention and deletion

Retention is limited by purpose, contract and applicable law. Import CSV/XLSX payloads and any supporting OCR PDF or image are private, company-scoped, copied to recovery storage and automatically due for deletion after seven days; minimized batch and approval metadata may remain for audit. Company deletion begins by blocking access and revoking sessions, then requires independent Founder approval and verified execution of a complete Central, tenant and R2 manifest. The current canary does not promise automatic one-day erasure. Required security, tax, contractual or dispute evidence may be retained for its lawful period.

Document reading controls

Document reading is optional and deterministic. Up to ten PDF pages, JPG, PNG or WebP files are read in the user’s browser. The interface shows recognised text and every allowed template field for correction. Figure fields reject alphabetic characters, server validation is repeated, and the customer must separately confirm the source document, figures and final save. OCR output is never treated as authoritative and never posts stock automatically.

CERT-In operational archive gate

Residency limitation: a separate private audit bucket retains only minimum security and operational metadata under a 180-day lock and deletion lifecycle. Its APAC placement is best effort and is not represented as Indian data residency. No live customer data should be placed in the service until Indian residency is contractually guaranteed or an India-resident archive provider is connected and verified. The ordinary private-files bucket is not used as a substitute compliance archive.

Customer controls

The customer controls authorised users and entered business data. MSMENXT MICRO does not automatically send accounting entries, payments, tax filings or employment decisions to an external system.

Incident handling

Security incidents are triaged using minimum necessary operational evidence. Affected customers and authorities are notified as required by applicable law and verified incident scope.

Grievance and privacy contact

Bhupesh Purohit, Grievance Officer
support@msmenxt.com · +91 95876 47474

We aim to acknowledge a privacy grievance within one business day. Acknowledgement is not the same as final resolution.

Legal CentrePrivacy PolicyTerms of Use Consent NoticeDPASubprocessors Retention & Security

© 2026 Zertical Private Limited. MSMENXT MICRO does not use generative AI.