Skip to content
MSMENXT MICRO
Legal CentrePrivacy PolicyTerms of Use Consent NoticeDPASubprocessors Retention & Security

Zertical Private Limited

MSMENXT MICRO Retention and Security

The current controls, lifecycle approach and explicit pre-production limitation for MSMENXT MICRO.

Effective
9 August 2026
Version
micro-retention-security-2026-08-09-v3

Access and tenant isolation

  • Passwords are salted and hashed with a server-side secret and are never displayed.
  • Identity and company are resolved from the authenticated session; browser-supplied company identifiers are not trusted.
  • Only one active session is allowed, with an eight-hour maximum and a three-minute recovery window after unexpected closure.
  • Company business records are stored in routed tenant D1 databases and queried by authenticated company identity.
  • Uploaded files use private, company-scoped R2 object keys; public bucket access is not enabled.

Operational records

Central D1 stores identity, subscription, routing, lifecycle and security-relevant audit metadata. Tenant business payloads are not copied into Central operational audit views. Passwords and raw business payloads are excluded from logs.

Retention and deletion

Retention is limited by purpose, contract and applicable law. Import CSV/XLSX payloads and any supporting OCR PDF or image are private, company-scoped, copied to recovery storage and automatically due for deletion after seven days; minimized batch and approval metadata may remain for audit. Company deletion begins by blocking access and revoking sessions, then requires independent Founder approval and verified execution of a complete Central, tenant and R2 manifest. The current canary does not promise automatic one-day erasure. Required security, tax, contractual or dispute evidence may be retained for its lawful period.

Document reading controls

Document reading is optional and deterministic. Up to ten PDF pages, JPG, PNG or WebP files are read in the user’s browser. The interface shows recognised text and every allowed template field for correction. Figure fields reject alphabetic characters, server validation is repeated, and the customer must separately confirm the source document, figures and final save. OCR output is never treated as authoritative and never posts stock automatically.

CERT-In operational archive gate

Residency limitation: a separate private audit bucket retains only minimum security and operational metadata under a 180-day lock and deletion lifecycle. Its APAC placement is best effort and is not represented as Indian data residency. No live customer data should be placed in the service until Indian residency is contractually guaranteed or an India-resident archive provider is connected and verified. The ordinary private-files bucket is not used as a substitute compliance archive.

Customer controls

The customer controls authorised users and entered business data. MSMENXT MICRO does not automatically send accounting entries, payments, tax filings or employment decisions to an external system.

Incident handling

Security incidents are triaged using minimum necessary operational evidence. Affected customers and authorities are notified as required by applicable law and verified incident scope.

Grievance and privacy contact

Bhupesh Purohit, Grievance Officer
rishav@msmescores.com · +91 95876 47474

We aim to acknowledge a privacy grievance within one business day. Acknowledgement is not the same as final resolution.

Legal CentrePrivacy PolicyTerms of Use Consent NoticeDPASubprocessors Retention & Security

© 2026 Zertical Private Limited. MSMENXT MICRO does not use generative AI.