Security and data protection
This page describes the protections built into Nadigit IMS and what remains the responsibility of the team that runs the server.
Where the data lives
Nadigit IMS is installed on your server: business data, user accounts and generated documents stay there. Nothing is sent outside, except to the services you enable yourself (see below).
Authentication
- Sign-in is handled by a dedicated authentication service (Keycloak, OpenID Connect standard). Passwords are verified and stored by this service only, in its own database, separate from business data.
- After sign-in, every call carries a signed, short-lived access token. The application services verify its signature on every request.
- The first administrator receives a temporary password, to change at the first sign-in.
- At the point of sale, the screen can be locked between customers and unlocked with the user's PIN code.
Roles and permissions
Each user has one or more roles: Administrator, Vendor, Warehouseman, Cashier, Accountant, Auditor. The role determines the menus shown and what the server accepts: an action that is not allowed is refused by the application services, even when attempted outside the console. See who sees what.
Organization separation
With the Enterprise plan, one installation can run several companies.
- Each organization has its own warehouses, shops, catalog, customers, suppliers, stock, sales, purchases, payments and documents.
- Every request runs in the active organization. A user only sees and changes the data of the active organization, and can only activate the organizations they are a member of.
- Reports, dashboards and NadiPilot answers cover the active organization only, within the limits of the role's permissions.
- Shared across the installation: user accounts (each linked to its organizations) and tax rules.
Encrypted traffic
- All traffic goes through a single HTTPS entry point. The Let's Encrypt certificate is obtained and renewed automatically; you can also supply your own.
- Internal components are not exposed directly.
- The authentication admin console and the API explorer are closed to everyone by default. They only open to the addresses you allow.
Installation secrets
- Database passwords and technical keys are generated at installation, unique to each installation.
- They are kept in the
.envconfiguration file, readable by its owner only. The initial credentials are ininstall-summary.txt, protected the same way: keep it off the server, somewhere safe. - Backups contain a copy of these secrets: protect them like the server itself.
E-commerce integrations
- Each store receives a separate connector identity, which can only reach the Integration API and a single warehouse and shop.
- The store is not trusted: Nadigit IMS recalculates the prices and taxes of every order it receives.
- Notifications sent to the store are signed (HMAC-SHA256, timestamped), so the store can verify they come from Nadigit IMS.
See Integration API.
External services
| Service | What leaves your server | How to avoid it |
|---|---|---|
| NadiPilot and invoice extraction (AI) | The questions asked and the data needed to answer them, or the invoice to read, are sent to the chosen AI provider | Use a local model (Ollama), or do not enable AI |
| Market trends (Enterprise) | General web searches: business sector, country and month, without any business data | Do not enable the tile |
| Nadigit licence server | Activation and verification of the installation's licence | Use a licence file, validated offline |
| E-mail, Telegram, WhatsApp | The content of the notifications you configure | Do not configure the channel |
| Online stores | Catalog, stock and order status of the bound warehouse | Do not create an integration |
See Configuration to enable or disable AI.
Licence
The licence is a document signed by Nadigit, bound to the server ID. It is verified locally: an installation without internet access works with a licence file. Without a valid licence, the application starts in restricted mode and only accepts activation.
Traceability
Sensitive actions are recorded in the audit log, available to administrators. See Administration.
Responsibilities
| Nadigit IMS | The team that runs the server |
|---|---|
| Authentication, roles, organization separation | User accounts: creation, roles, departures |
| Encrypted traffic and certificate renewal | Firewall, server access, operating system updates |
| Secret generation | Safekeeping of .env, install-summary.txt and backups |
| Backup and upgrade tools | Backup scheduling, off-site copies, restore tests |
| Audit log | Regular review of access and sensitive actions |
Report a security issue
If you think you have found a vulnerability, contact Nadigit support, describing the issue and how to reproduce it. Do not publish it before it is fixed.