Skip to main content

Security and data protection

This page describes the protections built into Nadigit IMS and what remains the responsibility of the team that runs the server.

Where the data lives​

Nadigit IMS is installed on your server: business data, user accounts and generated documents stay there. Nothing is sent outside, except to the services you enable yourself (see below).

Authentication​

  • Sign-in is handled by a dedicated authentication service (Keycloak, OpenID Connect standard). Passwords are verified and stored by this service only, in its own database, separate from business data.
  • After sign-in, every call carries a signed, short-lived access token. The application services verify its signature on every request.
  • The first administrator receives a temporary password, to change at the first sign-in.
  • At the point of sale, the screen can be locked between customers and unlocked with the user's PIN code.

Roles and permissions​

Each user has one or more roles: Administrator, Vendor, Warehouseman, Cashier, Accountant, Auditor. The role determines the menus shown and what the server accepts: an action that is not allowed is refused by the application services, even when attempted outside the console. See who sees what.

Organization separation​

With the Enterprise plan, one installation can run several companies.

  • Each organization has its own warehouses, shops, catalog, customers, suppliers, stock, sales, purchases, payments and documents.
  • Every request runs in the active organization. A user only sees and changes the data of the active organization, and can only activate the organizations they are a member of.
  • Reports, dashboards and NadiPilot answers cover the active organization only, within the limits of the role's permissions.
  • Shared across the installation: user accounts (each linked to its organizations) and tax rules.

Encrypted traffic​

  • All traffic goes through a single HTTPS entry point. The Let's Encrypt certificate is obtained and renewed automatically; you can also supply your own.
  • Internal components are not exposed directly.
  • The authentication admin console and the API explorer are closed to everyone by default. They only open to the addresses you allow.

Installation secrets​

  • Database passwords and technical keys are generated at installation, unique to each installation.
  • They are kept in the .env configuration file, readable by its owner only. The initial credentials are in install-summary.txt, protected the same way: keep it off the server, somewhere safe.
  • Backups contain a copy of these secrets: protect them like the server itself.

E-commerce integrations​

  • Each store receives a separate connector identity, which can only reach the Integration API and a single warehouse and shop.
  • The store is not trusted: Nadigit IMS recalculates the prices and taxes of every order it receives.
  • Notifications sent to the store are signed (HMAC-SHA256, timestamped), so the store can verify they come from Nadigit IMS.

See Integration API.

External services​

ServiceWhat leaves your serverHow to avoid it
NadiPilot and invoice extraction (AI)The questions asked and the data needed to answer them, or the invoice to read, are sent to the chosen AI providerUse a local model (Ollama), or do not enable AI
Market trends (Enterprise)General web searches: business sector, country and month, without any business dataDo not enable the tile
Nadigit licence serverActivation and verification of the installation's licenceUse a licence file, validated offline
E-mail, Telegram, WhatsAppThe content of the notifications you configureDo not configure the channel
Online storesCatalog, stock and order status of the bound warehouseDo not create an integration

See Configuration to enable or disable AI.

Licence​

The licence is a document signed by Nadigit, bound to the server ID. It is verified locally: an installation without internet access works with a licence file. Without a valid licence, the application starts in restricted mode and only accepts activation.

Traceability​

Sensitive actions are recorded in the audit log, available to administrators. See Administration.

Responsibilities​

Nadigit IMSThe team that runs the server
Authentication, roles, organization separationUser accounts: creation, roles, departures
Encrypted traffic and certificate renewalFirewall, server access, operating system updates
Secret generationSafekeeping of .env, install-summary.txt and backups
Backup and upgrade toolsBackup scheduling, off-site copies, restore tests
Audit logRegular review of access and sensitive actions

Report a security issue​

If you think you have found a vulnerability, contact Nadigit support, describing the issue and how to reproduce it. Do not publish it before it is fixed.

See also​