Nested / Security & PDPA

Data security and PDPA compliance

Accounting and financial data is a company's most important asset. Nested is designed with security in mind at every layer, from the infrastructure up to the permissions of each individual user.

Enterprise-grade infrastructure

Hosted on Microsoft Azure, a data center certified to international standards, with data encrypted both in transit (TLS) and at rest.

ISO 29110 development standard

The Nested team's software development process follows ISO/IEC 29110, which sets out software lifecycle practices and quality controls.

Automatic backups

Automatic scheduled backups, plus a Business Continuity Plan to cover system outages.

Permissions down to the individual user

Define roles and data permissions by department, job position and document type, so employees see only the data relevant to their duties.

Compliance with the Personal Data Protection Act (PDPA)

Nested processes the personal data held in a customer's system as a Data Processor, acting only on the instructions of the customer, who is the Data Controller.

  • Collects only the data necessary to provide the ERP service.
  • Records an audit trail of every access to and change made to a document.
  • Supports data subject rights, such as requests to access, correct or delete data.
  • A Data Processing Agreement is available for corporate customers.
Note: This page is a summary overview. If you need detailed security documentation, a Vendor Security Questionnaire or a data processing agreement, please contact our team to request the full documents.