XoraProXoraPro™

Security

Security at XoraPro

You are being asked to put your books, your payroll and your customer ledgers into our software. This is what we do to deserve that, and what we have not done yet.

Last reviewed 16 Aswin 2083 BS (2026-10-02 AD)

1. One business cannot see another

This is the most important thing on this page.

XoraPro serves many businesses from one system. Every record carries the identity of the business it belongs to, and every request checks the signed-in person's membership of that business before reading or writing anything.

That check is applied per request rather than by a single database-level mechanism, so the rule is repeated across the code and checked in review. We spell this out because an audit of an earlier draft of this page found it overstated.

Reaching another business's data by changing an identifier in a link or a request is something we test for specifically.

2. How people sign in

Weak sign-in is how small businesses actually get robbed, so this is where the real work went.

  • Passkeys. Sign in with your phone or laptop's fingerprint or face. There is no password to steal, guess or reuse. This is the strongest option and the one we recommend.
  • One-time six digit codes, instead of typing a password.
  • Two step verification is available to everyone, and is mandatory for accounting firm owners and administrators.
  • Trusted devices. A device you use daily can be remembered for up to 60 days so you are not challenged every morning. You can see the list and remove any of them at once, which is what you do when a phone is lost.

3. Who inside your business sees what

Each person is invited with a role, and the role decides what they can open.

Salary is the most sensitive number a business holds, and in Nepal a payslip is the document an employee takes to a bank. So membership of the business is not enough to read it. Only an owner, the payroll role, your accountant liaison, a read-only auditor, or your accounting firm's owner or admin can.

Your accountant can see everything, and can only change things if their role allows it.

Advice from working with real shops: give every person their own login. The moment one login is shared by five people, you lose the ability to know who did what.

4. Records cannot be quietly changed

A posted invoice, receipt or journal entry is never deleted. A mistake is corrected with a credit note, a debit note or a reversing entry. The original stays, the correction stays, and both are visible.

Every action that touches money is recorded with who did it, when, what the values were before and after, and from which address. Those records are then bound into a hash chain by a separate sealing process, so a row altered afterwards shows up as altered. The sealing runs every hour.

This is deliberate, and it follows the Procedure Related to Computerized Invoicing 2072. If there is ever a dispute, the record shows what actually happened.

Owners can read this record themselves. The Audit log, in the side menu, shows the business's latest 200 entries: who did what, when, and from which address. It can be filtered by kind of action and by severity, and downloaded as a PDF. Under Settings, Audit integrity, the owner can check at any time that no entry has been changed since it was sealed. If the business gives an auditor read-only access, the auditor can see the same record, and the owner can see every screen and file the auditor opened.

5. Where your data lives and how it travels

  • Everything between your device and XoraPro is encrypted in transit. Nothing about your business moves in plain text.
  • Servers and the database run in Nepal, in Ncell's data centre in Pokhara. The database is not exposed to the public internet.
  • Backups are encrypted on the server before they are stored with Cloudflare, and each fiscal year's copy is locked against deletion. Every week the server takes the latest backup back from Cloudflare, restores it into a separate test database, and checks that every table, and the number of rows in it, matches.
  • Payment gateway secrets are encrypted at rest and are never returned to the browser.
  • We do not store card numbers, and we never see a customer's wallet PIN or banking password.

The last full restore test, on 1 October 2026, restored the whole database from the copy at Cloudflare in 116 seconds, and every table matched. That is a measurement on the database as it was then (about 348 MB), not a promise. A real recovery also includes starting the service again and checking it, and takes longer as the data grows.

Your data lives in Nepal, and the encrypted backups are kept with Cloudflare in its Asia-Pacific region. Until 17 September 2026 XoraPro ran on Fly.io in Singapore; the copy that stayed there was deleted on 1 October 2026.

6. The July 2026 security audit

In July 2026 we ran a full security audit of the platform. It found 15 vulnerabilities. All 15 were fixed.

We give the number because a report that finds nothing usually means nobody looked properly. They included a way to bypass two step verification, several cases where changing an identifier in a request reached data it should not, and out of date dependencies with published vulnerabilities.

We keep looking after it too. In August 2026 we found that payroll could be read by anyone with a membership rather than by role, and fixed it. We do not hide findings like that.

7. Certifications: our honest position

We hold no security certifications. Not ISO 27001, not SOC 2. Not PCI DSS either, and we do not need it, because we do not store card data.

We are a young Nepali company and we are not going to pretend otherwise. Those certifications are expensive and take a year or more. We would rather spend that on the security work itself and be straight with you.

If your own contracts or your bank require a certified vendor, tell us before you sign up. We would rather say so now than have you find out later.

8. What we are still working on

We would rather list these than let you assume they are already done.

  • An independent external penetration test by a third party firm, not only our own audit.
  • A restore drill that compares the restored records themselves, not only each table and its number of rows.
  • A date search in the Audit log. Today the screen shows the latest 200 entries, and the PDF the latest 1,000.
  • Written security policies suitable for enterprise procurement review.

9. Reporting a security problem

If you have found a security problem in XoraPro, please tell us. We would much rather hear it from you than from anyone else. Email security@xorapro.com.

Tell us what you found, how to reproduce it, and how to reach you. Please do not post it publicly before we have had a chance to fix it.

Our commitment: if you research in good faith, test only against your own account, do not touch another business's data, do not run load or denial of service tests against the live service, and report to us privately, we will not take legal action against you.

If you accidentally reach data that is not yours, stop, do not keep it, and tell us at once.

10. If something goes wrong

If there is a security incident affecting your data, we will tell you. What happened, what data was involved, what we have done, and what you should do.

We will not wait until we know everything. We will tell you what we know as soon as we can confirm you are affected, and keep you updated. We will also report to the authorities in Nepal where the law requires it.

11. Contact

  • Security reports: security@xorapro.com
  • Everything else: support@xorapro.com
  • Phone: +977 9766007553
  • M/s N.P. Xora Private Limited, Ward No. 3, Samakhusi, Kathmandu, Nepal