Security
Security at XoraPro
Last reviewed 1 Aswin 2083 BS (2026-09-17 AD)
1. One business cannot see another
This is the most important thing on this page.
XoraPro serves many businesses from one system. Every record carries the identity of the business it belongs to, and every request checks the signed-in person's membership of that business before reading or writing anything.
That check is applied per request rather than by a single database-level mechanism, so the rule is repeated across the code and checked in review. We spell this out because an audit of an earlier draft of this page found it overstated.
Reaching another business's data by changing an identifier in a link or a request is something we test for specifically.
2. How people sign in
Weak sign-in is how small businesses actually get robbed, so this is where the real work went.
- Passkeys. Sign in with your phone or laptop's fingerprint or face. There is no password to steal, guess or reuse. This is the strongest option and the one we recommend.
- One-time six digit codes, instead of typing a password.
- Two step verification is available to everyone, and is mandatory for accounting firm owners and administrators.
- Trusted devices. A device you use daily can be remembered for up to 60 days so you are not challenged every morning. You can see the list and remove any of them at once, which is what you do when a phone is lost.
3. Who inside your business sees what
Each person is invited with a role, and the role decides what they can open.
Salary is the most sensitive number a business holds, and in Nepal a payslip is the document an employee takes to a bank. So membership of the business is not enough to read it. Only an owner, the payroll role, your accountant liaison, a read-only auditor, or your accounting firm's owner or admin can.
Your accountant can see everything, and can only change things if their role allows it.
Advice from working with real shops: give every person their own login. The moment one login is shared by five people, you lose the ability to know who did what.
4. Records cannot be quietly changed
A posted invoice, receipt or journal entry is never deleted. A mistake is corrected with a credit note, a debit note or a reversing entry. The original stays, the correction stays, and both are visible.
Every action that touches money is recorded with who did it, when, what the values were before and after, and from which address. Those records are then bound into a hash chain by a separate sealing process, so a row altered afterwards shows up as altered.
This is deliberate, and it follows the Procedure Related to Computerized Invoicing 2072. If there is ever a dispute, the record shows what actually happened.
5. Where your data lives and how it travels
- Everything between your device and XoraPro is encrypted in transit. Nothing about your business moves in plain text.
- Servers and the database run in Nepal, in Ncell's data centre in Pokhara. The database is not exposed to the public internet.
- Backups are encrypted on the server before they are stored with Cloudflare, each fiscal year's copy is locked against deletion, and a restore is tested every week.
- Payment gateway secrets are encrypted at rest and are never returned to the browser.
- We do not store card numbers, and we never see a customer's wallet PIN or banking password.
The data lives in Nepal. A frozen copy as it stood on 17 September 2026 stays with Fly.io in Singapore until the end of September 2026, when it is deleted.
6. The July 2026 security audit
In July 2026 we ran a full security audit of the platform. It found 15 vulnerabilities. All 15 were fixed.
We give the number because a report that finds nothing usually means nobody looked properly. They included a way to bypass two step verification, several cases where changing an identifier in a request reached data it should not, and out of date dependencies with published vulnerabilities.
We keep looking after it too. In August 2026 we found that payroll could be read by anyone with a membership rather than by role, and fixed it. We do not hide findings like that.
7. Certifications: our honest position
We hold no security certifications. Not ISO 27001, not SOC 2. Not PCI DSS either, and we do not need it, because we do not store card data.
We are a young Nepali company and we are not going to pretend otherwise. Those certifications are expensive and take a year or more. We would rather spend that on the security work itself and be straight with you.
If your own contracts or your bank require a certified vendor, tell us before you sign up. We would rather say so now than have you find out later.
8. What we are still working on
We would rather list these than let you assume they are already done.
- An independent external penetration test by a third party firm, not only our own audit.
- A tested restore drill, so we can state a recovery time rather than describe a process.
- Customer-visible audit logs, so an owner can see for themselves who did what and when.
- Written security policies suitable for enterprise procurement review.
9. Reporting a security problem
If you have found a security problem in XoraPro, please tell us. We would much rather hear it from you than from anyone else. Email security@xorapro.com.
Tell us what you found, how to reproduce it, and how to reach you. Please do not post it publicly before we have had a chance to fix it.
Our commitment: if you research in good faith, test only against your own account, do not touch another business's data, do not run load or denial of service tests against the live service, and report to us privately, we will not take legal action against you.
If you accidentally reach data that is not yours, stop, do not keep it, and tell us at once.
10. If something goes wrong
If there is a security incident affecting your data, we will tell you. What happened, what data was involved, what we have done, and what you should do.
We will not wait until we know everything. We will tell you what we know as soon as we can confirm you are affected, and keep you updated. We will also report to the authorities in Nepal where the law requires it.
11. Contact
- Security reports: security@xorapro.com
- Everything else: support@xorapro.com
- Phone: +977 9766007553
- M/s N.P. Xora Private Limited, Ward No. 3, Samakhusi, Kathmandu, Nepal