Secure website requests
Public API routes use request-size controls, rate limits and input validation. Security headers are configured at the hosting layer.
This page explains controls implemented in the public website architecture. Product-specific hosting, retention, backup, access and compliance terms should be confirmed for the product and deployment you purchase.
Public API routes use request-size controls, rate limits and input validation. Security headers are configured at the hosting layer.
Subscription pricing is selected server-side. Razorpay responses are checked cryptographically and confirmed against provider payment state before success is recorded.
Optional first-party analytics is sent only after the visitor allows analytics. Essential website functionality does not require analytics consent.
The Nextica AI guide is designed for product discovery and website guidance. It is not a legal, tax, secretarial, payroll or compliance adviser.
A standard security contact is published at /.well-known/security.txt for responsible vulnerability reporting.
Nextica does not use this page to imply ISO, SOC, statutory or regulatory certification. Any such requirement should be verified in writing for the relevant product.
Demo and quotation forms are designed to collect ordinary business contact details and workflow requirements. Do not submit passwords, OTPs, DSC credentials, payment-card details, PAN/Aadhaar documents or other confidential credentials through the public AI assistant or general enquiry fields.
The website architecture can connect to Supabase for enquiry/authentication data, Razorpay for payments, Resend for enquiry notifications and OpenAI for the optional AI product guide. These services activate only when the corresponding environment variables are configured. Their own terms and privacy practices also apply when enabled.
The AI product guide is instructed to answer from curated Nextica product information, avoid inventing prices or certifications, and route uncertain commercial facts back to the Nextica team. A local non-AI fallback remains available if the external AI service is not configured or temporarily unavailable.
For a security issue, use the contact published in security.txt. For normal product support or commercial questions, use the contact page or WhatsApp.
Ask for the hosting, access, backup, retention and deployment details that apply to the exact product you are evaluating.