Xigna
About Contact Log in

Security & Data Protection Statement

Security & Data Protection Statement

Effective Date: 1st of July 2026

1. Overview

At Xigna, we understand that financial data is among the most sensitive information an organization manages. Security, privacy, and responsible data handling are fundamental principles embedded into the design and operation of our platform.

Xigna provides financial intelligence, analytics, compliance monitoring, and decision-support capabilities by connecting with business financial systems. We are committed to protecting customer data through industry-standard security practices, controlled access, and transparent data management.

This Security & Data Protection Statement explains how Xigna protects customer information and maintains the confidentiality, integrity, and availability of data processed through our platform.

2. Data Security Principles

Xigna follows three core security principles:

Confidentiality

  • Customer financial information is accessible only to authorized users, systems, and processes that require access for legitimate business purposes.

Integrity

  • Financial data is protected against unauthorized modification, alteration, or corruption through access controls, validation mechanisms, and audit processes.

Availability

  • Xigna is designed to maintain reliable access to services and customer data through resilient infrastructure and operational safeguards.

3. Data We Process

Depending on customer configuration and connected systems, Xigna may process:

Financial Data

  • Chart of accounts
  • General ledger transactions
  • Accounts payable and accounts receivable information
  • Trial balances
  • Financial statements
  • Revenue and expense information
  • Tax-related transaction data
  • Cash flow information

Business Information

  • Company profile information
  • Organizational structure
  • User permissions
  • Operational metrics
  • Business performance indicators

User Information

  • Name
  • Email address
  • Account credentials
  • User roles and permissions
  • Activity logs

Xigna does not sell, rent, or use customer financial data for advertising purposes.

4. Data Ownership

Customers retain ownership of all financial and business data provided to Xigna.

Xigna acts as a technology service provider that processes customer information only to:

  • Provide requested platform functionality
  • Generate financial insights and analytics
  • Perform compliance and monitoring activities
  • Improve platform reliability and security
  • Provide customer support

Xigna does not claim ownership rights over customer data.

5. Data Encryption

Xigna applies encryption safeguards designed to protect information during transmission and storage.

Data in Transit

  • Customer data transmitted between connected systems and Xigna is protected using industry-standard encrypted communication protocols, including TLS encryption.

Data at Rest

  • Stored customer information is protected using encryption mechanisms provided by Xigna's cloud infrastructure and database providers.

6. Access Control and Authentication

Xigna applies access control measures designed around the principle of least privilege.

Security controls include:

  • Role-based access controls (RBAC)
  • User permission management
  • Restricted administrative access
  • Authentication controls
  • Secure session management
  • Access monitoring and logging

Employees and contractors are granted access only when required for their responsibilities.

7. Accounting System Integrations

Xigna integrates with third-party accounting platforms through authorized APIs and secure connection methods.

Examples include:

  • QuickBooks Online
  • Xero
  • NetSuite
  • Sage

Xigna does not access customer accounting systems outside the permissions granted by the customer.

Customers maintain control over:

  • Connected systems
  • Authorized access permissions
  • Data synchronization settings
  • Integration removal

8. API Security

Xigna uses secure API communication practices, including:

  • Token-based authentication
  • Secure credential storage
  • API permission validation
  • Request authorization checks
  • Monitoring for abnormal activity

Customer credentials are not stored in plain text.

9. Data Segregation

Xigna is designed to maintain logical separation between customer environments.

Customer financial information is isolated to prevent unauthorized access between organizations.

Each customer's:

  • Transactions
  • Reports
  • Analytics
  • Users
  • Configuration data

are protected through access boundaries.

10. Monitoring and Logging

Xigna maintains security monitoring practices to identify and investigate potential security events.

Security-related activities may include:

  • Authentication attempts
  • Permission changes
  • Administrative actions
  • System events
  • Integration activity

Logs are used for security, troubleshooting, auditing, and platform improvement purposes.

11. Employee Security

Xigna limits internal access to customer information.

Security practices include:

  • Confidentiality obligations
  • Access limitation based on business need
  • Secure development practices
  • Security awareness procedures

Employees are expected to handle customer information responsibly and securely.

12. Secure Development Practices

Security is incorporated throughout Xigna's software development lifecycle.

Practices include:

  • Secure coding standards
  • Code review processes
  • Dependency monitoring
  • Vulnerability management
  • Testing before deployment
  • Controlled release procedures

13. Data Retention and Deletion

Xigna retains customer information only for as long as necessary to provide services or comply with applicable obligations.

Customers may request:

  • Data export
  • Account closure
  • Data deletion, subject to legal requirements

Upon termination of services, customer data is handled according to applicable contractual obligations and retention policies.

14. Third-Party Service Providers

Xigna may use trusted third-party infrastructure and service providers to operate the platform.

Such providers may include:

  • Cloud hosting providers
  • Database providers
  • Authentication services
  • Monitoring services

Xigna evaluates third-party providers based on security, reliability, and privacy considerations.

15. Privacy and Regulatory Commitment

Xigna is committed to complying with applicable privacy and data protection requirements, including where applicable:

  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Provincial privacy requirements
  • Applicable international privacy regulations for customers operating in other jurisdictions

16. Security Incident Response

Xigna maintains procedures for identifying, responding to, and managing security incidents.

In the event of a confirmed security incident involving customer information, Xigna will:

  • Investigate the incident
  • Take corrective actions
  • Limit potential impact
  • Notify affected customers where required by applicable laws or agreements

17. Customer Responsibilities

Customers are responsible for maintaining appropriate security practices, including:

  • Protecting user credentials
  • Managing user permissions
  • Reviewing connected integrations
  • Maintaining accurate account information
  • Reporting suspected unauthorized access

Security is a shared responsibility between Xigna and its customers.

18. Contact Information

For questions regarding Xigna security practices, privacy, or data protection, please contact Xigna Security Team using email on official Xigna website.