Security & Data Protection Statement
Security & Data Protection Statement
Effective Date: 1st of July 2026
1. Overview
At Xigna, we understand that financial data is among the most sensitive information an organization manages. Security, privacy, and responsible data handling are fundamental principles embedded into the design and operation of our platform.
Xigna provides financial intelligence, analytics, compliance monitoring, and decision-support capabilities by connecting with business financial systems. We are committed to protecting customer data through industry-standard security practices, controlled access, and transparent data management.
This Security & Data Protection Statement explains how Xigna protects customer information and maintains the confidentiality, integrity, and availability of data processed through our platform.
2. Data Security Principles
Xigna follows three core security principles:
Confidentiality
- Customer financial information is accessible only to authorized users, systems, and processes that require access for legitimate business purposes.
Integrity
- Financial data is protected against unauthorized modification, alteration, or corruption through access controls, validation mechanisms, and audit processes.
Availability
- Xigna is designed to maintain reliable access to services and customer data through resilient infrastructure and operational safeguards.
3. Data We Process
Depending on customer configuration and connected systems, Xigna may process:
Financial Data
- Chart of accounts
- General ledger transactions
- Accounts payable and accounts receivable information
- Trial balances
- Financial statements
- Revenue and expense information
- Tax-related transaction data
- Cash flow information
Business Information
- Company profile information
- Organizational structure
- User permissions
- Operational metrics
- Business performance indicators
User Information
- Name
- Email address
- Account credentials
- User roles and permissions
- Activity logs
Xigna does not sell, rent, or use customer financial data for advertising purposes.
4. Data Ownership
Customers retain ownership of all financial and business data provided to Xigna.
Xigna acts as a technology service provider that processes customer information only to:
- Provide requested platform functionality
- Generate financial insights and analytics
- Perform compliance and monitoring activities
- Improve platform reliability and security
- Provide customer support
Xigna does not claim ownership rights over customer data.
5. Data Encryption
Xigna applies encryption safeguards designed to protect information during transmission and storage.
Data in Transit
- Customer data transmitted between connected systems and Xigna is protected using industry-standard encrypted communication protocols, including TLS encryption.
Data at Rest
- Stored customer information is protected using encryption mechanisms provided by Xigna's cloud infrastructure and database providers.
6. Access Control and Authentication
Xigna applies access control measures designed around the principle of least privilege.
Security controls include:
- Role-based access controls (RBAC)
- User permission management
- Restricted administrative access
- Authentication controls
- Secure session management
- Access monitoring and logging
Employees and contractors are granted access only when required for their responsibilities.
7. Accounting System Integrations
Xigna integrates with third-party accounting platforms through authorized APIs and secure connection methods.
Examples include:
- QuickBooks Online
- Xero
- NetSuite
- Sage
Xigna does not access customer accounting systems outside the permissions granted by the customer.
Customers maintain control over:
- Connected systems
- Authorized access permissions
- Data synchronization settings
- Integration removal
8. API Security
Xigna uses secure API communication practices, including:
- Token-based authentication
- Secure credential storage
- API permission validation
- Request authorization checks
- Monitoring for abnormal activity
Customer credentials are not stored in plain text.
9. Data Segregation
Xigna is designed to maintain logical separation between customer environments.
Customer financial information is isolated to prevent unauthorized access between organizations.
Each customer's:
- Transactions
- Reports
- Analytics
- Users
- Configuration data
are protected through access boundaries.
10. Monitoring and Logging
Xigna maintains security monitoring practices to identify and investigate potential security events.
Security-related activities may include:
- Authentication attempts
- Permission changes
- Administrative actions
- System events
- Integration activity
Logs are used for security, troubleshooting, auditing, and platform improvement purposes.
11. Employee Security
Xigna limits internal access to customer information.
Security practices include:
- Confidentiality obligations
- Access limitation based on business need
- Secure development practices
- Security awareness procedures
Employees are expected to handle customer information responsibly and securely.
12. Secure Development Practices
Security is incorporated throughout Xigna's software development lifecycle.
Practices include:
- Secure coding standards
- Code review processes
- Dependency monitoring
- Vulnerability management
- Testing before deployment
- Controlled release procedures
13. Data Retention and Deletion
Xigna retains customer information only for as long as necessary to provide services or comply with applicable obligations.
Customers may request:
- Data export
- Account closure
- Data deletion, subject to legal requirements
Upon termination of services, customer data is handled according to applicable contractual obligations and retention policies.
14. Third-Party Service Providers
Xigna may use trusted third-party infrastructure and service providers to operate the platform.
Such providers may include:
- Cloud hosting providers
- Database providers
- Authentication services
- Monitoring services
Xigna evaluates third-party providers based on security, reliability, and privacy considerations.
15. Privacy and Regulatory Commitment
Xigna is committed to complying with applicable privacy and data protection requirements, including where applicable:
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
- Provincial privacy requirements
- Applicable international privacy regulations for customers operating in other jurisdictions
16. Security Incident Response
Xigna maintains procedures for identifying, responding to, and managing security incidents.
In the event of a confirmed security incident involving customer information, Xigna will:
- Investigate the incident
- Take corrective actions
- Limit potential impact
- Notify affected customers where required by applicable laws or agreements
17. Customer Responsibilities
Customers are responsible for maintaining appropriate security practices, including:
- Protecting user credentials
- Managing user permissions
- Reviewing connected integrations
- Maintaining accurate account information
- Reporting suspected unauthorized access
Security is a shared responsibility between Xigna and its customers.
18. Contact Information
For questions regarding Xigna security practices, privacy, or data protection, please contact Xigna Security Team using email on official Xigna website.