Customer Trust & Data Processing
Controlled-launch trust center
Data handling, limits, retention, deletion, subprocessors, support, launch scope and known limitations in one customer-readable source of truth.
Last reviewed: August 14, 2026 · Controlled-launch disclosure revision: trust-2026-08-14
Controlled-launch scope
Certanexa's customer-facing controlled launch is intentionally narrower than the wider codebase and product roadmap. The released customer workflow is single-user, same-currency, two-way reconciliation using CSV or XLSX files, deterministic mapping, exception review, reconciliation history, core evidence reports, account security, billing and support surfaces.
- PowerBot and other AI-assisted product modules are hidden from the controlled-launch customer surface.
- OCR/PDF intake, ERP integrations, team access, approvals, compliance modules, cross-currency reconciliation, forecasting, advanced analytics and enterprise workflow modules are not represented as launch-ready capabilities.
- A roadmap, concept page or internal implementation does not create customer entitlement or a launch availability claim.
Supported operating envelope
These are support ceilings, not speed, scale or benchmark claims. Work outside this envelope is unsupported for the controlled launch and may be refused by the product.
- Browsers: the latest two stable versions of Google Chrome or Microsoft Edge on Windows 10 or Windows 11 desktop.
- Device baseline: at least 8 GiB RAM, 4 logical CPU cores and 2 GiB available persistent browser storage.
- Private/incognito browsing is not supported because durable browser storage can be unavailable or cleared unexpectedly.
- File formats: CSV and XLSX only.
- Per file: up to 100,000 data rows and 100 columns.
- Combined two-ledger run: up to 200,000 data rows.
- File size: up to 50 MiB for CSV and 25 MiB for XLSX.
- Currency: both ledgers in a reconciliation must use the same currency. Cross-currency matching is not a launch capability.
- Users: the controlled-launch workspace is single-user. Team invitations, delegated approvals and multi-user workflow authority are not part of the launch promise.
Customer data-handling guide
Core CSV/XLSX reconciliation is designed around browser-local processing. Identity, tenant/workspace authority, consent versions and billing state are server-authoritative so authentication and access controls cannot be bypassed by changing browser state.
- Uploaded launch files are processed in the browser for the core two-way reconciliation path rather than being silently uploaded to an AI or integration service.
- Browser-local workspace state can use IndexedDB, OPFS/DuckDB-backed storage, localStorage or sessionStorage depending on the specific state being retained.
- Account identity, workspace/tenant binding, accepted Terms/Privacy version, subscription state and security-relevant authority are handled through Certanexa's hosted service infrastructure.
- Hidden AI, OCR and ERP/integration modules are not invoked merely because code for those modules exists in the wider product repository.
- Do not upload data you are not authorized to process. Finance users remain responsible for validating reconciliation results and final accounting decisions.
Cookies and browser storage
Certanexa uses browser storage for authentication continuity, controlled-launch workspace state, preferences and safe return-to/attribution state. The controlled-launch application does not rely on advertising cookies as a reason to upload financial files.
- localStorage: limited preferences, auth/provider state and permitted attribution or return-state data.
- sessionStorage: short-lived signup/OAuth intent and return-to state that should not survive a normal session boundary.
- IndexedDB and OPFS: browser-local application/workspace data where the supported browser exposes those storage APIs.
- Authentication or infrastructure providers may set technically necessary cookies or equivalent browser tokens as part of secure session handling.
- Clearing site data can remove browser-local workspace state and may sign the user out.
Data retention
Retention depends on the class of data. Browser-local financial workspace data is controlled primarily by the user's browser; hosted identity and operational records have separate retention needs.
- Browser-local reconciliation files/workspace state: retained until the user clears/deletes the workspace or clears the site's browser storage; Certanexa does not promise a server-side expiry for data that remains only in the user's browser profile.
- Account, tenant/workspace and consent metadata: retained while the account is active and removed or de-identified through the account-deletion process, subject to security, legal and provider-backup constraints.
- Security and operational diagnostics: operational target of no more than 90 days unless an incident, abuse investigation or legal requirement requires longer preservation.
- Support correspondence: operational target of up to 24 months so prior cases can be understood and reopened.
- Billing/tax transaction records: may be retained for the statutory accounting period required by applicable law or the payment provider even after an account is closed.
Account, workspace and local-data deletion
There are separate deletion boundaries because some launch data is browser-local while account authority is hosted.
- Local workspace data: use the product's clear/delete workspace action where available, or clear Certanexa site data in the browser to remove localStorage, IndexedDB and OPFS data for that browser profile.
- Signing out does not by itself promise deletion of browser-local reconciliation data; deletion is a separate explicit action.
- Account deletion: contact support@certanexa.com from the account email. We verify authority before deleting or de-identifying hosted account/workspace metadata.
- Deletion requests are targeted for completion within 30 days after identity verification, excluding records that must be retained for fraud prevention, security, billing, legal or statutory accounting reasons.
- Provider backups can retain deleted records for a limited recovery window before normal backup expiry; restored data remains subject to the deletion request.
Production service providers and subprocessors
The controlled-launch service uses specialist providers for hosted identity, deployment, transactional email and billing. A provider is listed for the service function it performs; listing does not mean customer financial files are automatically sent to every provider.
- Supabase — authentication, authoritative account/workspace metadata, database and related hosted service functions.
- Vercel — web application hosting, edge/serverless delivery and deployment infrastructure.
- Resend — transactional email delivery where used by the authentication/email delivery configuration.
- Lemon Squeezy — paid subscription checkout, billing lifecycle and payment-provider records where paid billing is enabled.
- AI model providers, OCR providers and ERP/integration providers are not part of the default controlled-launch reconciliation path while those product modules remain release-hidden.
Security contact
Report suspected vulnerabilities, account takeover, unauthorized access or security incidents to security@certanexa.com. Do not include live customer financial files, passwords, access tokens or secret keys in the first report.
- Include the affected URL or surface, a concise reproduction description, impact and safe evidence such as redacted screenshots or request metadata.
- Security reports are prioritized separately from normal feature requests. If the dedicated address rejects delivery, use support@certanexa.com and put SECURITY in the subject.
Support contact and response window
Customer support is available at support@certanexa.com. Response windows are operational targets, not guaranteed contractual SLAs unless a signed customer agreement states otherwise.
- Access, billing or data-loss-risk blockers: initial response target within 1 business day.
- General product questions and non-blocking defects: initial response target within 2 business days.
- Include the account email, browser/version, operating system, approximate time and redacted error text. Do not email raw financial datasets unless support explicitly provides an approved secure transfer method.
Cancellation and refunds
A paid subscription can be cancelled so it does not renew. Unless a signed agreement or applicable law says otherwise, cancellation normally takes effect at the end of the already-paid billing period.
- Cancelling stops future renewal; it does not automatically create a prorated refund for an already-started billing period.
- Duplicate charges, unauthorized charges and billing-provider errors should be reported promptly to support@certanexa.com and will be investigated.
- Any refund required by applicable consumer law, payment-network rules or a signed customer agreement takes precedence over this general controlled-launch policy.
Marketing screenshot policy
Marketing imagery must not make a hidden, mock, internal or platform-direction module look generally available. Current controlled-launch proof is the reachable product surface, not a design concept.
- Screenshots used as product proof must come from a currently reachable release surface and must not reveal customer data.
- Concepts, mockups or roadmap imagery must be visibly labelled as concept/platform direction and cannot be used as evidence of current capability.
- AI, ERP, team access, compliance, forecasting, cross-currency and other release-hidden modules must not appear as ordinary launch navigation or entitlement in marketing proof.
Onboarding and first reconciliation guide
The launch journey is deliberately small: establish an authenticated identity, complete the governed workspace setup, then reconcile two supported files.
- 1. Create an account or sign in at app.certanexa.com. Complete email confirmation when requested.
- 2. Finish authenticated workspace setup. Pricing intent does not grant paid authority until the billing provider confirms it.
- 3. Use a supported Chrome/Edge desktop profile outside incognito/private mode.
- 4. Prepare two same-currency CSV/XLSX ledgers within the published row, column and file-size limits.
- 5. Import ledger A and ledger B, review deterministic field mapping, and correct any unsupported or ambiguous columns before matching.
- 6. Run the two-way reconciliation, review matched and unmatched items, and investigate exceptions using the released deterministic workflow.
- 7. Validate the result with professional finance judgment, then export or save the supported evidence/report output you need.
- 8. Clear the workspace when the browser-local data is no longer needed.
Known limitations and workarounds
Known limitations are published so a customer can distinguish a defect from an intentionally unsupported launch capability.
- Only two-way, same-currency reconciliation is supported. Workaround: split broader processes into separately controlled same-currency two-ledger runs.
- Only CSV and XLSX launch intake is supported. PDF/OCR, Parquet and integration-led intake are not launch promises; export source data to CSV/XLSX first.
- Private/incognito browsing is unsupported because persistent browser storage may not survive. Use a normal supported browser profile.
- The controlled-launch workspace is single-user. Do not rely on hidden team, approval or delegated-role surfaces.
- AI/PowerBot, ERP integrations, forecasting, compliance modules, cross-currency and enterprise workflow surfaces are hidden or internal until their release gates pass. There is no supported workaround that treats them as released features.
- Datasets above the published support envelope should be split before import. Do not treat successful parsing above a ceiling as certified support.
Document consistency
The Terms of Service and Privacy Policy remain the legal-policy documents. This page is the controlled-launch operational disclosure. If a signed customer agreement conflicts with this page, the signed agreement governs for that customer. Material product changes are reviewed against these disclosures before being promoted as customer-ready.