Nelum

Security & data

What we hold, and what we never hold

You are being asked to put incorporation documents, ownership structures, and passports into someone else's platform. These are the answers to the questions you should be asking before you do.

Nelum never holds your funds

Settlement is conducted directly between counterparties using non-administered escrow — funds move between wallets the counterparties themselves control. Nelum does not hold, control, custody, transmit, or have any power to move client funds or private keys at any time. Nelum's role in settlement is limited to read-only verification that a transfer the counterparties describe has occurred on-chain.

There is no Nelum wallet in the middle of your trade, no private key we could lose, and no balance we could freeze. That also means a transfer to a wrong or fraudulent address cannot be reversed by us — the security of your own wallet remains yours.

Verification documents are write-only

Incorporation certificates, ownership registers, and identity documents are submitted into private storage that has no read path through the platform. Once submitted, they cannot be downloaded again — including by the company that submitted them. There is nothing to leak through the product surface.

Access is scoped at the database

Row-level security governs every read. A company sees its own records and the deals it is party to. Trade documents are visible to the two counterparties on that deal and nobody else. This is enforced in the database, not by application code that could be bypassed.

Identity images expire

Representative photographs are held privately and served only through short-lived signed links, including on the public credential page. There is no permanent public URL for anyone's face.

Progressive disclosure of identity

On the marketplace, companies are identified by a pseudonymous reference with their country and verification status. Legal names are exchanged when both sides enter a deal, not before — so browsing the market does not expose who is buying what.

Every action is attributable

Stage advances, document uploads, role changes, and verification decisions are recorded with actor and timestamp. Company governance events record which fields changed — never the values, so an audit trail proves a change occurred without becoming a second copy of your data.

Retention is deliberate

Verification and transaction records are retained for the periods anti-money-laundering law requires, which is at least five years after the end of the relationship. Where that obligation applies we will say so rather than quietly keeping data or quietly deleting evidence.

Your rights over your data

You can access, correct, and port your personal data, and withdraw consent where processing rests on it — including consent to publish a representative's photograph on their credential page. Withdrawing that consent removes the photograph from public view.

Where anti-money-laundering law requires us to retain a verification record, that obligation takes precedence over a deletion request. We will restrict the record to meeting the legal obligation and tell you we have done so. The full detail is in our Privacy Notice.

Questions before you register?

If your compliance or security team needs detail we have not published here, ask us directly.

Contact us