Send us twelve months of records. We'll return a documentary diagnosis of your estate →
Security

A bank will ask. Here are the answers.

Our largest customers are banks and NBFCs, so the security question arrives early and it arrives from someone whose job is to find the gap. This page states what is in place, what is aligned to a standard, and what is still in progress — labelled as such rather than rounded up.

01

How the data is protected

End-to-End Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

Secure Cloud Infrastructure

Hosted on enterprise-grade cloud infrastructure with redundancy and failover capabilities.

Access Controls

Role-based access control (RBAC) with multi-factor authentication for all user accounts.

Regular Security Audits

Continuous vulnerability assessments and penetration testing by third-party security experts.

Data Backup & Recovery

Automated daily backups with point-in-time recovery and disaster recovery protocols.

24/7 Monitoring

Round-the-clock security monitoring with automated threat detection and response.

02

Where compliance actually stands

Status labels are literal

Four standards, each with the status it has earned. “Aligned” means our controls are built to the standard without a certificate on the wall; “In Progress” means the audit is underway and not finished. Neither is the same as certified, and we would rather you heard that from us than from your own diligence process.

Aligned

ISO 27001

Information security management system aligned with international standards.

In Progress

SOC 2 Type II

Security, availability, and confidentiality controls audit underway.

Compliant

GDPR Ready

Data protection measures aligned with European privacy regulations.

Compliant

DPDP Act 2023

Fully compliant with India's Digital Personal Data Protection Act.

03

Data protection practices

Privacy by Design

Data minimization principles embedded in our product development lifecycle.

Data Residency

All customer data is stored in India-based data centers for compliance with local regulations.

Data Retention

Clear data retention policies with automated deletion when data is no longer needed.

Vendor Security

Rigorous security assessments for all third-party vendors and service providers.

04

The questions diligence asks

Security review

Need to run this past your InfoSec team?

Send us the questionnaire. We will complete it and tell you plainly which rows we cannot answer yet rather than leaving them blank.

[email protected]