Security & Compliance

Last updated: 19 April 2026.

This page is our commitment to transparency. We disclose our security architecture, compliance status, and audit roadmap honestly — whether they are completed, in progress, or planned. If you have specific security questions before signing up, email [email protected].

Security architecture

ControlImplementationStatus
Encryption at restAES-256-GCM (Cloudflare D1, R2 default)Active
Encryption in transitTLS 1.2+ on all endpointsActive
Web Application FirewallCloudflare WAF with managed rulesetsActive
DDoS protectionCloudflare network-layer protectionActive
HSTS & strict CSPEnforced on all pagesActive
Multi-tenant isolationPer-tenant Cloudflare D1 databaseActive
Data residency by countryIndia / UAE / Singapore / EU / US regional D1Active
API credential vaultAES-GCM encrypted, rotated root keysActive
Audit loggingEvery data access logged immutablyIn progress
Role-based access controlPer-tenant RBAC matrixIn progress
Multi-factor authenticationFor admin and staff accessIn progress
72-hour breach notificationMonitoring + alert pipelineIn progress
Customer-managed keys (BYOK)Customer uploads encryption keyPlanned (Enterprise plan)
Zero-knowledge architectureField-level encryption with customer keysPlanned (Enterprise plan)

Compliance status

FrameworkStatusTarget date
DPDPA 2023 (India)CompliantActive
RBI Master Directions on IT (NBFC sector relevant)AlignedActive
GDPR (EU/UK)AlignedActive for EU/UK tenants
UAE PDPLAlignedActive for UAE tenants
Singapore PDPAAlignedActive for Singapore tenants
VAPT (Vulnerability & Penetration Test)PlannedWithin 6 months of go-live
SOC 2 Type IPlannedWithin 12 months
SOC 2 Type IIPlannedWithin 18 months
ISO 27001:2022PlannedWithin 18–24 months
PCI-DSSN/AWe don't store card data — gateways are PCI-certified

Underlying infrastructure certifications

While we work toward our own certifications, our infrastructure provider Cloudflare maintains the following independent certifications that benefit our platform:

Sub-processor certifications

Sub-processorFunctionTheir certifications
CloudflareCloud infrastructureSOC 2 II, ISO 27001, PCI-DSS L1
RazorpayPayment gatewayPCI-DSS L1, ISO 27001, RBI-licensed PA
CashfreePayment gateway (backup)PCI-DSS L1, ISO 27001, RBI-licensed PA
SurepassKYC verificationUIDAI-certified OVSE, ISO 27001
SetuAccount Aggregator (TSP)Sahamati-certified, partnered with RBI-licensed AAs
WhiteBooksGST e-Invoice + filingGSTN-licensed GSP
AWSEmail delivery (SES)SOC 1/2/3, ISO 27001, FedRAMP, etc.
MetaWhatsApp Business APISOC 2, ISO 27001

Customer-controlled security features

Reporting security issues

If you discover a security vulnerability:

Requesting our security documents

The following documents are available under NDA for prospective customers:

Email [email protected] with your NDA or sign ours.

Honest disclosure

We are an early-stage SaaS platform. We do not yet have SOC 2 or ISO 27001 certifications — and we will not pretend otherwise. Our certification roadmap above is realistic, not aspirational. If your organization requires immediate certified-platform assurance before adoption, we recommend a phased approach:

We respect your security requirements and would rather lose a deal than over-promise on certifications we don't yet hold.

Contact

Security: [email protected]
Privacy/data requests: [email protected]
Data Protection Officer: [email protected]
General: [email protected]