Boring on the outside. Serious on the inside.
Your data runs your business. We treat it like a vault: access-scoped, fully logged, and hosted in India.
Passwords & transport
Passwords are hashed with bcrypt and never stored in plain text. Traffic is served over HTTPS, and sessions can be revoked server-side.
Strict tenant isolation
Every query is scoped to your builderId at the middleware layer. Super-admins can cross tenants only with explicit impersonation that lands in your audit log.
Audit-grade trail
Every mutation lands in a time-series audit log. If a primary write blips, the doc is preserved in a dead-letter collection for replay — never silently dropped.
Data residency in India
Your production data is hosted in an Indian region. We do not copy your data out of India.
The full security checklist.
No security-theatre. These are the actual controls our auth, API, and data layers ship with.
Authentication & sessions
Authorization
Network & application security
Observability
Data lifecycle
Every request, end to end.
Encrypted in transit, authenticated, scoped to your tenant, and stored in India — the path every action takes.
How we handle your data.
You own your data
You remain the owner of your data — we only process it to run the product for you. Export everything to CSV any time; a DPA is available on request.
GST-ready invoicing
Invoices carry a valid GSTIN, and your bills can be configured to print your GSTIN on every document.
Hosted in India
Your production data is hosted in an Indian region, so it stays under Indian jurisdiction.
Planned, not yet certified. We'll say so here the day that changes — no badges we haven't earned.
Security, answered plainly.
The questions builders ask before they trust us with their numbers.
Your production data is hosted in an Indian region, and we never copy it out of India.
Traffic is served over HTTPS, and passwords are hashed with bcrypt so they are never reversible. Sessions can be revoked server-side, and accounts lock after repeated failed logins.
No. Every query is scoped to your builderId at the middleware layer, so tenants are isolated by default. Super-admins can cross tenants only through explicit impersonation that is recorded in your audit log.
You own your data. We act only as the processor that stores and runs it for you, you can export everything to CSV any time, and a data processing agreement (DPA) is available on request.
Passwords are hashed with bcrypt and are never reversible. Accounts lock after 5 failed attempts within a 15-minute window, and sessions can be revoked server-side via a token version.
Your data is yours. You can export everything to CSV at any time, and on account closure we delete your data on request — there is no lock-in.
Still have questions? Contact our security team →
Need documentation?
Reviewing us for procurement? Request our security pack — sent to enterprise prospects on request: