We follow generally accepted industry practices for information security: encrypted connections (TLS) for all data in transit, encryption at rest with our cloud providers, role-based access control so staff see only what their role requires, row-level access rules in our database, audit logging of internal activity, strong authentication for staff accounts, and periodic security reviews of the platform.
We align our practices with recognised guidelines including the Information Technology Act, 2000 and the SPDI Rules, 2011, the Digital Personal Data Protection Act, 2023, and — where applicable to clients outside India — GDPR principles of lawful basis, purpose limitation, data minimisation and storage limitation. No method of transmission or storage is perfectly secure, so we ask you to keep your account credentials confidential.