Access is locked down
- Our servers have no open door to the public internet. Administrative access is only possible through a private, encrypted VPN tunnel tied to specific cryptographic keys held on two enrolled devices. An outside attacker scanning our address simply sees nothing.
- Password logins are disabled entirely. There is no password to guess, phish or reuse — access requires a cryptographic key that never leaves the enrolled device.
- Automated brute-force protection blocks repeated access attempts before they become a problem.
Your credentials are never lying around
- We never ask for your passwords. We work through delegated, revocable access that stays in your name — see our access checklist for exactly what we ask for and why.
- Every secret our systems use — API keys, tokens — is held in an encrypted vault, never written into code or configuration files. An independent scan confirmed zero plaintext credentials on disk.
Watched around the clock
- Continuous monitoring runs on every server — a daily health check plus automatic anomaly alerts every fifteen minutes.
- An unusual spike in outbound data — the clearest early sign of a breach — triggers an immediate alert.
- File-integrity monitoring fingerprints hundreds of thousands of system files nightly, so any unexpected change is caught.
- A tripwire watches our domains' DNS records and alerts instantly on any unexpected change.
- We run our own automated penetration testing continuously against our systems, to find and fix weaknesses before anyone else does.
Encrypted end to end
- Every website we run is served over HTTPS/TLS, and all administration travels inside the encrypted VPN tunnel.
- Where we hold customer personal data — name, email, phone, address — it is encrypted at rest in an isolated, access-logged table. Never in plain text.
- Records are linked internally using keyed hashing, so our systems can work with data without exposing the underlying identifiers.
You stay in control
- Least privilege. We ask for the lowest level of access that does the job, and read-only wherever the platform allows it.
- Revoke us instantly, any time. Your accounts, assets and data always remain yours — nothing is held hostage and nothing needs our permission to take back.
- Every access to personal data is written to a tamper-evident audit log.
- Built-in erasure and consent enforcement. Right-to-be-forgotten is built in, and consent is enforced at the system level — data cannot be used for targeting unless the customer has opted in. Aligned with India's DPDP Act.
What we do not claim. We hold no ISO or SOC 2 certification, and we will not tell you otherwise.
Everything on this page describes controls that are running today. If a security question matters to your
decision, ask us and you will get a straight answer.
Have a security question before you start?
Ask it before you grant a single permission. We would rather answer twenty questions now than have you wondering later.