Legal · v1.0 · Updated 2/13/2026
Security Policy
Founding Partner Program Notice — This Platform is currently operated by an independent founder as part of its Founding Partner Program. Company registration details will be published here once the platform is incorporated. Until then, references to 'the Company' shall mean 'the Platform' operated by the Founder.
Encryption
- Data at rest: AES-256
- Data in transit: TLS 1.3
- Passwords: bcrypt with per-user salts
Access
- Role-based access control (RBAC)
- Mandatory MFA for internal admins
- Least-privilege principle
Monitoring
- Structured audit logs of all admin actions
- Real-time anomaly detection
- Failed-login rate-limiting
Vulnerability Management
- Regular dependency scans
- Annual penetration test by an independent firm
Incident Response
Response team available 24×7. Notification obligations under DPDP §8(6) will be met within 72 hours of a data breach becoming known.