Home / Security & trust

We ask you to put your brand behind our codes.

That only works if our own security, privacy and residency standards are beyond argument. Here is exactly what we do, in plain language, with no marketing softening.

01

Architecture & tenant isolation

Every customer runs in a logically isolated tenant. Identifiers, signing keys, consumer records and audit logs are partitioned at the data layer and enforced at the access layer — not filtered by a query parameter that someone could forget to apply.

Per-tenant signing keys, never shared or reused
Row-level isolation enforced at the database layer
Separate environments for production, staging and testing
No customer data in non-production environments
Tenant isolation Dedicated keys Env separation
02

Encryption & key management

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Signing keys are held in a managed key store and are never written to application logs, backups in plaintext, or developer machines.

TLS 1.3 for all external and internal traffic
AES-256 at rest for databases, object storage and backups
Hardware-backed key storage with scheduled rotation
Encrypted, tested backup and restore procedures
TLS 1.3 AES-256 Key rotation
03

Identity & access control

Access is granted by role and reviewed quarterly. Enterprise customers can federate identity through their own provider, and every privileged action is attributable to a named human being — not a shared login.

Role-based access with least-privilege defaults
SSO and SCIM provisioning on Enterprise
Mandatory multi-factor authentication for all staff
Immutable audit logs of every privileged action
RBAC SSO + SCIM Audit logs
04

India data residency

Serialization records, consumer verification data and backups are stored in Indian data centres by default. This is our starting position, not a paid enterprise upgrade.

Primary and backup storage in India
No cross-border replication of customer data by default
On-premises or private-cloud deployment available
Documented sub-processor register, reviewed annually
India primary No default egress On-prem option
05

DPDP & consumer privacy

A verification scan should not require a shopper to hand over their identity. We collect the minimum needed to trace a unit, and we only collect personal data when the consumer actively chooses to claim a reward or register a warranty.

Explicit, purpose-limited consent with plain-language notice
Verification works fully without any personal data
Data-subject access, correction and erasure tooling
Configurable retention with automated expiry
Data processing agreements available for every customer
DPDP aligned Consent capture Retention limits
06

Operational security

Secure development is enforced by process, not intention. Code review is mandatory, dependencies are scanned continuously, and the same discipline applies to our own staff as to anyone else.

Mandatory peer review and automated SAST in CI
Continuous dependency and container scanning
Annual independent penetration testing
Documented incident response with customer notification SLAs
SAST in CI Dep scanning Annual pen test
07

Compliance posture

We are explicit about what we hold today and what is in progress. If an RFP asks for a certification we do not yet have, we will tell you rather than quietly implying otherwise.

DPDP-aligned data handling and records of processing
GST-compliant contracting and invoicing
ISO 27001 readiness programme underway
SOC 2 Type II audit planned for 2027
Security questionnaire responses available on request
DPA available ISO 27001 in progress SOC 2 planned 2027

Responsible disclosure

If you believe you have found a security vulnerability in VeriTrace, please tell us before you tell anyone else. We will acknowledge within one working day, keep you updated, and credit you publicly if you wish.

Incident response commitments

Acknowledge any confirmed incident to affected customers within 24 hours
Written root-cause analysis within 7 days of resolution
No silent fixes — you will always hear it from us first