Skip to content

Security

Security you can show your client.

The controls, defaults, and reviews behind ProjectSathi. Updated as our posture evolves.

Encryption

TLS 1.2+ in transit. AES-256 at rest. Database backups encrypted with rotated keys.

Access control

Role-based access per site. SSO and audit trail on Enterprise. Least-privilege production access.

Hosting

Hosted on AWS Mumbai region. Data stays in India unless you ask otherwise.

Backups

Automated daily backups. 30-day point-in-time recovery on Growth and above.

Audit & monitoring

Application and infrastructure logs retained for 90 days. Anomaly alerts on production access.

Vulnerability management

Continuous dependency scanning. Quarterly third-party penetration tests on Enterprise.

Need a deeper review?

Enterprise customers get a security review, signed DPA, and a quarterly briefing on our security roadmap. Write to security@projectsathi.org to start.