🔐
Data privacy — GDPR & India DPDP
A lawful basis for every purpose, consent on every form (recorded, not just ticked), a full privacy policy with named sub-processors, data-subject rights and defined retention. EU-facing apps add a §5 DDG Impressum.
Built to
♿
Accessibility — WCAG 2.1 AA
Colour-contrast, full keyboard navigation, screen-reader labels, visible focus and reduced-motion support. Our latest audited build scores full WCAG 2.1 AA.
Met on audited apps
🛡️
App security — OWASP Top 10
Server-side validation, rate limiting, no secrets in the browser, security headers (CSP, HSTS), generic error pages and least-privilege multi-tenant isolation enforced with row-level security.
Built to
📜
SOC 2 & ISO 27001
We design to the SOC 2 and ISO 27001 control sets, but these are independent certifications that need an external auditor and an observation window. We have not obtained them yet — and we'll say so plainly until we do.
Roadmap — not yet certified
🔒
Privacy-first by default
We use only cookieless, first-party analytics — aggregate page views, nothing more. No cookies, no cross-site tracking, no advertising pixels. Your business data is yours; it is never the product.
Met
💳
Card payments — PCI DSS
Our apps record cash, UPI, bank and cheque accounting and never store card data, so PCI DSS doesn't apply. If card payments are ever added, we use hosted checkout to stay in the smallest possible scope.
Out of scope