Bank-Grade Security

Enterprise-Grade

Your data security and privacy are our top priorities. Multi-layered protection at every level of the stack โ€” designed for Indian businesses and regulators.

Encryption
AES-0
Bits at rest & transit
Uptime SLA
0
Monthly availability
Compliance
0
Active certifications
Monitoring
24ร—0
Security ops center
Our Security Approach

Multi-Layered Protection

Every rupee, every byte, every API call โ€” protected by overlapping controls and continuous validation.

Data Encryption

AES-256 at rest, TLS 1.3 in transit, tokenization for card and bank account numbers. Master keys rotated every 90 days via AWS KMS HSM.

Regulatory Compliance

PCI DSS Level 1, ISO 27001:2022, SOC 2 Type II, GDPR and Indian IT Act 2000 aligned. Reports available on request under NDA.

Advanced Authentication

TOTP + SMS MFA, biometric login, risk-based step-up auth, RBAC with maker-checker flows and IP allow-lists for enterprise plans.

Fraud Prevention

ML risk engine scores every payout and payout link. Device fingerprinting, velocity checks, geo-anomaly detection, manual review queues.

Infrastructure Security

AWS ap-south-1 SOC 2 data centers, private VPCs, hardened bastions, zero-trust IAM, weekly CVE scans, WAF + DDoS mitigation.

Backup & Recovery

Continuous incremental backups, cross-region replication, 35-day point-in-time restore, annual disaster-recovery fire drills with RTO < 4 hours.

Compliance & Certifications

Audited, Certified, Trusted

Independent third-parties validate our security posture every year. Badges below are representative; copies available via your account manager.

PCI DSS
Payment Card Industry Level 1
ISO 27001
Information Security Mgmt 2022
SOC 2
Service Org Control Type II
GDPR
EU Data Protection Ready
Security Process

Continuous Improvement Loop

Security isn't a checkbox. It's a weekly cadence of scans, reviews, tests and training โ€” formalized below.

01

Quarterly Security Audits

Internal audit team reviews access logs, IAM policies, secrets rotation and data retention controls. Action items tracked with 30-day SLOs.

02

Bi-Annual Penetration Testing

CERT-IN empanelled firms run black-box, gray-box and red-team exercises. Scope includes web, mobile, APIs and cloud infra.

03

Secure SDLC + SAST/DAST

OWASP ASVS checklist, mandatory PR reviews, pre-commit hooks, Snyk SAST + SCA, OWASP ZAP DAST in every staging pipeline.

04

24ร—7 SOC Monitoring

SIEM ingests VPC flow, WAF, CloudTrail and app logs. Threat intel feeds + automated runbooks. Critical pages: on-call paged within 5 min.

05

Ongoing Team Training

Every team member does secure-coding / phish-resistance modules quarterly. New hires complete mandatory security onboarding in week one.

Responsible Disclosure

Found a vulnerability?

We thank independent researchers with up to โ‚น2,00,000 bounty + hall of fame credit, per severity.

SEVERITY
โ‚น5K โ€“ โ‚น2L
RESPONSE SLA
24 hrs
PATCH SLA
30 days
Report to security@credvue.in with full PoC, steps and impact. We'll open a secure channel within 24 hours.
Report a Vulnerability
Security FAQ

Frequently Asked Questions

Quick answers on encryption, compliance, incidents and account controls.

Every card number, bank account and UPI handle is tokenized via PCI-compliant vaults. PII fields are AES-256-GCM encrypted with envelope encryption (DEK wrapped by AWS KMS CMKs). All API traffic uses TLS 1.3 with forward secrecy. We maintain PCI DSS Level 1 โ€” the highest standard for payment processing.
Our CSIRT responds per the documented runbook: (1) containment within 1 hour, (2) forensic investigation, (3) regulator + customer notifications within mandatory timelines (72h under GDPR / Indian DPDP Act), (4) root-cause + remediation tracked to closure. We also carry cyber liability insurance with โ‚น50 Cr aggregate cover.
Critical / CVSS โ‰ฅ 9.0 patches applied within 24 hours in production. High severity (7.0โ€“8.9) within 7 days. Medium (4.0โ€“6.9) in the next release cycle. All packages scanned weekly via Snyk and Trivy; container images signed with Sigstore cosign.
Every plan supports TOTP MFA, SMS fallback, session timeout and device history. Business and Enterprise plans add: IP allow-list, API key restrictions, role-based access with maker-checker approvals, webhook signing secrets, custom password policies and audit log export (SIEM-ready JSON).
Default retention: customer transaction data for 7 years (Indian regulatory requirement), audit logs for 2 years, raw backups for 35 days PITR then tiered archive. On written deletion request, active records are cryptographically shredded within 30 days; backup copies expire naturally per tier. This is audited annually.

Need a copy of our SOC 2 report?

Share your company email and we'll route it through your account manager or sales engineer within one business day.