Trust & security

Your franchisees' data, and what we do with it

A franchise platform holds other people's businesses: their sales, their agreements, their staff. Here is how that is protected, in plain terms — and where to read the current detail rather than a marketing summary of it.

The posture

How your data is protected

Isolation is structural

Every record carries its organisation’s identity and every query is scoped to it at the framework layer, not by a check each feature has to remember. Cross-tenant access exists only through explicit, audited administrative tooling.

Access is a capability, not a role

Each sensitive action maps to a named capability granted per member. The API enforces it and the interface only mirrors it, so hiding a button is never what keeps someone out.

Credentials and codes are hashed

Passwords and one-time codes are stored only as cryptographic hashes. One-time email codes protect signup, password reset and privileged logins, and the platform-owner console requires a second factor.

Card data never reaches us

Payments run through Razorpay. Card details are handled entirely on their side and are not stored on our servers.

Sensitive actions leave a trail

Append-only audit logs cover privileged actions, consent capture and rights-request handling — including who acted, and on whose behalf when a consultancy operates inside a client’s workspace.

Hosted in India, over TLS

The platform runs on infrastructure in India and every surface is served over TLS. Databases are backed up on a schedule and deployments are scripted rather than manual.

The authoritative version

The full posture lives in the app

The complete security page — including the current sub-processor table and the responsible-disclosure address — is served from the platform itself, where it is rendered from live configuration rather than copied into a marketing page. That is the version to read, and the version to send to a security reviewer.

What we do not claim

  • No ISO 27001 or SOC 2 certification. We have not been through either audit, and a badge we have not earned is worse than none.
  • No claim of an independent penetration test. If one matters to your procurement, raise it with us before you buy.
  • The security page and the legal pages are marked as pending legal review until counsel signs them off.

If you find a problem

Responsible disclosure

If you believe you have found a security vulnerability, write to us with reproduction details. We acknowledge reports promptly, do not pursue good-faith researchers, and credit fixes where they are wanted. The disclosure address is on the full security page.

Questions a security review would ask

Send them to us before you buy rather than after. We would rather answer a hard question early.