SECURITY · TRUST · COMPLIANCE

Bank-Grade Security

Your financial data, documents, and business intelligence are protected by multiple layers of enterprise-grade security controls.

🔐
AES-256
Encryption at rest
🌐
TLS 1.3
Encryption in transit
📋
ISO 27001
Info Security Mgmt
SOC 2 Type II
In progress
🇪🇺
GDPR
EU Data Protection
🇮🇳
DPDPA 2023
India Data Protection
🏦
PCI-DSS
Payment Security
🔒
Row-Level Security
Database isolation
🛡️
WAF
Web App Firewall
🔍
Pen Testing
Quarterly audits
📊
SIEM
24/7 monitoring
🚨
Incident Response
72hr notification

Data Encryption

  • All data encrypted at rest using AES-256-GCM
  • All data in transit protected by TLS 1.3 with HSTS
  • Database backups encrypted with separate key management
  • VDR documents encrypted with per-document encryption keys
  • Key management via industry-standard HSM-backed systems

Access Control

  • Role-Based Access Control (RBAC) — 8 distinct roles with granular permissions
  • Row-Level Security (RLS) on all Supabase database tables
  • Multi-Factor Authentication (MFA) available on all accounts
  • Session management with secure HTTP-only cookies
  • Admin actions require re-authentication and are fully audit-logged
  • Service accounts use scoped API keys — no master credentials in application code

Virtual Data Room Security

  • NDA-gating — no document access without executed NDA
  • Automatic PDF watermarking with user ID + timestamp + IP
  • Access logs for every document view, download, and share
  • Time-limited access tokens for investor document access
  • AI-powered sensitive data detection before upload
  • Document shredding on subscription expiry (30-day grace)

Infrastructure Security

  • Hosted on AWS (Mumbai for India, Frankfurt for EU, Virginia for US)
  • Vercel Edge Network with DDoS protection
  • Railway compute with network isolation
  • Web Application Firewall (WAF) with OWASP ruleset
  • Rate limiting on all API endpoints
  • Automated vulnerability scanning on every deployment
  • No data stored in third-party AI provider infrastructure (all AI processing is on our stack)

Compliance & Audit

  • GDPR Art. 25 — Privacy by Design and by Default
  • DPDPA 2023 — Data Principal rights management built-in
  • SEBI/RBI — Audit trails for all capital market-related actions
  • PMLA — AML transaction monitoring and suspicious activity flagging
  • Full audit log of all admin actions, data access, and AI decisions
  • Quarterly penetration testing by independent security firm
  • Annual security assessment and ISO 27001 gap analysis

Payment Security

  • PCI-DSS Level 1 compliant payment processing via Razorpay / Stripe / PayTabs
  • Card data never touches CapitalSync servers — tokenisation by payment gateway
  • Razorpay webhook signatures verified on every payment event
  • Transaction monitoring for fraud patterns
  • Refund and dispute handling in compliance with RBI payment guidelines

Responsible Disclosure

We operate a responsible disclosure programme. If you discover a security vulnerability in CapitalSync, please report it responsibly to security@capitalsync.net.

We commit to: acknowledge receipt within 24 hours · provide status updates every 7 days · resolve critical vulnerabilities within 30 days · not pursue legal action against good-faith security researchers following this policy.

Data Breach Notification Policy

In the event of a data breach affecting your personal data: We will notify affected users within 72 hours of discovery (GDPR Art. 34 / DPDPA Sec. 8(6)). We will notify the relevant supervisory authority (Data Protection Board of India / EU DPA / DIFC CDPP) within 72 hours. Notification will include nature of breach, data affected, likely consequences, and remediation steps.

Privacy PolicyTerms of ServiceDisclaimer← Back to Home