SECURITY · TRUST · COMPLIANCE
Bank-Grade Security
Your financial data, documents, and business intelligence are protected by multiple layers of enterprise-grade security controls.
🔐
AES-256
Encryption at rest
🌐
TLS 1.3
Encryption in transit
📋
ISO 27001
Info Security Mgmt
✅
SOC 2 Type II
In progress
🇮🇳
DPDPA 2023
India Data Protection
🔒
Row-Level Security
Database isolation
🔍
Pen Testing
Quarterly audits
🚨
Incident Response
72hr notification
Data Encryption
- All data encrypted at rest using AES-256-GCM
- All data in transit protected by TLS 1.3 with HSTS
- Database backups encrypted with separate key management
- VDR documents encrypted with per-document encryption keys
- Key management via industry-standard HSM-backed systems
Access Control
- Role-Based Access Control (RBAC) — 8 distinct roles with granular permissions
- Row-Level Security (RLS) on all Supabase database tables
- Multi-Factor Authentication (MFA) available on all accounts
- Session management with secure HTTP-only cookies
- Admin actions require re-authentication and are fully audit-logged
- Service accounts use scoped API keys — no master credentials in application code
Virtual Data Room Security
- NDA-gating — no document access without executed NDA
- Automatic PDF watermarking with user ID + timestamp + IP
- Access logs for every document view, download, and share
- Time-limited access tokens for investor document access
- AI-powered sensitive data detection before upload
- Document shredding on subscription expiry (30-day grace)
Infrastructure Security
- Hosted on AWS (Mumbai for India, Frankfurt for EU, Virginia for US)
- Vercel Edge Network with DDoS protection
- Railway compute with network isolation
- Web Application Firewall (WAF) with OWASP ruleset
- Rate limiting on all API endpoints
- Automated vulnerability scanning on every deployment
- No data stored in third-party AI provider infrastructure (all AI processing is on our stack)
Compliance & Audit
- GDPR Art. 25 — Privacy by Design and by Default
- DPDPA 2023 — Data Principal rights management built-in
- SEBI/RBI — Audit trails for all capital market-related actions
- PMLA — AML transaction monitoring and suspicious activity flagging
- Full audit log of all admin actions, data access, and AI decisions
- Quarterly penetration testing by independent security firm
- Annual security assessment and ISO 27001 gap analysis
Payment Security
- PCI-DSS Level 1 compliant payment processing via Razorpay / Stripe / PayTabs
- Card data never touches CapitalSync servers — tokenisation by payment gateway
- Razorpay webhook signatures verified on every payment event
- Transaction monitoring for fraud patterns
- Refund and dispute handling in compliance with RBI payment guidelines
Responsible Disclosure
We operate a responsible disclosure programme. If you discover a security vulnerability in CapitalSync, please report it responsibly to security@capitalsync.net.
We commit to: acknowledge receipt within 24 hours · provide status updates every 7 days · resolve critical vulnerabilities within 30 days · not pursue legal action against good-faith security researchers following this policy.
Data Breach Notification Policy
In the event of a data breach affecting your personal data: We will notify affected users within 72 hours of discovery (GDPR Art. 34 / DPDPA Sec. 8(6)). We will notify the relevant supervisory authority (Data Protection Board of India / EU DPA / DIFC CDPP) within 72 hours. Notification will include nature of breach, data affected, likely consequences, and remediation steps.