Trust & Security

Security at Shivakarma

Security is not a feature we add at the end - it runs through how we build, host and operate every system we deliver. This page explains the safeguards protecting your data and how to report a problem to us.

How We Protect You

Our Security Pillars

Layered controls across infrastructure, application, people and process - so that a single failure never becomes a breach.

Data Encryption

TLS 1.2+ for all data in transit and AES-256 encryption at rest for databases, backups and stored documents.

Access Control

Role-based permissions on a least-privilege model, enforced multi-factor authentication, and quarterly access reviews.

Infrastructure Hardening

Firewalled, patched servers in secure data centres with network segmentation and continuous availability monitoring.

Secure Development

Peer-reviewed code, parameterised database access, dependency scanning, and OWASP Top 10 checks before every release.

Backup & Recovery

Automated daily backups with retention windows, periodic restore testing, and documented recovery objectives per service.

People & Process

Background-verified staff, signed confidentiality agreements, security awareness training, and a defined incident response plan.

Responsible Disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers and will not pursue legal action against anyone who reports a genuine issue in good faith and follows the guidelines below.

What to send us
  • The affected URL, endpoint or product

  • Clear steps to reproduce the issue

  • Proof of impact - screenshots or request logs

  • Your name, if you would like to be credited

Please do not
  • Access, modify or delete data that is not yours

  • Run denial-of-service or high-volume automated tests

  • Use social engineering or physical intrusion

  • Disclose the issue publicly before it is fixed

Acknowledged within 2 working days
Target fix window 30 days for critical issues
Chat on WhatsApp