Security & Trust

Data Security

How DarzioTech protects your business data with enterprise-grade security — encryption, access controls, infrastructure hardening, and incident response.

Last Updated: May 2025
1

Security Architecture

DarzioTech is built on a defence-in-depth architecture. Every layer of the stack — network, application, database, and client — implements independent security controls so that no single failure compromises your data.

The platform enforces HTTPS-only access with HSTS headers, content security policies, and strict CORS controls. All API endpoints are rate-limited to prevent abuse.

2

Encryption Standards

All data in DarzioTech is encrypted at every stage — in transit and at rest.

  • In transit: TLS 1.2/1.3 with strong cipher suites on all connections
  • At rest: AES-256 encryption on all database volumes and backup files
  • Passwords: bcrypt hashing with a cost factor of 12 — never stored in plaintext
  • JWT tokens: signed with RS256 (asymmetric), short-lived (15 min) with secure refresh
  • SMTP credentials and API keys: encrypted in the database, never exposed via API
3

Access Controls

DarzioTech enforces strict multi-tenant isolation — every database query is scoped to your tenant ID. It is architecturally impossible for one shop's data to leak into another's.

Within your account, role-based access control (RBAC) lets you assign staff to Owner, Manager, or Staff roles, each with precisely scoped permissions.

  • Owner role: full access including billing, staff management, and data export
  • Manager role: orders, customers, staff scheduling — no billing or admin settings
  • Staff role: assigned tasks and attendance only — no sensitive business data
4

Data Centers & Infrastructure

DarzioTech is hosted on infrastructure located within India, complying with Indian data localization requirements. Servers are deployed behind a firewall with SSH key-only access and no exposed management ports.

Automated daily backups are encrypted and stored in a geographically separate location within India. Point-in-time recovery is available for the last 30 days.

5

Vulnerability Management

We maintain a continuous patching schedule for all server OS packages, language runtimes, and dependencies. Critical CVEs are patched within 24 hours of disclosure.

Our codebase undergoes regular internal security reviews covering OWASP Top 10 vulnerabilities including SQL injection, XSS, CSRF, and insecure deserialization.

6

Incident Response

In the event of a confirmed security incident affecting your data, we will notify affected users within 72 hours of detection via email, in accordance with CERT-In guidelines.

Notifications will include: nature of the incident, data affected, steps taken to contain it, and recommendations for your account.

  • Detection & containment: within 4 hours of incident identification
  • Internal escalation: immediate notification to our security team
  • User notification: within 72 hours of confirmed breach (CERT-In compliant)
  • Post-incident report: published within 14 days with root cause and remediation
7

Your Security Responsibilities

Security is a shared responsibility. While DarzioTech secures the platform infrastructure, you are responsible for the security of your account credentials and the devices used to access DarzioTech.

  • Use a strong, unique password for your DarzioTech account
  • Do not share login credentials with unauthorized individuals
  • Log out of DarzioTech on shared or public devices after use
  • Report any suspicious activity to support@darziotech.in immediately
  • Regularly review staff access and remove accounts for former employees

Have questions about this policy?

support@darziotech.in