Security, privacy and trust — stated plainly
Everything a procurement or security team needs to evaluate InCore in one place — our controls, data residency, privacy posture, certification roadmap, resilience and sub-processors. We're a new product, and we tell you exactly where we are. No inflated claims.
The fast answers
The questions a reviewer asks first — answered up front.
Hosted on AWS in the Asia-Pacific (Mumbai) region — your data stays in India.
HTTPS everywhere; encrypted S3-compatible object storage for documents and media.
Org- and site-scoped access enforced on every request — never trusted from the client.
Field-level change history and e-signature sign-off on every business record.
Automated daily backups with restore drills; soft-delete only — data is never hard-deleted.
Built to India's Digital Personal Data Protection Act — data minimization and your rights.
How the platform is built
Security is designed into every layer — from authentication and tenant isolation to org/site-scoped access, field-level change history, e-signature sign-off and encrypted, backed-up storage.
- JWT short-lived access tokens with refresh rotation and blacklist
- Session capping and active-session governance
- MFA (OTP) enforced by account policy
- Password policy, history and account lockout
- OAuth2 authorization server for governed integrations
- Server-side RBAC via groups and policies
- Org- and site-scoped access — a user sees only their business units and sites
- Module- and object-level permission checks on every protected endpoint
- Deny-by-default: an unknown resource means no access
- Every business record scoped to an Account (tenant) boundary
- Base-model scope keys (tenant / organization / site) never trusted from the client
- Account-scoped querysets across all modules
- Isolation verified by automated tests and code review
- Field-level change history on every record — a full old → new timeline
- Multi-tier e-signature sign-off (Supervisor → PM → PMO) with IP / user-agent capture
- Soft delete only — business data is never hard-deleted
- Activity log, active sessions and API denial log
- Idempotent sync — a retried field mutation never double-posts
- Append-only stock, quantity and e-signature ledgers
- Server-set timestamps and correlation IDs for traceability
- Conflict-safe reconciliation between field capture and systems of record
- HTTPS everywhere; encrypted S3-compatible object storage
- Daily backups with tested restore
- Restricted database access and secret hygiene — never log secrets
- Separate Development, QA/Staging, UAT and Production; controlled releases with rollback
Where we are — honestly
We won't badge what we haven't earned. Here's the real status of every attestation, and what's on the roadmap as we scale.
Independent testing scheduled ahead of general availability; the overview and results are shared with prospects on request.
Planned as we scale. Until earned, judge us on the architecture and documentation — not a badge.
An ISMS aligned to ISO 27001 controls is the target as the customer base grows.
Data minimization, purpose limitation, and data-subject rights (access / erase) built in from day one.
We complete your questionnaire and walk your team through controls, data flows and sub-processors before you commit.
Your data, your rights
Built to align with India's Digital Personal Data Protection Act (DPDP Act 2023) — with data ownership, minimization and transparent sub-processing.
Your project data is yours. We process it to run the service you've licensed — nothing else — and you can export it. On exit, we return or delete it per your agreement.
We collect only what the platform needs to operate, and use it only for that purpose — the core of DPDP-Act alignment.
Built to support access and erasure of personal data, with the audit trail to evidence it.
We keep a current list of sub-processors and the data each handles, shared with prospects and customers on request.
Uptime, backups and recovery
What keeps the service running — and what happens when something goes wrong.
We agree uptime and response targets that fit your operation in your contract. Founding customers get priority support with a direct line to the engineering team.
Automated daily backups with tested restore, and defined recovery objectives. Soft-delete-only means accidental deletions are recoverable.
Development, QA/Staging, UAT and Production are separate. Releases are controlled, reviewed and reversible with rollback.
A defined process to detect, contain, communicate and remediate — with customer notification per your agreement.
Who we rely on
The third parties that help us run InCore, and where your data sits. The full current list is provided to prospects and customers on request.
| Sub-processor | Purpose | Data region |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting & encrypted object storage | Asia-Pacific (Mumbai), India |
We notify customers of material changes to sub-processors per your agreement. Request the full, current list any time.
Evaluating InCore for procurement?
We'll share our security overview, complete your vendor security questionnaire, provide the sub-processor list and walk your team through our controls and data flows.
Reporting a vulnerability? Email security@incore.in.