Trust Center

Security, privacy and trust — stated plainly

Everything a procurement or security team needs to evaluate InCore in one place — our controls, data residency, privacy posture, certification roadmap, resilience and sub-processors. We're a new product, and we tell you exactly where we are. No inflated claims.

At a glance

The fast answers

The questions a reviewer asks first — answered up front.

🇮🇳
Data residency in India

Hosted on AWS in the Asia-Pacific (Mumbai) region — your data stays in India.

🔒
Encrypted in transit & at rest

HTTPS everywhere; encrypted S3-compatible object storage for documents and media.

🛡️
Server-side RBAC, deny-by-default

Org- and site-scoped access enforced on every request — never trusted from the client.

📝
Full audit trail

Field-level change history and e-signature sign-off on every business record.

💾
Daily backups, tested restore

Automated daily backups with restore drills; soft-delete only — data is never hard-deleted.

⚖️
DPDP Act 2023 aligned

Built to India's Digital Personal Data Protection Act — data minimization and your rights.

Controls

How the platform is built

Security is designed into every layer — from authentication and tenant isolation to org/site-scoped access, field-level change history, e-signature sign-off and encrypted, backed-up storage.

🪪
Identity & authentication
  • JWT short-lived access tokens with refresh rotation and blacklist
  • Session capping and active-session governance
  • MFA (OTP) enforced by account policy
  • Password policy, history and account lockout
  • OAuth2 authorization server for governed integrations
🛡️
Authorization & access control
  • Server-side RBAC via groups and policies
  • Org- and site-scoped access — a user sees only their business units and sites
  • Module- and object-level permission checks on every protected endpoint
  • Deny-by-default: an unknown resource means no access
🏢
Multi-tenant isolation
  • Every business record scoped to an Account (tenant) boundary
  • Base-model scope keys (tenant / organization / site) never trusted from the client
  • Account-scoped querysets across all modules
  • Isolation verified by automated tests and code review
📝
Auditability & sign-off
  • Field-level change history on every record — a full old → new timeline
  • Multi-tier e-signature sign-off (Supervisor → PM → PMO) with IP / user-agent capture
  • Soft delete only — business data is never hard-deleted
  • Activity log, active sessions and API denial log
📶
Field & offline integrity
  • Idempotent sync — a retried field mutation never double-posts
  • Append-only stock, quantity and e-signature ledgers
  • Server-set timestamps and correlation IDs for traceability
  • Conflict-safe reconciliation between field capture and systems of record
💾
Data protection & operations
  • HTTPS everywhere; encrypted S3-compatible object storage
  • Daily backups with tested restore
  • Restricted database access and secret hygiene — never log secrets
  • Separate Development, QA/Staging, UAT and Production; controlled releases with rollback
Certifications & attestations

Where we are — honestly

We won't badge what we haven't earned. Here's the real status of every attestation, and what's on the roadmap as we scale.

Independent penetration test (VAPT)
Planned before GA

Independent testing scheduled ahead of general availability; the overview and results are shared with prospects on request.

SOC 2 Type II
On the roadmap

Planned as we scale. Until earned, judge us on the architecture and documentation — not a badge.

ISO/IEC 27001
On the roadmap

An ISMS aligned to ISO 27001 controls is the target as the customer base grows.

DPDP Act 2023 readiness
Aligned by design

Data minimization, purpose limitation, and data-subject rights (access / erase) built in from day one.

Vendor security questionnaire
Available now

We complete your questionnaire and walk your team through controls, data flows and sub-processors before you commit.

Privacy & data protection

Your data, your rights

Built to align with India's Digital Personal Data Protection Act (DPDP Act 2023) — with data ownership, minimization and transparent sub-processing.

🗃️
You own your data

Your project data is yours. We process it to run the service you've licensed — nothing else — and you can export it. On exit, we return or delete it per your agreement.

🎯
Purpose limitation & minimization

We collect only what the platform needs to operate, and use it only for that purpose — the core of DPDP-Act alignment.

🔎
Data-subject rights

Built to support access and erasure of personal data, with the audit trail to evidence it.

🧾
Transparent sub-processing

We keep a current list of sub-processors and the data each handles, shared with prospects and customers on request.

Availability & resilience

Uptime, backups and recovery

What keeps the service running — and what happens when something goes wrong.

🟢
Availability targets

We agree uptime and response targets that fit your operation in your contract. Founding customers get priority support with a direct line to the engineering team.

💾
Backup & recovery

Automated daily backups with tested restore, and defined recovery objectives. Soft-delete-only means accidental deletions are recoverable.

🧱
Environment separation

Development, QA/Staging, UAT and Production are separate. Releases are controlled, reviewed and reversible with rollback.

🚨
Incident response

A defined process to detect, contain, communicate and remediate — with customer notification per your agreement.

Sub-processors

Who we rely on

The third parties that help us run InCore, and where your data sits. The full current list is provided to prospects and customers on request.

Sub-processorPurposeData region
Amazon Web Services (AWS)Cloud hosting & encrypted object storageAsia-Pacific (Mumbai), India

We notify customers of material changes to sub-processors per your agreement. Request the full, current list any time.

Statutory & compliance, built in
GST e-invoicing (IRN)CLRA / BOCW registersInd AS 115 revenueStatutory Measurement BookTDS / PT / statutory payroll

Evaluating InCore for procurement?

We'll share our security overview, complete your vendor security questionnaire, provide the sub-processor list and walk your team through our controls and data flows.

Reporting a vulnerability? Email security@incore.in.