Trust · Infrastructure

Security Policy

Last reviewed: 18 July 2026 · Owner: Chetan Purnapatre, Founder & CEO

This page describes the security posture Dhurandhar Technologies Private Limited maintains for the DHURANDHAR Platform. It is maintained by the app owner and reflects controls currently enabled in production.

1. Guiding principles

  • Least privilege - every user, service and database role gets the minimum access required.
  • Defence in depth - multiple independent controls at network, application and data layers.
  • Encryption everywhere - in transit and at rest, no exceptions.
  • Secure by default - Row-Level Security is enabled on every table before it goes live.
  • Auditable - all administrative and financial actions leave an immutable audit trail.

2. Encryption

  • In transit: TLS 1.3 with HSTS enforced across www.dhurandharone.com and all API endpoints. HTTP requests are redirected to HTTPS.
  • At rest: AES-256 encryption on database volumes and object storage (AWS ap-south-1, Mumbai).
  • Passwords: hashed with bcrypt (cost factor 10+). Plaintext passwords are never stored or logged.
  • Secrets: API keys and service credentials are stored in a secrets manager, injected at runtime, and rotated regularly.

3. Payments

  • All payments are processed by Razorpay Software Private Limited, a PCI-DSS Level 1 certified payment gateway.
  • Card numbers, CVV and UPI PINs never touch our servers. Card entry happens on Razorpay's PCI-scoped iframe.
  • We retain only a payment reference ID, method used, amount, and where applicable the last 4 digits of the instrument for support reconciliation.
  • Refunds are processed only through the original payment method, using signed server-side calls to the Razorpay refund API.
  • Every booking financial field (price, GST, discount, refund) is protected by database triggers that reject any client-side modification.

4. Authentication & access control

  • Email/password, phone OTP, and Google Sign-In powered by an industry-standard identity provider.
  • Passwords are validated against the Have-I-Been-Pwned breach corpus at signup and change.
  • Session tokens are short-lived JWTs with automatic refresh rotation; tokens are stored in secure, httpOnly-equivalent storage where the platform permits.
  • Roles are stored in a separate user_roles table and evaluated by a SECURITY DEFINER function - preventing client-side privilege escalation.
  • Partner (pandit / karyakarta) accounts require KYC document verification and cannot self-verify their own trust status.

5. Database security

  • Row-Level Security (RLS) is enabled on every user-facing table. Users can read/write only rows they own.
  • Every public-schema table has explicit GRANT statements scoped to specific roles - no default anon access.
  • Financial fields on bookings, trust fields on partners, and loyalty fields on profiles are guarded by triggers that reject unauthorised updates.
  • Booking event history is append-only and cryptographically chained via audit triggers.
  • Backups are encrypted, taken daily, and retained for 30 days with point-in-time recovery.

6. Application security

  • All server functions validate input with strict schemas (Zod).
  • Webhook endpoints verify HMAC signatures with constant-time comparison before processing.
  • Rate limiting and abuse detection on authentication, OTP and messaging endpoints.
  • Content Security Policy, X-Frame-Options and X-Content-Type-Options headers on all HTML responses.
  • Automated dependency scanning and static analysis on every deployment.

7. Infrastructure

  • Primary hosting on globally distributed edge compute; primary data storage in AWS Mumbai (ap-south-1).
  • Isolated production, staging and development environments. Production data is never copied to lower environments.
  • Access to production infrastructure requires SSO + MFA and is limited to named engineers.
  • All infrastructure changes are code-reviewed and traceable via version control.

8. Monitoring & incident response

  • 24×7 uptime, latency and error-rate monitoring.
  • Security events (failed logins, privilege escalation attempts, unusual refund patterns) are logged and alerted.
  • Incident response SLA: acknowledgement within 4 hours, initial mitigation within 24 hours, root-cause report within 7 days.
  • Data breaches that meaningfully impact users will be notified to affected users and the Data Protection Board of India in accordance with DPDPA §8(6).

9. Responsible disclosure

If you believe you have found a security vulnerability, please email us at security@dhurandharone.com. We commit to:

  • Acknowledge your report within 48 hours.
  • Not pursue legal action against good-faith researchers who follow this policy.
  • Credit you publicly on our Trust page (unless you prefer anonymity) once the issue is fixed.

Please do not run automated scanners that generate significant traffic, access data belonging to other users, or attempt to disrupt the service.

10. Compliance posture

DHURANDHAR is designed to comply with:

  • The Digital Personal Data Protection Act, 2023 (India).
  • The Information Technology Act, 2000 and its Rules.
  • The Goods and Services Tax Act and associated invoicing requirements.
  • Razorpay merchant terms and PCI-DSS scope reduction guidance.

We do not claim independent certification (e.g., SOC 2, ISO 27001) at this stage. When those audits are completed, evidence will be published here.

11. Contact

SANATANA VERIFIEDTRUSTED BY 2M+ FAMILIESSECURE VEDIC COMMERCEAUTHENTIC PANDIT NETWORKTHE DIGITAL OPERATING SYSTEM FOR HINDU LIFESANATANA VERIFIEDTRUSTED BY 2M+ FAMILIESSECURE VEDIC COMMERCEAUTHENTIC PANDIT NETWORKTHE DIGITAL OPERATING SYSTEM FOR HINDU LIFE