Security & compliance
Built secure, hosted in India
Security and India’s data-protection rules are designed into the platform, not bolted on. Here’s exactly what protects your data.
SOC 2 Type 1 audit is targeted for Q2 2027, with Type 2 to follow. We are not yet SOC 2 certified.
Data protection
AES-256 PII vault
Customer phone, email and name are encrypted at the database layer; only authorised services can decrypt them.
Hosted in India
All data lives in the AWS Mumbai (ap-south-1) region, with no cross-border transfer.
Per-tenant isolation
Row-level security scopes every record to a single merchant and location. Tenants never see each other’s data.
Access & change control
Least-privilege roles
Role-based access across dashboard, POS and kiosk. Admin actions are enforced server-side, not just hidden in the UI.
Signed device identity
Each kiosk and POS runs on a signed, location-scoped token, so a device can only touch its own outlet’s data.
Reviewed changes
Every code and schema change ships through pull-request review and CI. No direct writes to production.
Payments & privacy rights
No card data stored
Card numbers, CVV and UPI PINs never touch our systems. PhonePe handles all payment instruments.
Consent on record
Customer consent is captured before contact data is stored, in line with DPDPA-2023.
Export & erasure
A single request exports or permanently deletes a customer’s personal data (DPDPA data-subject rights).
Retention limits
Transient data (OTPs, rate-limit records, logs) is auto-purged on schedule. Nothing is kept longer than needed.
Subprocessors
Who processes data on our behalf
Third parties we rely on, and where they operate.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, auth & backend | Mumbai (ap-south-1), India |
| Cloudflare | CDN, DNS & web hosting | Global edge |
| Cloudflare R2 | App update installers | Global |
| PhonePe | Payment processing | India |
| MSG91 | OTP & transactional SMS | India |
| Google & Facebook | Optional social sign-in prefill | Global |
| Reelo | Optional per-merchant loyalty | India |
Your data rights & security reviews
Customers can request access, export or deletion of their personal data any time. See our privacy policy. Evaluating EnsmblOS for procurement? Request our security questionnaire and we’ll get back to you.