Security Policy
1. Our Commitment to Security
Annaswaad integrates data security into the core architecture of our digital storefront. We implement privacy-by-design principles and robust operational controls designed to protect your personal data from unauthorized access, accidental loss, alteration, and unlawful disclosure.
2. Technical & Infrastructure Safeguards
We deploy verified, enterprise-grade technical safeguards across all user touchpoints:
A. HTTPS TLS Encryption in Transit
All communications between your browser or mobile device and Annaswaad's servers are encrypted using Transport Layer Security (TLS 1.2+ / HTTPS). This prevents interception or tampering of data during transmission across public networks.
B. OTP Passwordless Authentication
To eliminate the risks associated with weak or reused passwords, Annaswaad utilizes a passwordless One-Time Password (OTP) authentication model. Every OTP is dynamically generated, time-limited, and protected by automated rate-limiting and device fingerprinting to prevent brute-force attacks.
C. Razorpay PCI-DSS Tokenized Payments
Annaswaad never stores full credit card, debit card, UPI, or banking credentials on our servers. All payment transactions are processed through Razorpay, a PCI-DSS Level 1 compliant payment gateway that utilizes advanced tokenization and end-to-end encryption.
D. Role-Based Access Controls (RBAC)
Access to backend databases and administrative dashboards is strictly restricted using multi-factor authentication and Role-Based Access Controls (RBAC). Only authorized staff members with documented operational necessity are granted access to customer support records.
E. Automated Data Erasure Workflows
Transient authentication logs and expired OTP records are automatically purged from database tables after 30 days. When an account deletion is initiated, automated background workers securely remove device push tokens and non-essential personal identifiers.
3. Vulnerability Management & Incident Response
Our cloud infrastructure is monitored using automated operational and security controls for unauthorized intrusion attempts or service anomalies. We also perform regular software updates, security patching, and system maintenance where reasonably practicable. In the event of a suspected security incident, our engineering team adheres to documented incident response protocols to contain risks and notify relevant regulatory authorities and users as required under law.
4. Responsible Disclosure
If you are a security researcher or customer who has discovered a potential vulnerability in our digital storefront or APIs, please report it immediately to our security team at support@annaswaad.com. We appreciate your assistance in keeping Annaswaad secure.
Version: 2026-07-01 | Effective Date: 1 July 2026
Last Updated: 1 July 2026
