🛡️ Enterprise-grade security

Security built in
from day one

Your business data is the most sensitive thing we touch. We treat security as a first principle, not an afterthought.

99.9%
Uptime SLA
AWS Mumbai multi-AZ
AES-256
Encryption Standard
At rest and in transit
6 hrs
Backup Frequency
30-day retention
<30 min
Incident Response
Critical severity SLA

Security pillars

🔒

Encryption

All data encrypted at rest (AES-256) and in transit (TLS 1.3). Database keys rotated quarterly. Backups independently encrypted with separate key hierarchies.

  • AES-256 at rest
  • TLS 1.3 in transit
  • Quarterly key rotation
  • Encrypted backups
🏗️

Infrastructure

AWS Mumbai (ap-south-1). Multi-availability zone deployment. Automatic failover with under 30-second RTO. Auto-scaling compute and CDN edge caching.

  • AWS Mumbai multi-AZ
  • Auto-failover (<30s RTO)
  • Auto-scaling compute
  • CDN edge caching
💾

Data Backups

Automated backups every 6 hours with 30-day retention. Point-in-time recovery available on Business plans. Cross-region backup replication to ap-southeast-1.

  • 6-hour automated backups
  • 30-day retention
  • Point-in-time restore
  • Cross-region replication
🔑

Access Controls

Granular role-based access control. MFA enforcement for all users. IP allowlisting, session timeouts, and SSO via SAML 2.0.

  • Role-based permissions
  • MFA enforcement
  • IP allowlisting
  • SSO via SAML 2.0
🏢

Tenant Isolation

Every tenant's data isolated at the database level. No shared tables. No cross-tenant data leakage. Verified by independent security audits.

  • Database-level isolation
  • No shared data tables
  • Independent audit verified
  • Tenant-scoped API tokens
👁️

Audit Logging

Every action in Stockivio is logged — who did what, when, from where. Audit logs are tamper-proof and retained for 12 months.

  • Immutable audit trails
  • User action logging
  • IP and device tracking
  • 12-month retention
📡

Monitoring

24/7 infrastructure and application monitoring. Automated anomaly detection flags unusual access, login attempts, and API abuse.

  • 24/7 monitoring
  • Anomaly detection
  • Login attempt alerts
  • API rate limiting
🚨

Incident Response

Dedicated security response team. Under-30-minute response to critical incidents. Customers notified within 72 hours of any breach per IT Act requirements.

  • <30 min critical response
  • Defined escalation matrix
  • 72-hour breach notification
  • Post-incident reports

Compliance & certifications

ISO 27001
In Progress
Target: Q4 2025
SOC 2 Type II
In Progress
Target: Q3 2025
GDPR Compliant
Active
IT Act 2000
Active
🔐

Security questions or concerns?

Report security vulnerabilities to security@stockivio.com. We respond within 24 hours and maintain a responsible disclosure policy with bounty rewards.

Contact Security Team →