KaryaGati Software
Security
How one customer's data is kept from ever reaching another.
Last updated 15 September 2026
The short version
- Separation between customers is enforced by the database, not by application code.
- A query with no tenant set fails with an error — it never returns everything.
- Card numbers never touch our servers. Passwords are stored as hashes we cannot read.
- Support access to your workspace is deliberate, recorded and time-boxed.
- We hold no ISO 27001 or SOC 2 certificate. Everything here is what we actually do.
The wording below is what counts legally. This summary is here so you know what it says.
Keeping customers apart
The strongest thing we have, so it goes first — and in plain terms rather than as an adjective.
- Every record belongs to exactly one organisation, and that ownership is part of the record’s identity — not a filter a query might forget.
- Every link between two records is checked by the databaseagainst both the record and the organisation. A row from one customer cannot be attached to another’s.
- A query issued with no organisation set fails closed. It raises an error rather than returning everything.
Encryption
| What | How |
|---|---|
| Every connection | TLS 1.2 or better. Plain HTTP is redirected, never served |
| Database and backups | Encrypted at rest |
| Passwords | bcrypt hashes only — unreadable to us and to anyone who copies the database |
| Your WhatsApp provider keys | AES-256-GCM, with the key held outside the database |
| Card details | Never reach our servers. Razorpay is PCI-DSS Level 1 |
Who can do what
- Permissions are data, not code. The server checks every request. A hidden button is a convenience, never the control.
- Sessions live in httpOnly cookies, so no script on the page can read them — a short access token plus a separate refresh token.
- Our staff back-office is a separate application with a separate session. A customer session can never become a staff one, or the reverse.
- Sign-in accepts one-time codes over WhatsApp, SMS and email as well as passwords.
What we can see
Our engineers do not browse customer data. Support access to a workspace is deliberate, recorded and time-boxed — every session is written to an audit trail with who opened it and why.
Keeping it running
- Encrypted daily backups, kept 30 days. Restores are tested — an untested backup is a rumour.
- Rate limiting on every public endpoint, so brute-forcing sign-in is useless.
- Parameterised queries throughout. No string-built SQL anywhere.
- Dependencies watched for known vulnerabilities; critical patches ship within 7 days.
Messaging safeguard
Outbound WhatsApp, SMS and email can be switched off per workspace, and it is forced off for every demo. The block sits at the transport, not in the calling code, so a sandbox cannot message a real person even by accident.
Reporting a vulnerability
Found something? Tell security@karyagati.in before telling anyone else, with steps to reproduce it.
- We acknowledge within 2 working days and keep you posted.
- No legal action against anyone reporting in good faith who stays in their own test data and gives us time before disclosing.
- Credit once the fix ships, with your permission.
Please do not scan production, touch data that is not yours, or degrade the service for other customers.
What we do not claim
We are a small team, so we would rather be straight with you: we hold no ISO 27001 or SOC 2 certificate today. Everything on this page is what we actually do, not what an auditor has signed. Send us your security questionnaire at security@karyagati.in and we will answer it honestly.
If something goes wrong
We tell affected customers without undue delay — what happened, what data was involved, what we have done, what you should do. We would rather tell you early and revise the detail than wait until the picture is tidy.