Security Posture

Security at Kryptasys.

DPDP Shield was built to the standards it enforces — every checkpoint, every evidence format, and every security control maps to a real DPDPA obligation that Kryptasys itself follows. We hold ourselves to the same standard we set for our customers.

Infrastructure

DPDP Shield runs on Supabase (Mumbai region, ISO 27001 and SOC 2 Type II certified data centre). Frontend deployed on Vercel with global edge network. All data stored strictly within India.

Data Protection

All data is encrypted in transit via TLS 1.3 and at rest via AES-256. No customer data is used for training any AI models or shared with third parties under any circumstances.

Access Controls

Row-level security (RLS) is rigidly enforced at the database level ensuring strict multi-tenant isolation. All sessions are authenticated exclusively via cryptographically signed JWTs.

Responsible Disclosure

We take security reports very seriously. If you've found a security issue or vulnerability in Kryptasys products, please report it to our team. We will respond within 48 hours.

Report an Issue →