Security
Your data security is our top priority. Learn how we protect your information with industry-leading security practices.
Encryption
- • HTTPS/TLS for all data in transit
- • AES-256 encryption for data at rest
- • End-to-end encryption for sensitive operations
- • SHA-256 hashing for passwords
Authentication
- • Multi-factor authentication (OTP via email)
- • Secure password requirements
- • JWT-based session management
- • Automatic session timeout (30 min)
Compliance
- • GDPR compliance for EU users
- • India DPDP compliance
- • PCI DSS compliance for payments
- • Regular security audits
Incident Response
- • 24/7 security monitoring
- • Rapid incident response team
- • Transparent vulnerability disclosure
- • User notification within 72 hours
Data Protection
We implement multiple layers of security to protect your data:
In Transit
- All connections use HTTPS with TLS 1.3
- Certificate pinning for API communications
- No data transmitted in plain text
At Rest
- Database encryption using AES-256
- Encrypted backups with separate keys
- Secrets stored in encrypted vaults (not in code)
- Passwords hashed with bcrypt + salt
Authentication & Access Control
We protect accounts with multiple security measures:
- Email OTP: One-time passwords sent via Microsoft Graph API for signup verification
- Password Policy: Minimum 8 characters, complexity requirements
- Session Management: JWT tokens with automatic expiration
- Brute Force Protection: Rate limiting on login attempts
- Admin Access: Separate admin authentication system
- API Keys: Secure key generation and rotation
Infrastructure Security
Our platform is built on secure infrastructure:
- Database: PostgreSQL on managed cloud hosting with automatic backups
- Application Servers: Containerized deployment with auto-scaling
- CDN: Global content delivery with DDoS protection
- Firewalls: Web application firewalls (WAF) blocking malicious requests
- Network Isolation: VPC/VPN for all infrastructure
- Monitoring: 24/7 logs and alerts for suspicious activity
API Security
All APIs implement industry-standard security:
- Authentication: JWT bearer tokens or OAuth 2.0
- Rate Limiting: Prevent abuse and DDoS attacks
- Input Validation: Sanitize all user inputs
- CORS: Strict cross-origin policies
- Versioning: API versions for deprecation management
- Logging: All requests logged for audit trails
Payment Security
We use Razorpay, a PCI DSS Level 1 certified payment processor:
- No Card Storage: We never see or store credit card details
- PCI Compliance: Razorpay handles all PCI requirements
- Tokenization: Cards are tokenized for recurring charges
- Fraud Detection: Advanced fraud prevention by Razorpay
- Webhooks: Secure, signed webhooks for payment notifications
License Key Security
License keys for products like School ERP:
- Generated using cryptographic random number generators
- Unique per user/subscription
- Non-transferable and non-shareable
- Automatically revoked on subscription cancellation
- Validated on product activation
Privacy & Data Governance
Your data rights are protected:
- Data Minimization: We collect only necessary data
- User Control: Export, update, or delete your data
- No Selling: We never sell user data to third parties
- Limited Sharing: Only with essential service providers (email, payments)
- Retention Policy: Data deleted after account closure + 90 days
Compliance & Certifications
We comply with major data protection regulations and hold industry certifications:
- ISO 9001:2015: Quality Management System - Certified
- ISO/IEC 27001:2022: Information Security Management System - Certified
- GDPR (EU): General Data Protection Regulation - Compliant
- DPDP (India): Digital Personal Data Protection Act, 2023 - Compliant
- PCI DSS: Payment Card Industry Data Security Standard - Level 1
Vulnerability Disclosure
Found a security issue? We take it seriously. Please report vulnerabilities responsibly:
- Email: security@sanglob.com
- Do not publicly disclose vulnerabilities before we've had 90 days to fix them
- Include: vulnerability description, steps to reproduce, potential impact
- We'll acknowledge receipt within 24 hours and provide status updates
Security Best Practices for Users
You can strengthen your account security:
- ✅ Use a unique, strong password (12+ characters, mixed case, numbers, symbols)
- ✅ Enable 2FA/OTP whenever available
- ✅ Verify OTP emails are from noreply@sanglob.com
- ✅ Never share your login credentials or license keys
- ✅ Log out of public computers after use
- ✅ Keep your browser and OS updated
- ✅ Use a password manager (Bitwarden, 1Password, LastPass)
- ❌ Don't click links in unsolicited emails (phishing)
- ❌ Don't use the same password across sites
- ❌ Don't save passwords in browsers on shared computers
Incident Response
If a security incident occurs:
- We detect and contain the threat within hours
- Affected users are notified within 72 hours
- Full details and remediation steps are provided
- Post-incident analysis identifies root cause and improvements
Security Roadmap
We're continuously improving security:
- ⬜ Two-factor authentication (2FA) via authenticator apps
- ⬜ Advanced threat detection and machine learning
- ⬜ Annual third-party security audits
- ⬜ Bug bounty program
- ⬜ ISO 27001 certification
- ⬜ Hardware security key support
Questions?
For security concerns or questions:
- Email: security@sanglob.com
- Privacy: privacy@sanglob.com
- Support: /support