Skip to content
Legal & Compliance

Security & Compliance

Effective date: 18 September 2026

1.

Our Commitment to Security

Security is not an add-on feature at Stockrect — it’s a foundational principle. Every element of the platform is designed with data protection, access control, and operational integrity at its core. This page describes the security measures and compliance frameworks that protect your business data.

2.

Data Protection

Encryption at Rest

All customer data stored in Stockrect is encrypted using industry-standard AES-256 encryption. This includes primary databases, backups, and any temporary storage.

Encryption in Transit

All data transmitted between your browser, mobile devices, and Stockrect servers is encrypted using TLS 1.3, the current industry standard for transport layer security. Older TLS versions and unencrypted HTTP are not supported.

Access Controls

Every action on the Stockrect platform respects role-based access controls (RBAC). Users see only the data and functions authorized for their assigned role. Fine-grained module-level permissions ensure that sensitive data (e.g., purchase margins, financial reports) is visible only to authorized personnel.

Multi-Factor Authentication

Multi-factor authentication (MFA) is supported for all user accounts and strongly recommended for administrative accounts. Stockrect supports TOTP (time-based one-time passwords), SMS-based OTP, and email-based OTP.

3.

Infrastructure Security

Cloud Infrastructure

Stockrect Cloud SaaS runs on secure, industry-leading cloud infrastructure with data centers located in India. Our cloud providers maintain SOC 2 Type II, ISO 27001, and other relevant certifications.

Data Residency

Customer data on Cloud SaaS resides in Indian data centers, in compliance with data localization requirements for Indian businesses. For dedicated hosted deployments, customers may select specific regions. For on-premise deployments, data resides entirely within the customer’s infrastructure.

Backup and Disaster Recovery

Where we host the platform, database backups run daily (incremental) and weekly (full), are stored in encrypted form within India or other compliant geographical regions, and are retained for a minimum of 7 to 30 days depending on the hosting configuration. If the production environment is corrupted by a system failure or technical malfunction, you may request restoration from the most recent available backup and we initiate it, on a reasonable-effort basis, within two (2) business days of the written request. Disaster recovery procedures are tested regularly. For on-premise and customer-hosted deployments, backup, retention and restoration are the customer’s responsibility unless separately contracted.

Physical Security

Our cloud infrastructure providers maintain enterprise-grade physical security at their data centers, including 24/7 monitoring, biometric access controls, and restricted physical access.

4.

Application Security

Secure Development

Stockrect follows secure software development practices, including:

  • Regular security code reviews
  • Automated vulnerability scanning
  • Dependency monitoring for known vulnerabilities
  • Security testing as part of the release pipeline

Audit Trail

Every action on the platform is captured in an immutable audit trail with user attribution, timestamps, and complete change history. This audit trail supports both operational review and compliance requirements.

Session Management

User sessions are managed with configurable timeout policies. Inactive sessions are automatically terminated. Suspicious activity (e.g., login from unusual locations) triggers additional verification.

5.

Compliance

Digital Personal Data Protection Act 2023

Stockrect is designed to support customer compliance with the Digital Personal Data Protection Act 2023. We provide the tools and controls necessary for data controllers to meet their obligations under the Act, including data subject rights fulfillment, retention management, and consent tracking.

Information Technology Act 2000

Stockrect operates in compliance with the Information Technology Act 2000, IT Rules 2011, and related regulations governing IT service providers in India.

GST Regulations

Stockrect‘s GST compliance features are designed to meet the requirements of the Goods and Services Tax Act and related notifications. Direct GSP integration ensures accurate IRN generation, e-way bill compliance, and GST return preparation.

6.

Operational Security

Employee Training

All ElasticServe employees receive regular security training covering data protection, secure development practices, incident response, and social engineering awareness.

Access Management

Employee access to customer data is granted on a strict need-to-know basis, monitored, and periodically reviewed. Access is immediately revoked upon employee departure.

Incident Response

ElasticServe maintains an incident response process to detect, contain, investigate, and remediate security incidents. If personal data we process for a customer is subject to unauthorized access, disclosure, alteration, loss or compromise, we notify that customer without undue delay and in any case within seventy-two (72) hours of becoming aware of it, provide all reasonable details available, and cooperate in any required remedial, forensic, legal or regulatory action.

7.

Deployment Options for Security-Sensitive Buyers

Cloud SaaS

The standard deployment option, hosted on our secure cloud infrastructure in India. Suitable for most businesses.

Dedicated Hosted

For businesses requiring higher isolation, we offer dedicated cloud instances where your deployment runs on isolated infrastructure. Available on Business and Enterprise tiers.

On-Premise Deployment

For businesses with strict data sovereignty requirements or air-gapped operational needs, Stockrect can be deployed entirely within your infrastructure. Available on Enterprise tier.

8.

Reporting Security Issues

If you discover a security vulnerability or have security-related concerns, please report them to us at support@stockrect.com. We will acknowledge receipt within 48 hours and work with you to investigate and address the issue.

We appreciate responsible disclosure and will not pursue legal action against security researchers who follow responsible disclosure practices.

9.

Business Continuity

ElasticServe maintains business continuity plans to ensure that customer operations are not disrupted by common failure scenarios. This includes:

  • Geographic redundancy for cloud infrastructure
  • Regular backup testing
  • Documented recovery procedures
  • Alternative work arrangements for our team in case of infrastructure disruption
10.

Contact

For security-related questions or concerns:

Security and data protection: support@stockrect.com
General inquiries: hello@stockrect.com
Address: 1103, Titanium One, S.G. Highway, Near Pakwan Cross Road, Bodakdev, Ahmedabad 380054, Gujarat, India
Phone: (+91) 799-047-8054

If you believe you have found a security vulnerability or a personal data breach, contact support@stockrect.com. We notify affected customers of a confirmed personal data breach without undue delay and in any case within seventy-two (72) hours of becoming aware of it, provide all reasonable details available, and cooperate in any required remedial, forensic, legal or regulatory action.

Questions about this page?

Write to us and we'll walk you through it — or book a discovery call and we'll answer alongside everything else.