Security & Compliance
Effective date: 18 September 2026
Our Commitment to Security
Security is not an add-on feature at Stockrect — it’s a foundational principle. Every element of the platform is designed with data protection, access control, and operational integrity at its core. This page describes the security measures and compliance frameworks that protect your business data.
Data Protection
Encryption at Rest
All customer data stored in Stockrect is encrypted using industry-standard AES-256 encryption. This includes primary databases, backups, and any temporary storage.
Encryption in Transit
All data transmitted between your browser, mobile devices, and Stockrect servers is encrypted using TLS 1.3, the current industry standard for transport layer security. Older TLS versions and unencrypted HTTP are not supported.
Access Controls
Every action on the Stockrect platform respects role-based access controls (RBAC). Users see only the data and functions authorized for their assigned role. Fine-grained module-level permissions ensure that sensitive data (e.g., purchase margins, financial reports) is visible only to authorized personnel.
Multi-Factor Authentication
Multi-factor authentication (MFA) is supported for all user accounts and strongly recommended for administrative accounts. Stockrect supports TOTP (time-based one-time passwords), SMS-based OTP, and email-based OTP.
Infrastructure Security
Cloud Infrastructure
Stockrect Cloud SaaS runs on secure, industry-leading cloud infrastructure with data centers located in India. Our cloud providers maintain SOC 2 Type II, ISO 27001, and other relevant certifications.
Data Residency
Customer data on Cloud SaaS resides in Indian data centers, in compliance with data localization requirements for Indian businesses. For dedicated hosted deployments, customers may select specific regions. For on-premise deployments, data resides entirely within the customer’s infrastructure.
Backup and Disaster Recovery
Where we host the platform, database backups run daily (incremental) and weekly (full), are stored in encrypted form within India or other compliant geographical regions, and are retained for a minimum of 7 to 30 days depending on the hosting configuration. If the production environment is corrupted by a system failure or technical malfunction, you may request restoration from the most recent available backup and we initiate it, on a reasonable-effort basis, within two (2) business days of the written request. Disaster recovery procedures are tested regularly. For on-premise and customer-hosted deployments, backup, retention and restoration are the customer’s responsibility unless separately contracted.
Physical Security
Our cloud infrastructure providers maintain enterprise-grade physical security at their data centers, including 24/7 monitoring, biometric access controls, and restricted physical access.
Application Security
Secure Development
Stockrect follows secure software development practices, including:
- Regular security code reviews
- Automated vulnerability scanning
- Dependency monitoring for known vulnerabilities
- Security testing as part of the release pipeline
Audit Trail
Every action on the platform is captured in an immutable audit trail with user attribution, timestamps, and complete change history. This audit trail supports both operational review and compliance requirements.
Session Management
User sessions are managed with configurable timeout policies. Inactive sessions are automatically terminated. Suspicious activity (e.g., login from unusual locations) triggers additional verification.
Compliance
Digital Personal Data Protection Act 2023
Stockrect is designed to support customer compliance with the Digital Personal Data Protection Act 2023. We provide the tools and controls necessary for data controllers to meet their obligations under the Act, including data subject rights fulfillment, retention management, and consent tracking.
Information Technology Act 2000
Stockrect operates in compliance with the Information Technology Act 2000, IT Rules 2011, and related regulations governing IT service providers in India.
GST Regulations
Stockrect‘s GST compliance features are designed to meet the requirements of the Goods and Services Tax Act and related notifications. Direct GSP integration ensures accurate IRN generation, e-way bill compliance, and GST return preparation.
Operational Security
Employee Training
All ElasticServe employees receive regular security training covering data protection, secure development practices, incident response, and social engineering awareness.
Access Management
Employee access to customer data is granted on a strict need-to-know basis, monitored, and periodically reviewed. Access is immediately revoked upon employee departure.
Incident Response
ElasticServe maintains an incident response process to detect, contain, investigate, and remediate security incidents. If personal data we process for a customer is subject to unauthorized access, disclosure, alteration, loss or compromise, we notify that customer without undue delay and in any case within seventy-two (72) hours of becoming aware of it, provide all reasonable details available, and cooperate in any required remedial, forensic, legal or regulatory action.
Deployment Options for Security-Sensitive Buyers
Cloud SaaS
The standard deployment option, hosted on our secure cloud infrastructure in India. Suitable for most businesses.
Dedicated Hosted
For businesses requiring higher isolation, we offer dedicated cloud instances where your deployment runs on isolated infrastructure. Available on Business and Enterprise tiers.
On-Premise Deployment
For businesses with strict data sovereignty requirements or air-gapped operational needs, Stockrect can be deployed entirely within your infrastructure. Available on Enterprise tier.
Reporting Security Issues
If you discover a security vulnerability or have security-related concerns, please report them to us at support@stockrect.com. We will acknowledge receipt within 48 hours and work with you to investigate and address the issue.
We appreciate responsible disclosure and will not pursue legal action against security researchers who follow responsible disclosure practices.
Business Continuity
ElasticServe maintains business continuity plans to ensure that customer operations are not disrupted by common failure scenarios. This includes:
- Geographic redundancy for cloud infrastructure
- Regular backup testing
- Documented recovery procedures
- Alternative work arrangements for our team in case of infrastructure disruption
Contact
For security-related questions or concerns:
Security and data protection: support@stockrect.com
General inquiries: hello@stockrect.com
Address: 1103, Titanium One, S.G. Highway, Near Pakwan Cross Road, Bodakdev, Ahmedabad 380054, Gujarat, India
Phone: (+91) 799-047-8054
If you believe you have found a security vulnerability or a personal data breach, contact support@stockrect.com. We notify affected customers of a confirmed personal data breach without undue delay and in any case within seventy-two (72) hours of becoming aware of it, provide all reasonable details available, and cooperate in any required remedial, forensic, legal or regulatory action.
Questions about this page?
Write to us and we'll walk you through it — or book a discovery call and we'll answer alongside everything else.