Draft — pending licensed-lawyer review. This is a strengthened working draft to reduce risk, not final legal advice, and not a guarantee. Complete the highlighted fill-ins and have a licensed Indian lawyer / privacy counsel / CA finalise it before real-customer use.
Security Statement
How MAUZOP protects data. No certification is claimed.
- Access control: least privilege, role-based access, unique accounts, admin controls and monthly reviews.
- Privacy by design: we never ask for passwords, OTP, full bank login, or full Aadhaar; sensitive fields are masked before logging/storage.
- Encryption: HTTPS in transit; encrypted storage where practical; secrets in a manager/environment, never in code.
- Secure uploads: file-type/size checks and quarantine of risky files.
- Logging & audit: auth, admin, report, upload, consent and deletion events are logged.
- Backups & recovery: scheduled backups with restore testing before real-customer data.
- Incident response: a defined workflow for suspected leaks or wrong reports.
Honest note
No system can claim zero security risk. We are not ISO/IEC 27001 certified; we follow ISO-style audit-readiness direction. A security audit is required before public launch with real customer data.
Report a security concern via the Contact/Grievance page.