Trust
Your data, locked down.
Books, BOQs, site photos, vendor bank details and tax data deserve serious infrastructure. Here's how we protect what you put into Rebaar.
IN
India data residency
Production database and object storage hosted in India.
ENC
Encrypted at rest
Third-party tokens and document files are encrypted before storage using industry-standard authenticated encryption.
TLS
TLS in transit
All traffic between you and Rebaar uses modern TLS.
2FA
2FA and SSO
TOTP authenticator app for personal accounts. Google, Microsoft, OIDC, and SAML available for enterprise SSO.
WS
Per-workspace credentials
Payment, messaging, and GST integration credentials are scoped to your workspace and never shared across tenants.
TI
Multi-tenant isolation
Tenant data is strictly partitioned. No customer can read another customer's data.
AUD
Audit-grade activity log
Every mutation captured with actor, timestamp, and before/after detail. Exportable.
DPDP
DPDP-aligned
Right-to-access (per-user export) and right-to-erasure (workspace and member level) per DPDP Act 2023.
Operational practices
· Daily encrypted backups, 30-day retention, point-in-time recovery
· Code review on every change · automated tests on every deploy
· Third-party penetration test planned post-launch (not yet conducted)
· Vulnerability disclosure: [email protected]
· No production credentials on developer machines
Compliance & regulation
· DPDP Act 2023 aligned (right to access + erasure implemented)
· GST IRP / e-Way Bill — registered under your GSTIN via your NIC or GSP credentials. Rebaar is not itself a GSP.
· Razorpay PCI-DSS Level 1 handles cardholder data (Rebaar never stores card numbers)
· Right to export, right to delete — anytime, no questions asked
· DPA template available for enterprise customers — email [email protected]
Doing security diligence?
We'll share our architecture overview, threat model, and DPA on request — and meet a 30-minute call with your security team.
Reporting a vulnerability
Found a security issue in Rebaar? Email [email protected] with a description, steps to reproduce, and impact. We respond within 1 business day.
See our machine-readable policy at /.well-known/security.txt.
Please DO:
- Give us reasonable time to fix before public disclosure (90 days standard)
- Provide enough detail that we can reproduce
- Use a test workspace, not a real customer's data
Please DO NOT:
- Run automated scanners against production (it trips the WAF and rate limits)
- Access, modify, or delete data that isn't yours
- Run denial-of-service tests
- Social-engineer Rebaar staff or customers
We're a bootstrapped company without a paid bug bounty — but we credit reporters publicly (with consent) and offer a free year of Growth plan for valid findings.
Acknowledgments
We thank the following researchers who have responsibly disclosed security issues to us. (Empty for now — Rebaar launched in 2026; the list grows from here. To be listed, include your preferred name and link when you report.)
Data Protection Officer
For DPDP Act 2023 requests, data-protection complaints, or to exercise your data rights (access, correction, erasure, grievance redressal), contact:
Data Protection Officer: Tej (Founder)
Email: [email protected]
Postal: Rebaar, Bengaluru, India
Response window: 30 days (DPDP Act requirement)
We may appoint a separate DPO once Rebaar is classified as a Significant Data Fiduciary (SDF) under DPDP rules. Until then, the founder serves as the designated contact.