Trust

Your data, locked down.

Books, BOQs, site photos, vendor bank details and tax data deserve serious infrastructure. Here's how we protect what you put into Rebaar.
IN
India data residency
Production database and object storage hosted in India.
ENC
Encrypted at rest
Third-party tokens (payment, GST, WhatsApp) are encrypted with AES-256-GCM at the application layer before storage. Database and file storage are encrypted at rest by the hosting provider.
TLS
TLS in transit
All traffic between you and Rebaar uses modern TLS.
2FA
2FA and SSO
TOTP authenticator app for personal accounts. Google, Microsoft, OIDC, and SAML available for enterprise SSO.
WS
Per-workspace credentials
Payment, messaging, and GST integration credentials are scoped to your workspace and never shared across tenants.
TI
Multi-tenant isolation
Tenant data is strictly partitioned. No customer can read another customer's data.
AUD
Audit-grade activity log
Every mutation captured with actor, timestamp, and before/after detail. Exportable.
DPDP
DPDP-aligned
Right-to-access (per-user export) and right-to-erasure (workspace and member level) per DPDP Act 2023.

Operational practices

· Daily encrypted off-site backups kept 12 months · 7-day point-in-time recovery
· Code review on every change · automated tests on every deploy
· Third-party penetration test planned post-launch (not yet conducted)
· Vulnerability disclosure: [email protected]
· No production credentials on developer machines

Compliance & regulation

· DPDP Act 2023 aligned (right to access + erasure implemented)
· GST IRP / e-Way Bill — registered under your GSTIN via your NIC or GSP credentials. Rebaar is not itself a GSP.
· Razorpay PCI-DSS Level 1 handles cardholder data (Rebaar never stores card numbers)
· Right to export, right to delete — anytime, no questions asked
· DPA template available for enterprise customers — email [email protected]
Doing security diligence?
We'll share our architecture overview, threat model, and DPA on request — and meet a 30-minute call with your security team.
Email security@

Reporting a vulnerability

Found a security issue in Rebaar? Email [email protected] with a description, steps to reproduce, and impact. We respond within 1 business day.

See our machine-readable policy at /.well-known/security.txt.

Please DO:

  • Give us reasonable time to fix before public disclosure (90 days standard)
  • Provide enough detail that we can reproduce
  • Use a test workspace, not a real customer's data

Please DO NOT:

  • Run automated scanners against production (it trips the WAF and rate limits)
  • Access, modify, or delete data that isn't yours
  • Run denial-of-service tests
  • Social-engineer Rebaar staff or customers

We're a bootstrapped company without a paid bug bounty — but we credit reporters publicly (with consent) and offer a free year of Growth plan for valid findings.

Acknowledgments

We thank the following researchers who have responsibly disclosed security issues to us. (Empty for now — Rebaar launched in 2026; the list grows from here. To be listed, include your preferred name and link when you report.)

Log retention

Every workspace has an activity log — a complete record of who did what: sign-ins and failed sign-ins, permission and role changes, approvals, money movements, exports, and any support access by our staff. We retain it for a minimum of one year, and by default indefinitely.

A workspace Owner can set a shorter stated retention period in Settings → Data & retention, but the one-year floor always applies: breaches are typically discovered months after they occur, and a shorter window would destroy the evidence before anyone went looking. This meets India's DPDP Rules (2025) expectation for access logs and exceeds the 180 days required by the CERT-In directions of 2022. Log timestamps are recorded in UTC on clock-synchronised (NTP) infrastructure hosted in India.

Business records — invoices, tax documents and journal entries — are kept for 8 years under the Companies Act and are never removed by retention settings. Deleting a workspace is a separate, explicit action; see our privacy policy for how erasure requests are handled.

Data Protection Officer

For DPDP Act 2023 requests, data-protection complaints, or to exercise your data rights (access, correction, erasure, grievance redressal), contact:

Data Protection Officer: Tej (Founder)
Postal: Rebaar, Bengaluru, India
Response window: 30 days (DPDP Act requirement)

We may appoint a separate DPO once Rebaar is classified as a Significant Data Fiduciary (SDF) under DPDP rules. Until then, the founder serves as the designated contact.