Security
Last updated 2026-06-04
Template for demonstration — review and adapt with qualified counsel before relying on it.
Security practices at Harvbery Technologies Pvt. Ltd.:
- Transport security: HTTPS/TLS everywhere, HSTS, strict security headers.
- Authentication: bcrypt password hashing, TOTP two-factor auth, signed httpOnly session cookies, one-shot session revocation, login throttling + account lockout, and enterprise SSO (OIDC).
- Authorisation: role-based access control and matter-level ethical-wall screening; strict tenant isolation.
- Auditability: append-only, hash-chained audit log with a tamper-evidence verifier.
- Data protection: PII redaction in logs, configurable retention with automated purge, full data export, and right-to-erasure workflows aligned to the DPDP Act.
- Operations: structured logging, error tracking, health/readiness probes, and least-privilege infrastructure.
Responsible disclosure: email security@harvbery.example. See /.well-known/security.txt.