Built for India · Built for IT review

The facts your security team needs. Plainly.

Where the data lives. How it's encrypted. Who can access it. How fast we recover. What's certified, what's in progress, what's still on the roadmap. Without the marketing varnish.

DPDP Act 2023 AWS Mumbai AES-256 TLS 1.3 MFA all plans
Compliance status

Every cert. Every claim. Current state.

The one screenshot your security team will paste into the review. We tell you what's done, what's in progress, and what's a target — not a single one of these is wishful.

Compliant

DPDP Act 2023

Compliant with India's Digital Personal Data Protection Act. Consent flows, purpose limitation, data subject rights all built in.

Effective: Platform-wide
Audit: Internal · annual
DPA: View →
In progress

ISO 27001:2022

Information security management certification. Audit firm engaged, control framework documented, evidence collection underway.

Status: Stage 1 complete
Target: Q4 2026 certification
Auditor: Available on request
2027 target

SOC 2 Type II

US-focused audit standard. Not yet started — committing for 2027 after ISO 27001 is in place. Most India-only buyers don't need this; we'll have it for those who do.

Status: Planning · 2027
Type II readiness: 2027 H2
Customer ask? Email us
Active

Encryption at rest + in transit

AES-256 for data at rest in databases, backups, and object storage. TLS 1.3 for all data in transit, including internal service-to-service traffic.

At rest: AES-256 · AWS KMS
In transit: TLS 1.3 · HSTS preload
Key rotation: Annual
Mumbai + Hyd

Data residency

All customer data stored in AWS regions in India. Production in Mumbai (ap-south-1), DR replica in Hyderabad (ap-south-2). No cross-border data transfer.

Primary: ap-south-1 (Mumbai)
DR: ap-south-2 (Hyderabad)
Outside India: Never
Active

Backups + disaster recovery

Daily automated backups with 35-day retention. Cross-region replication to Hyderabad. RTO 4 hours · RPO 1 hour — tested quarterly with documented runbooks.

Retention: 35 days · point-in-time
RTO / RPO: 4h / 1h
DR drills: Quarterly
Active

Access controls

MFA on all plans. SSO (SAML 2.0, OIDC) on Enterprise. Role-based access control with audit logging on all admin actions. Session timeout and IP allowlisting on Enterprise.

MFA: All plans · TOTP + SMS
SSO: Enterprise · Okta, Entra
RBAC: Custom roles
Annual

Penetration testing

Annual third-party penetration test by CERT-In empanelled firm. Findings remediated and re-tested. Latest report available under NDA for Enterprise prospects.

Cadence: Annual
Scope: App + infra · OWASP Top 10
Report: NDA · Enterprise
Active

Incident response

24×5 monitoring with on-call rotation, automated alerting on anomalies. 72-hour breach notification per DPDP Act 2023. Public status page with subscribe.

On-call: 24×5 · alerting via PagerDuty
Breach notify: 72h · DPDP-compliant
Status: status.hrplanr.com
Need our SOC 2 plan? Pen-test summary? Sub-processor list? Email security@hrplanr.com — we respond within one business day.
01 · Data residency

Your data stays in India. Period.

Customer data — employee records, payslips, documents, Aadhaar references — is stored in AWS regions in India. The production database runs in Mumbai (ap-south-1). The disaster recovery replica is in Hyderabad (ap-south-2). Logs, backups, and search indexes follow the same residency rule.

No data is transferred outside India for processing or storage. The full sub-processor list — including which inference provider serves AI requests — is published in our DPA.

Customer data locations
All India · No cross-border
M
AWS Mumbai · Primary ap-south-1 · production DB + app servers + logs
Primary
H
AWS Hyderabad · DR replica ap-south-2 · cross-region read replica + backups
DR
AI
AI inference · in-region Mumbai endpoint for Enterprise · zero-retention contracts
Enterprise
×
Outside India Customer data: never. CDN edge: static assets only.
Excluded
02 · Encryption

Encrypted on the way in. Encrypted at rest. Decrypted only on demand.

Every byte of customer data is encrypted at rest with AES-256 using AWS KMS. Encryption keys are scoped per-tenant and rotated annually. Backups are encrypted with separate keys.

In transit, every connection uses TLS 1.3. The application enforces HSTS with preload; older TLS versions are refused. Service-to-service traffic inside our VPC is also TLS-encrypted — no plaintext on any network, internal or external.

At-rest cipher
AES-256-GCM
Key management
AWS KMS · per-tenant
Key rotation
Annual · automated
In-transit cipher
TLS 1.3
TLS 1.2 minimum
Enforced
TLS 1.0 / 1.1 / SSL
Rejected
HSTS
Preload list
Database encryption
RDS native + column-level for PII
Backup encryption
Separate KMS key
Aadhaar storage
Last-4 only · UI never shows full
03 · Access controls

Who can see what. Provable, auditable.

MFA is mandatory on all plans — TOTP via authenticator app, with SMS fallback. SSO (SAML 2.0 + OIDC) is included on Enterprise; supported IdPs include Okta, OneLogin, Google Workspace, and Microsoft Entra.

Inside the platform, role-based access control governs every action. Custom roles available on Enterprise. Every admin action — viewing a payslip not your own, exporting data, changing a salary — is recorded in an audit log accessible to admins.

1. Authentication Email + password OR SSO via Okta/Entra. Password rules: ≥12 chars · no reuse · breach-checked against HaveIBeenPwned.
2. MFA · mandatory all plans TOTP via Authy/Google Authenticator. SMS fallback. Recovery codes generated on enrollment.
3. Role enforcement · RBAC Default roles: Employee · Manager · HR · Admin · Finance. Custom roles on Enterprise. Permission check on every API call.
4. Audit log · every admin action Who · what · when · from where. Immutable. 365-day retention standard, longer on Enterprise. Exportable.
5. Session policies · Enterprise IP allowlisting · session timeout · device pinning · force logout on suspicious activity.
04 · Backups + disaster recovery

What happens when the worst happens.

Automated daily backups with point-in-time recovery, retained for 35 days. Backups are stored cross-region in Hyderabad, encrypted with separate keys. We run a full disaster recovery drill quarterly, with documented runbooks reviewed each cycle.

The numbers we commit to: RTO 4 hours · RPO 1 hour. The last drill (Mar 2026) recovered a full tenant in 2 hours 18 minutes. The drill report is available to Enterprise customers under NDA.

Backup frequency
Daily · automated
Point-in-time recovery
35 days
Backup location
Mumbai + Hyderabad
Backup encryption
AES-256 · separate KMS key
RTO (Recovery Time Objective)
4 hours
RPO (Recovery Point Objective)
1 hour
DR drill cadence
Quarterly · documented
Last drill (Mar 2026)
Full restore in 2h 18m
Data export on request
JSON · CSV · API
Termination data retention
7 yrs statutory · then deleted

Responsible disclosure

Found a vulnerability? We want to hear about it. Email security@hrplanr.com with details — we acknowledge within one business day and triage within three.

We commit not to take legal action against good-faith security research that follows our disclosure policy.

Read the full disclosure policy →
PGP key · security@hrplanr.com 7F8A 3D2B 9C4F 1E62 · E5A7 8B4C 6D31 2F9E · fingerprint published 14 Mar 2026 Bug bounty programme launching Q4 2026 · join the wait list →
For IT & security teams

Need a security questionnaire filled? We've got you.

Send us your CAIQ, SIG, or in-house security questionnaire. We complete most in 3-5 business days. Pen-test summary, sub-processor list, DPA, and architecture diagrams available under NDA.

Bring your hardest security questions.

We'd rather answer them now than during procurement.