Trust & Security

How Bizmitra protects your business data — the security we build in, the privacy laws we honour, and how to report a vulnerability responsibly.

Encryption & access

Data is encrypted in transit (TLS). Access is least-privilege and role-based; credentials are stored hashed and shown once.

Auditable by design

Every legal acceptance, consent change, and data-request is recorded in an append-only audit trail with actor, time, and IP.

Tenant isolation

Customer data is logically isolated per tenant. Cross-tenant access is denied by construction, not by convention.

Your privacy rights

Under DPDP, GDPR, and CCPA you can access, export, correct, or delete your personal data, and withdraw consent at any time. We operate a deadline-bound request pipeline for every user type.

Exercise a data right

Signed-in users can request an export or deletion from their portal's Privacy settings. Everyone else can reach us at the contact below.

Open privacy settings →

Responsible vulnerability disclosure

We welcome reports from security researchers and will work with you in good faith. Please give us reasonable time to remediate before any public disclosure.

Please do

  • Report suspected vulnerabilities privately to the contact below.
  • Give enough detail to reproduce the issue.
  • Allow reasonable time to fix before disclosure.
  • Act in good faith and avoid privacy violations.

Please don't

  • Access, modify, or delete data that isn't yours.
  • Run denial-of-service or spam tests.
  • Use social engineering or physical attacks.
  • Publicly disclose before we've remediated.
Security contact security@bizmitra.io security.txt →

Sub-processors

We're transparent about the third parties that help us run the service. See the current list of sub-processors, what they process, and where.

Who processes your data

Hosting, email, payments, analytics (consented), and AI inference providers.

View sub-processors →