CorporateWalla logoCorporateWalla
Back to home

Security Practices

Effective: 15 June 2026 · Operated by DSG CORPORATE FINANCIAL ADVISORS LLP

At CorporateWalla®, we take the security of your data and documents seriously. Here's how we protect you.

1. Encryption

  • In transit: All data exchanged with our website uses TLS 1.2+ (HTTPS). We get an A+ rating on SSL Labs
  • At rest: All KYC documents and PII are stored in AES-256 encrypted volumes (AWS EBS, Mumbai region)
  • Backups: Daily encrypted backups, retained for 30 days, stored in a separate AWS region

2. Access control

  • Role-based access control (RBAC) — staff can only access the data they need for their role
  • Multi-factor authentication (MFA) mandatory for all employee logins
  • Least-privilege principle — no standing admin access
  • Quarterly access reviews

3. Audit and monitoring

  • All access to customer data is logged in an immutable audit trail
  • Real-time alerts on suspicious activity (anomalous login, bulk download, etc.)
  • Annual third-party penetration testing by an independent firm (cert available on request)
  • Vulnerability scanning on every code deploy

4. KYC document handling

  • Encrypted storage in access-controlled S3 buckets
  • Auto-deletion 90 days after case closure (unless retention is required by law)
  • Files never leave our infrastructure except when filing on your behalf with government portals (over secure HTTPS)
  • Files never shared with third parties (except as required for the service, e.g., bank KYC for account opening)

5. Payment security

  • All payments processed by Razorpay / Stripe (PCI-DSS Level 1 certified)
  • We do not store your card / UPI / bank credentials
  • Tokenization for repeat payments

6. Infrastructure

  • Hosting on AWS Mumbai region (ap-south-1)
  • Web application firewall (WAF) and DDoS protection via Cloudflare
  • Daily database snapshots, point-in-time recovery up to 7 days
  • 99.9% uptime SLA on the website

7. Employee security

  • Background verification (BGV) for all new hires
  • Non-disclosure agreements (NDAs) and confidentiality clauses in every employment contract
  • Annual security awareness training
  • Phishing simulation exercises quarterly

8. Compliance

  • Digital Personal Data Protection Act, 2023
  • Information Technology Act, 2000 + IT Rules 2011 (Reasonable Security Practices)
  • ISO 27001 certification — in progress, expected Q4 2026
  • GDPR (for our NRI / EU clients)

9. Vulnerability disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a vulnerability, please email info@corporatewalla.com with details and a proof-of-concept. We commit to:

  • Acknowledge within 48 hours
  • Provide a status update within 5 business days
  • Fix critical vulnerabilities within 7 days of confirmation
  • Credit you in our security hall of fame (with your consent)

Please do not exploit the vulnerability beyond what is necessary to demonstrate it. Do not access, modify, or retain user data. Do not publicly disclose until we have fixed the issue.

10. Breach notification

In the event of a data breach affecting your personal data, we will notify you and the Data Protection Board of India within 72 hours, as required by the DPDP Act 2023.

11. Report an issue

To report a security issue or ask a question, contact our security team at info@corporatewalla.com. PGP key available on request.

Questions about this policy? Email info@corporatewalla.com or call +91 72783 76654.