Security & Infrastructure
Nausha Technologies applies reasonable technical and organizational safeguards designed to protect the confidentiality, integrity, and availability of information handled through our websites, applications, and services.
Contact our security and compliance team at: info@nausha.in
[Security Vulnerability Report]Our security practices are designed around core engineering principles including secure development, access control, encryption, least privilege, monitoring, and protection of sensitive information.
1Security Architecture & Approach
At Nausha Technologies, security is treated as an important part of our software development and operational processes.
Depending on the nature of the service, our security controls may include:
Security controls may vary depending on the product, service, infrastructure provider, and technical requirements involved.
2Encryption & Transport Security
Encryption in Transit
Where supported by our infrastructure and applicable service configuration, communications with Nausha websites, applications, APIs, and related services are protected using HTTPS/TLS.
We configure our services to use modern and industry-accepted transport-security protocols and cryptographic configurations appropriate to the underlying infrastructure. We do not intentionally design our public services to transmit sensitive information through unencrypted HTTP connections.
Encryption at Rest
Data stored through our infrastructure may benefit from encryption-at-rest capabilities provided by our cloud and infrastructure providers.
For services hosted on Google Cloud, Google Cloud provides encryption at rest for customer content at the storage layer. Specific encryption mechanisms and key-management arrangements may vary by service and configuration. We do not represent that every individual application component or customer-controlled environment uses an identical encryption configuration.
3Cloud Infrastructure
Nausha Technologies may use third-party cloud and infrastructure providers to host, operate, monitor, and scale our applications and services.
Where applicable, our infrastructure may include managed cloud services, containerized workloads, databases, object storage, networking services, monitoring systems, and automated deployment systems. For services hosted on Google Cloud Platform, Google Cloud provides security controls including encryption at rest and encryption in transit as part of its infrastructure.
The specific infrastructure used by a particular Nausha product may differ from the infrastructure used by another product.
4Payment Security
Where Nausha accepts online payments through a third-party payment provider, payment processing is handled through the applicable payment service provider. For example, Razorpay provides payment infrastructure with PCI DSS-related security controls and certifications for its applicable entities and services.
Payment Information
Depending on the integration and payment method, Nausha may receive transaction-related information such as payment or order ID, transaction status, amount, currency, payment method type, and refund status.
Where payment processing is handled by a third-party payment provider, Nausha does not intentionally store complete card numbers, CVVs, PINs, or similar payment credentials on its own application servers.
Payment Verification
Our payment integrations use server-side verification, authenticated API communication, and webhook validation appropriate to the payment provider's standards.
Where webhook signatures are supported and required by the payment provider, we validate the cryptographic authenticity of relevant webhook events before treating them as trusted notifications.
PCI DSS Scope
Nausha Technologies does not claim to be independently PCI-DSS certified merely because we use a PCI-compliant payment provider.
The applicable PCI DSS responsibilities depend on the payment integration, systems involved, and scope of the relevant payment environment.
5Access Controls & Data Protection
We apply access controls appropriate to the nature of the systems and information involved:
Least Privilege
Access to administrative systems, production environments, databases, deployment systems, and other sensitive resources is strictly restricted according to operational requirements.
Authentication & Authorization
Administrative and internal systems employ strong authentication, role-based access permissions, multi-factor authentication (MFA), and credential expiration policies where appropriate.
Secret Management
API keys, passwords, tokens, signing secrets, and other sensitive credentials are managed separately from public application code. Production secrets are never exposed through client-side code, public repositories, or unsecured configuration files.
Application Security Controls
Our applications employ input validation, output encoding, parameterized database queries, rate limiting, secure session management, and continuous dependency updates to defend against common web application vulnerabilities.
6Security Monitoring & Maintenance
We may use logging, monitoring, alerts, automated health checks, and operational reviews to identify service failures, suspicious activity, and security anomalies.
Security monitoring and log retention practices may vary depending on the specific service, operational environment, and underlying cloud infrastructure.
7Vulnerability Disclosure
We welcome responsible reports from security researchers, customers, developers, and other individuals who identify potential security vulnerabilities in our websites, applications, or APIs.
Reporting a Vulnerability
Direct communications channel for verified security findingsPlease submit vulnerability reports by email to info@nausha.in with the exact subject line:
- A clear description of the suspected vulnerability
- The affected website, application endpoint, API, or feature
- Step-by-step instructions to reproduce the issue
- Relevant HTTP request/response payloads or screenshots
- Proof-of-concept information where appropriate
- Your assessment of the potential security impact
Responsible Disclosure Guidelines
Security researchers interacting with our services are expected to:
- Avoid accessing, downloading, modifying, deleting, or exposing data belonging to other users.
- Avoid disrupting services, performing denial-of-service (DoS/DDoS), or degrading system availability.
- Avoid social engineering (phishing), physical attacks, or attacks directed at third-party infrastructure.
- Avoid testing against accounts, records, or infrastructure that you do not own.
- Provide sufficient technical detail for our engineering team to reproduce and verify the issue.
- Allow reasonable time for investigation and remediation before publicly disclosing any vulnerability.
We review legitimate security reports and may contact the reporter for clarification. Response and remediation times depend on the severity, complexity, and affected systems. This disclosure process does not create a contractual obligation to provide a response SLA, bounty reward, or specific remediation outcome.
8Security Limitations
No internet-connected service, software application, electronic storage system, or network transmission method can be guaranteed to be completely secure.
Although Nausha Technologies takes reasonable technical and organizational measures to protect information and systems, we cannot guarantee that our services will be immune from every vulnerability, attack, unauthorized access attempt, service interruption, or other security incident.
If we become aware of a confirmed security incident affecting personal information or our services, we will assess and respond to it in accordance with applicable law and our internal incident-response procedures. We may update our security practices as our products, infrastructure, technology, and applicable legal requirements evolve.
9Legal & Governance Information
Statutory & Compliance Details
Official administrative reference for security and infrastructure postureThis document is governed by the applicable laws of India.
The information provided on this page describes our general security approach and is not intended to disclose confidential security architecture, credentials, internal network configurations, proprietary controls, or other information that could compromise the security of our systems.
Legal & Governance Inquiries
This document is governed by the laws of India. For statutory notices, formal service of process, or compliance inquiries, direct all communications to: