Legal & trust
Security
Overview of security practices, infrastructure protections, and responsible disclosure for the EasyAavaas platform.
At EasyAavaas, protecting the confidentiality, integrity, and availability of our platform and your data is a core priority. This page summarizes the technical and organizational measures we use to safeguard the Services.
This overview is provided for transparency and does not constitute a warranty or contractual commitment beyond what is stated in our Terms & Conditions.
1. Security Overview
EasyAavaas is a multi-tenant cloud platform serving property owners, staff, and tenants. Our security program is designed to protect account credentials, property and tenant data, payment records, uploaded documents, and operational workflows across web and mobile channels.
We apply defense-in-depth principles: secure development practices, least-privilege access, encryption, monitoring, and incident response procedures.
2. Infrastructure and Hosting
- Production workloads are hosted on reputable cloud infrastructure with physical and environmental controls managed by the cloud provider.
- Network segmentation and firewalls limit exposure of internal services.
- Regular backups and recovery procedures support business continuity.
- API services are served over HTTPS via https://api.easyaavaas.com.
3. Encryption
- Data in transit is protected using TLS (HTTPS) for website, API, and mobile app communications.
- Sensitive credentials such as authentication tokens are stored using platform-appropriate secure storage mechanisms on mobile devices.
- Server-side secrets and credentials are managed using access-controlled secret management practices.
- We prioritize encryption at rest for production databases and file storage where supported by our infrastructure.
4. Authentication and Access Control
- User sign-in uses OTP verification tied to a registered mobile number.
- Sessions use short-lived access tokens with refresh token rotation to reduce exposure from compromised credentials.
- Role-based access control (RBAC) and granular permission overrides restrict what each user can view or modify within a property.
- Administrative and production access is limited to authorized personnel on a need-to-know basis.
- Inactive sessions may expire; users can log out from the app at any time.
5. Application Security
- Input validation and authorization checks are enforced on API endpoints before data is read or modified.
- Property scope controls prevent cross-property data access unless a user has legitimate membership and permissions.
- File uploads are subject to type and size limits; documents are stored in controlled storage services.
- Security-relevant events are logged for monitoring and investigation.
- We review dependencies and apply security patches on a risk-prioritized basis.
6. Notifications and Third-Party Integrations
Push notifications are delivered through industry-standard services such as Firebase Cloud Messaging. Only the minimum data necessary to deliver notifications is shared with such providers, in accordance with our Privacy Policy.
OTP and messaging providers process phone numbers solely to deliver authentication and service messages you or your property operator enable.
7. Incident Response
We maintain procedures to detect, assess, contain, and remediate security incidents. Where required by law, we will notify affected users and relevant authorities of a personal data breach within applicable timelines.
If you believe your account has been compromised, contact [email protected] immediately and change any reused passwords on other services.
8. Responsible Disclosure
We welcome reports from security researchers and users who identify potential vulnerabilities in good faith. Please report concerns to:
- Email: [email protected]
- Include a detailed description, steps to reproduce, affected URLs or endpoints, and impact assessment if known.
- Do not access, modify, or exfiltrate data belonging to other users.
- Allow reasonable time for us to investigate and remediate before public disclosure.
We will acknowledge valid reports within a reasonable timeframe and may recognize researchers who help improve our security, at our discretion.
9. Compliance and Privacy Alignment
Our security practices are aligned with our Privacy Policy and applicable data protection requirements in India, including the DPDP Act as implemented. We assess vendors that process personal data under appropriate contractual safeguards.
10. Your Security Responsibilities
You play an important role in keeping your data secure:
- Do not share OTP codes or allow others to use your authenticated session.
- Assign staff permissions carefully and revoke access when roles change.
- Use current versions of the mobile app and a supported operating system.
- Report suspicious activity, phishing messages, or unauthorized access promptly.
- Ensure tenant documents and payment proofs are uploaded only with proper authorization.
11. Limitations
No security measure is perfect. While we work continuously to improve our protections, we cannot guarantee that unauthorized access, loss, or alteration will never occur. See our Terms & Conditions for limitations of liability.
12. Contact
- Security reports: [email protected]
- Privacy: [email protected]
- Support: [email protected]