Security & trust

Your data stays in India, and stays yours

Trial results, quality records and plant data are some of the most sensitive information our customers share. Our digital services are designed around a simple set of commitments.

Indiacustomer data stored in Indian data centres
Isolatedevery organisation's data separated at the database
Loggedsign-ins, sign-offs and document access
Opt-inany benchmarking is anonymised and opt-in only
Our commitments

Security designed in, not bolted on

These principles apply to every Greenprastha digital service, from enquiry forms and document sharing to trial records and certificates.

Data residency in India

Customer data is stored and processed in Indian data centres (Mumbai region).

Encryption everywhere

TLS in transit with HSTS, and encryption at rest for databases, files and backups.

Strict access control

Row-level security isolates each organisation's data; staff access is least-privilege and role-based.

Strong sign-in

Multi-factor authentication for staff, and single sign-on for enterprise customers.

Complete audit trail

An append-only log of sign-ins, trial sign-offs, certificate issue and document access.

Short-lived access

Downloads use time-limited links and are watermarked with the recipient's name.

Privacy

Your data is used only for what you agree to

DPDP Act 2023

Our privacy practices follow India's Digital Personal Data Protection Act, with consent recorded and honoured.

No names without permission

We never publish customer names, logos or data without written permission.

Anonymised benchmarking

Fleet comparisons are opt-in, anonymised, and shown only when a cohort is large enough to protect identity.

Engineer working at a test rig
Plant connectivity

Outbound only. Never into your plant.

Where customers choose to share operating data, it flows out through an on-site gateway over HTTPS, signed and replay-protected. We never make inbound connections to customer control systems.

  • Per-device keys, rotated on schedule
  • Signed requests with a short replay window
  • CSV upload for sites without a live connection
Responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers and respond promptly. Please don't access or modify data that isn't yours, and give us reasonable time to fix an issue before disclosure.

Security contact
security@greenprastha.comWe acknowledge reports within two working days.

Security questionnaire?

We're happy to complete your supplier security and data-protection questionnaires.