TRUST · SECURITY

Data Security Statement

Encoreats’ security governance, incident response and user responsibilities.

Effective: 01 AUGUST 2026Last reviewed: 31 July 2026
India-focused draft. Publish only after the bracketed company details, actual workflows and active contact channels are completed.

Security programme

Encoreats aims to apply risk-based administrative, technical and organisational controls across identities, applications, cloud infrastructure, data stores, vendors and operations.

Core controls

  • Least-privilege and role-based access.
  • Multi-factor authentication for privileged access.
  • Encryption in transit and appropriate encryption at rest.
  • Secure development, review, dependency and vulnerability management.
  • Central logging, monitoring, backups and recovery testing.
  • Secrets management and separation of environments.
  • Vendor due diligence and contractual data-security obligations.

CERT-In readiness

Applicable systems should use accurate time synchronisation, designate an incident point of contact, report specified cyber incidents within the prescribed six-hour period, and securely retain required ICT logs for a rolling period of 180 days within Indian jurisdiction.

Personal data incidents

The incident plan covers containment, investigation, evidence preservation, risk assessment, processor coordination, affected-person communication and notification to the competent authority where required.

Responsible disclosure

Security researchers should report suspected vulnerabilities to security@encoreats.info with reproduction steps and avoid privacy invasion, service disruption, data extraction, extortion or public disclosure before a reasonable remediation period.

User security

Use unique passwords, enable available MFA, keep devices updated, verify domains and never disclose OTPs, UPI PINs, banking passwords or CVVs.

Launch and legal-review notice

This is a structured operational draft for Encoreats and not a substitute for advice from a qualified Indian advocate, chartered accountant, data-protection professional, or other specialist. Before publication, replace all bracketed fields, confirm that every email inbox and response workflow is operational, and ensure the wording matches the actual product, payment, refund, data-retention, verification, event, and partner processes.