Back to Home
● SECURITY ARCHITECTURESOC 2 TYPE II & ISO 27001 ALIGNED

Security, Privacy & Infrastructure Compliance

At SettleKar, security is foundational to our enterprise workforce relocation platform. Learn about our data protection controls, encryption standards, and threat monitoring.

1. Trust & Compliance Framework

SettleKar adheres to international information security benchmarks, including SOC 2 Type II controls and ISO 27001 ISMS principles. Our corporate relocation engine ensures strict isolation between enterprise tenant datasets.

ENCRYPTION256-Bit AES / TLS 1.3
AUTHENTICATIONFirebase Custom Tokens
AUDIT LOGGINGImmutable Ledger

2. 256-Bit Data Encryption Standards

All data transmitted between enterprise clients, field PAs, and SettleKar servers is encrypted using industry-standard TLS 1.3 protocols with cipher suites enforcing perfect forward secrecy. Data stored at rest in Cloud Firestore is encrypted using 256-bit AES storage keys.

3. Auth & Role-Based Access Control (RBAC)

We enforce granular Role-Based Access Control (RBAC) across our enterprise environment:

  • Super Admin Level: Global access restricted exclusively to audited `admin@settlekar.in` accounts.
  • Corporate Partner Level: Isolated partner data views restricted by verified UID and custom token claims.
  • Branch Office Level: Access scope strictly constrained to relocations initiated by the specific branch location (`off_...`).
  • Property Associate Level: Limited view restricted to assigned employee tickets for on-ground verification.

4. PA Field Security & Audit Controls

Every Property Associate (PA) undergoes background verification and identity checks before being granted access to field assignment features. Field submissions (HD videos, property checklists) are watermarked and timestamped for auditability.

5. Uptime SLA & Threat Monitoring

SettleKar maintains an operational uptime SLA of 99.99%. Automated DDoS mitigation and web application firewall (WAF) rules continuously protect against malicious requests, SQL injection, and cross-site scripting (XSS).

6. Vulnerability & Responsible Disclosure

We welcome reports from security researchers and corporate IT administrators. If you believe you have discovered a vulnerability, report it to our Security Operations Center:

SettleKar Security Operations Center (SOC)
PGP Fingerprint: `7F8A 4B1C 92D3 E4F5 6789 0123 4567 89AB`