Security, Privacy & Infrastructure Compliance
At SettleKar, security is foundational to our enterprise workforce relocation platform. Learn about our data protection controls, encryption standards, and threat monitoring.
1. Trust & Compliance Framework
SettleKar adheres to international information security benchmarks, including SOC 2 Type II controls and ISO 27001 ISMS principles. Our corporate relocation engine ensures strict isolation between enterprise tenant datasets.
2. 256-Bit Data Encryption Standards
All data transmitted between enterprise clients, field PAs, and SettleKar servers is encrypted using industry-standard TLS 1.3 protocols with cipher suites enforcing perfect forward secrecy. Data stored at rest in Cloud Firestore is encrypted using 256-bit AES storage keys.
3. Auth & Role-Based Access Control (RBAC)
We enforce granular Role-Based Access Control (RBAC) across our enterprise environment:
- Super Admin Level: Global access restricted exclusively to audited `admin@settlekar.in` accounts.
- Corporate Partner Level: Isolated partner data views restricted by verified UID and custom token claims.
- Branch Office Level: Access scope strictly constrained to relocations initiated by the specific branch location (`off_...`).
- Property Associate Level: Limited view restricted to assigned employee tickets for on-ground verification.
4. PA Field Security & Audit Controls
Every Property Associate (PA) undergoes background verification and identity checks before being granted access to field assignment features. Field submissions (HD videos, property checklists) are watermarked and timestamped for auditability.
5. Uptime SLA & Threat Monitoring
SettleKar maintains an operational uptime SLA of 99.99%. Automated DDoS mitigation and web application firewall (WAF) rules continuously protect against malicious requests, SQL injection, and cross-site scripting (XSS).
6. Vulnerability & Responsible Disclosure
We welcome reports from security researchers and corporate IT administrators. If you believe you have discovered a vulnerability, report it to our Security Operations Center: