Security & Compliance

Last updated: Jan 11, 2025

At DaanSetu, we prioritize the security of your data and the integrity of our platform. Our compliance measures ensure a safe and trustworthy crowdfunding experience for all users.

1. Data Encryption & Transmission

  • SSL/TLS Encryption: All data exchanged between your browser and our servers is protected with industry-standard SSL/TLS encryption.
  • Database Encryption: Sensitive information (e.g., payment details, passwords) is encrypted at rest using AES-256.

2. Payment Security

  • PCI-DSS Compliance: We partner with certified payment gateways (Razorpay, Stripe, PayPal) that adhere to PCI-DSS standards.
  • Tokenization: Card details are tokenized, ensuring no raw card data is stored on our servers.

3. Access Control & Authentication

  • Secure Authentication: Enforced strong password policies and optional two-factor authentication (2FA) for all user accounts.
  • Role-Based Access: Administrative functions are limited to authorized personnel with strict access controls.

4. Regular Security Audits & Monitoring

  • Penetration Testing: Quarterly third-party penetration tests to identify and remediate vulnerabilities.
  • Continuous Monitoring: 24/7 monitoring of network traffic and server logs for suspicious activity.

5. Compliance with Laws & Regulations

  • Indian IT Act & Rules: We comply with the provisions of the Information Technology Act, 2000, and related rules.
  • Data Protection Standards: While India’s Personal Data Protection Bill is under consideration, we adhere to global best practices (GDPR-aligned principles) for data handling.

6. Incident Response & Reporting

  • Incident Response Plan: Defined procedures for identifying, containing, and recovering from security incidents.
  • User Notification: Prompt notification to affected users in case of data breaches, per applicable regulations.

7. User Responsibilities

Thank you for trusting DaanSetu. We continually enhance our security posture to protect your data and enable a reliable crowdfunding environment.