Bank-Grade Protection

Your Jewellery Data. Protected Like a Vault.

AES-256 encryption. India data residency. Quarterly ethical hacking. Daily backups. Your HUID records, gold inventory, and customer data are safer with SoniERP than on any paper register.

AES-256 Encrypted
DPDP Act Compliant
India Data Residency
VAPT Tested
99.9% Uptime SLA
6 Layers of Protection

How We Keep Your Data Safe

In Transit & At Rest

AES-256 Encryption

All your data — inventory, customer records, GST invoices, gold loan details — is encrypted using AES-256, the same standard used by global banks. Data in transit is protected by TLS 1.3.

  • Encryption at rest (database level)
  • TLS 1.3 for all API communications
  • Encrypted backups
  • Zero plaintext storage
Quarterly Penetration Testing

VAPT Tested

Every quarter, certified ethical hackers conduct a Vulnerability Assessment and Penetration Test (VAPT) on our entire platform — API, frontend, mobile app, and infrastructure.

  • OWASP Top 10 tested
  • API security audit
  • Mobile app security review
  • Report available on request
Zero-Trust Access

JWT + MFA Authentication

Every staff member's access is governed by role-based permissions (Owner, Manager, Salesperson, Accountant). Multi-factor authentication prevents unauthorised access even if passwords are compromised.

  • Role-based access control (RBAC)
  • Session expiry + device tracking
  • Suspicious login alerts
  • Account lockout after failed attempts
30-Day Retention

Daily Automated Backups

Your store data is backed up automatically every 6 hours. Daily snapshots are retained for 30 days, and weekly archives for 12 months — complying with India's 7-year GST record retention requirement.

  • Backups every 6 hours
  • Point-in-time recovery
  • Cross-region replication
  • 7-year GST archive compliance
Mumbai AWS Region

India Data Residency

All your data is stored exclusively in AWS Mumbai (ap-south-1), within India's borders. We do not transfer your data internationally. Compliant with the Digital Personal Data Protection Act, 2023.

  • AWS ap-south-1 (Mumbai)
  • No international data transfers
  • DPDP Act 2023 compliant
  • Data sovereignty guaranteed
Multi-AZ Deployment

99.9% Uptime SLA

SoniERP runs on a multi-availability-zone deployment with automatic failover. If one zone has issues, traffic automatically routes to healthy zones — no downtime, no data loss.

  • Multi-AZ architecture
  • Auto-scaling under load
  • CDN for global performance
  • Incident response < 15 minutes

Responsible Disclosure

Found a security vulnerability? We appreciate responsible disclosure and reward it. Email us at security@sonierp.in with details. We respond within 24 hours and offer bounties for valid critical and high severity findings.

Report a Vulnerability

Security FAQs

Is my HUID and inventory data safe?

Yes. Your HUID codes, inventory weights, and product details are encrypted at rest using AES-256 and can only be accessed by authenticated staff with appropriate RBAC roles. We never share or sell your data.

Who can see my store's data?

Only you and staff members you explicitly grant access to. SoniERP staff can only access anonymised system metrics — never your store's inventory, customer, or financial data, unless you open a support ticket and explicitly authorise us.

What happens if there is a security breach?

We have a 72-hour breach notification policy. If any security incident affects your data, we will notify you via email and WhatsApp within 72 hours with full details and remediation steps, as required by the DPDP Act, 2023.

Can I export my data at any time?

Yes, always. Go to Settings → Data Export to download your complete store data as CSV, JSON, or PDF. Your data is yours. We will never hold it hostage.

Are you SOC 2 certified?

We are currently undergoing SOC 2 Type II certification (expected Q4 2026). Our security practices already meet SOC 2 requirements — certification is the formal audit process.

Questions About Our Security?

Our security team responds within 24 hours. We speak jeweller, not jargon.