CredSetu handles financial transaction data, which the IT Act SPDI Rules 2011 classify as Sensitive Personal Data or Information. This page summarises, in plain language, the security practices we apply to protect it. It is a public summary — it does not cover every internal operational detail.
Encryption
- In transit: TLS 1.2 or higher on every connection that carries your data
- At rest: AES-256 encryption for all databases and file storage
Infrastructure
CredSetu is hosted on Amazon Web Services, Mumbai (ap-south-1) region. Your data is stored in India.
Access Control
- Access to production data follows the principle of least privilege — team members only get access to what their role requires
- Multi-factor authentication is enforced on every account with access to production systems or infrastructure
- Access grants are reviewed periodically, and access that is no longer needed is revoked promptly
- Credentials and API keys are never shared in plaintext, and are rotated on a defined schedule or immediately upon suspected compromise
Data Classification
We classify transaction amounts, repayment history, Trust Score, and phone numbers linked to financial records as Sensitive Personal Data — our highest protection tier. This data is encrypted at rest and in transit, access to it is logged, and it is never exported to a personal device.
If Something Goes Wrong
In the event of a suspected data breach or unauthorised access, we follow a fixed incident response process:
- Contain the issue and assess what data and how many users are affected
- Notify CERT-In within the timeframe required under the CERT-In Directions, 2022, where the incident meets the reporting threshold
- Notify affected users directly, in plain language — what happened, what data was involved, what we have done, and what you should do, if anything
- Remediate the issue and rotate any credentials that were or may have been exposed
We do not conceal a security incident from affected users or from CERT-In where notification is legally required.
Reporting a Security Concern
If you believe you have found a security issue affecting CredSetu, please tell us at support@credsetu.in — we take reports seriously and will follow up directly.
Compliance Basis
Our security practices are maintained to meet the “reasonable security practices” standard under Section 43A of the IT Act, 2000, the SPDI Rules 2011, the CERT-In Directions 2022, and the Digital Personal Data Protection Act, 2023. For how we collect, use, and share your data, see our Privacy Policy.