Security
What we do today, and what is on the roadmap.
We separate the security controls that are live in production from the ones we plan to add. We do not claim certifications we have not been awarded.
In place today
- Client data is stored in India. Our database and document storage run on infrastructure located in Mumbai.
- Data in transit is encrypted using TLS 1.2 or higher.
- Role-based access control (Admin, Edit, View) on every workspace surface.
- Every create, update, delete and export is written to an audit log with the acting user and timestamp.
- Workspace isolation is enforced in the application layer: every query is scoped to the workspaces a user belongs to.
- Statutory company data is sourced from the government's own MCA dataset on data.gov.in, not from third-party scrapers.
- Security disclosure mailbox: security@hyperfiling.com.
On the roadmap
- Database-layer isolation: Postgres Row-Level Security policies are written and will be enforced once the application connects with a non-superuser role. Isolation today rests on application-layer query scoping.
- Encryption at rest for stored documents.
- Tamper-evident audit log with a defined retention period.
- AI processing entirely within India. Inference enters via the Mumbai region today, on a provider profile that may route outside India under load.
- SOC 2 Type II audit (target window: late 2026).
- ISO 27001 information security management certification (target window: 2027).
- Customer-managed encryption keys for Enterprise customers.
- SAML / OIDC single sign-on for Firm and Enterprise tiers.
Data Residency
Notice OCR & DPDPA Compliance
Image OCR uploads (notice photos, scanned PDFs) are processed by AWS Bedrock Claude Sonnet 4.5 in our currently configured Bedrock region. While production runs in us-east-1, image bytes transiently leave Indian jurisdiction during processing. Bedrock does not retain prompts or images after the response. HyperFiling will migrate image OCR to ap-south-1 when AWS makes Claude Sonnet 4.5 generally available there.
Disclosure
Found a vulnerability?
Email security@hyperfiling.com with reproduction steps. We acknowledge within two working days. Coordinated disclosure is welcome. We will not pursue good-faith researchers who follow the disclosure policy.