Security & trustFolio 03
Built for the most sensitive data an employer holds.
PAN, Aadhaar, bank accounts and payslip details are encrypted at rest, access is limited to the people assigned, and every action leaves a record. Designed around India’s Digital Personal Data Protection Act 2023 (DPDP).
- PAN
- ABCPK••••F
- Stored as $enc$1$k1$Qm9vN2x…
- Aadhaar
- XXXX XXXX 4821
- Stored as $enc$1$k1$c1RkZ0…
- Bank account
- ••••••••7731
- Stored as $enc$1$k1$9fK3xL…
- Date of birth
- ••/••/19••
- Stored as $enc$1$k1$Zm1QaW…
Encrypted with AES-256-GCM before it reaches the database
- Personal fields & files
- AES-256-GCM
- Passwords
- Argon2id
- Audit trail
- 10 categories · 3 years
- Designed around
- DPDP Act 2023
01 · Defence in depth
Encrypted field by field, file by file.
Four layers stand between the internet and an employee's PAN. Open the vault.
-
Layer 4 · The data itself
Encryption at rest
AES-256-GCM
- On personal fields: PAN, UAN, Aadhaar, date of birth, mobile, address, bank account, portal e-mails, client identifiers and invoice bill-to details
- Every uploaded file encrypted with its own key (envelope encryption). Tampering, reordering or truncation is detected.
- Aadhaar is only ever displayed masked, as the last four digits
- Searchable identifiers use keyed hashes (HMAC-SHA256 blind indexes)
- Keys rotate without downtime. The application refuses to start without its keys.
-
Layer 3 · Who you are
Password hashing
Argon2id
$argon2id$v=19$m=102400,t=2,p=8$c2FsdHNhbHQ…
- Temporary passwords must be changed on first sign-in
- Reset links are single-use, stored only as a hash, and expire after 2 hours
- Client sessions end after 1 hour. Disabled logins are cut off immediately.
- Multi-factor authentication Coming
-
Layer 2 · What you may see
Access by assignment
Server-side checks
- Row-level security is enabled on every database table, as a second layer behind the application’s own checks
- Team members see only the clients allocated to them, enforced on every request
- Client logins are separate from team accounts and scoped to one employer
-
Layer 1 · The front door
Headers & rate limits
CSP · HSTS · 429
- Rate limiting and lockout on all logins, resets, paid lookups and uploads
- HSTS, Referrer-Policy, Permissions-Policy and no-store on sensitive responses; Content-Security-Policy (report-only while the last inline scripts are migrated)
- Uploaded active content (HTML, SVG) is forced to download in a sandbox, never rendered inline
02 · Access control
The right people, and only them.
Every action is checked on the server against who you are and which clients you are allocated to. The person who prepares a payroll can never be the one who approves it.
| Action | Administrator | Team member allocated to the client | Team member not allocated | Client portal user one employer |
|---|---|---|---|---|
| See the client's records, calendar and vault | Yes | Yes | No | Own employer only |
| Prepare and compute payroll | Yes | Yes | No | No |
| Approve payroll Maker ≠ checker | Yes, if they did not compute it | Yes, if they did not compute it | No | Yes, when client approval is on |
| Send back with a reason | Yes | Yes | No | Yes, when client approval is on |
| Finalize and release statutory files | Yes | No | No | No |
| Reopen a finalized month (until any return for it is filed) | Yes, with a reason | No | No | No |
| Add clients, payroll settings and paid GST/MCA lookups | Yes | No | No | No |
Every cross-client access attempt in our internal security review was denied.
03 · Audit trail
A lasting answer to “who did this?”.
- Sign-ins and sign-outs, uploads, downloads, previews, filings, edits, approvals and payroll steps are all logged
- Before and after values on master-data and billing changes
- Retained for 3 years
- Payroll log entries never contain salary amounts
10 categories
- Compliance
- Document
- Company Data
- System
- Client
- Employee
- Assignment
- Authentication
- Billing
- Payroll & HR
- Payroll & HRPayroll for Sep 2026 approved by the clientA. Menon
- DocumentDownloaded PF ECR Sep 2026.txtR. Sharma
- Company DataEdited IFSC for E-027 · before → after keptR. Sharma
- ComplianceESIC contribution Aug 2026 filedP. Verma
- AuthenticationSigned in · client portalA. Menon
- AssignmentClient allocated to P. VermaAdmin
- AuthenticationSigned in · team portalR. Sharma
04 · DPDP Act 2023
Your obligations under DPDP, supported by the platform.
For your employees' data, you (the employer) are the Data Fiduciary and Shardhan processes on your instruction. For portal users, Shardhan is the Fiduciary.
| DPDP requirement | What the platform does |
|---|---|
| Notice and consent s.5–6 | Privacy notice shown at sign-in. Consent recorded per login with the notice version. A new version asks again. |
| Reasonable security safeguards s.8(5) | Encryption at rest, access control, rate limiting, security headers, audit trail |
| Breach notification s.8(6) | Written breach-response runbook covering CERT-In 6-hour reporting and notice to the Board and affected people |
| Erasure when purpose is served s.8(7) | Retention schedule with automated purge. Payroll and invoice records are held for 8 financial years as the law requires; contact data is erased on request. |
| Access and correction s.11–12 | Machine-readable export of a person's data. Correction and erasure tooling. |
| Grievance redressal s.8(9), s.13 | Grievance officer contact on the privacy notice |
Engineering interpretation of the Act, pending review by counsel. Not legal advice.
05 · Application security
Tested, then tested again.
- Internal security review against OWASP ASVS Level 2 controls: 15 findings, none critical (3 high); 12 fixed, 1 mitigated, 2 tracked as deployment actions
- Django's production deployment check: 0 warnings
- No known vulnerable dependencies at review (pip-audit)
- 800+ automated tests across the platform
- Accessibility checked against WCAG 2.2 AA with axe-core: 0 serious or critical issues on audited screens
- Payslip PDFs are password-protected with AES-256 by default
06 · Responsible disclosure
Found something? Tell us.
Write to our privacy and security desk. Please include the steps to reproduce, and give us a reasonable time to fix it before you share it. We will acknowledge your report.
legal@shardhanconsultants.com