Security & trustFolio 03

Built for the most sensitive data an employer holds.

PAN, Aadhaar, bank accounts and payslip details are encrypted at rest, access is limited to the people assigned, and every action leaves a record. Designed around India’s Digital Personal Data Protection Act 2023 (DPDP).

One employee record, as the database stores it (illustrative)
PAN
ABCPK••••F
Stored as $enc$1$k1$Qm9vN2x…
Aadhaar
XXXX XXXX 4821
Stored as $enc$1$k1$c1RkZ0…
Bank account
••••••••7731
Stored as $enc$1$k1$9fK3xL…
Date of birth
••/••/19••
Stored as $enc$1$k1$Zm1QaW…

Encrypted with AES-256-GCM before it reaches the database

Personal fields & files
AES-256-GCM
Passwords
Argon2id
Audit trail
10 categories · 3 years
Designed around
DPDP Act 2023

01 · Defence in depth

Encrypted field by field, file by file.

Four layers stand between the internet and an employee's PAN. Open the vault.

  1. Layer 4 · The data itself

    Encryption at rest

    AES-256-GCM

    • On personal fields: PAN, UAN, Aadhaar, date of birth, mobile, address, bank account, portal e-mails, client identifiers and invoice bill-to details
    • Every uploaded file encrypted with its own key (envelope encryption). Tampering, reordering or truncation is detected.
    • Aadhaar is only ever displayed masked, as the last four digits
    • Searchable identifiers use keyed hashes (HMAC-SHA256 blind indexes)
    • Keys rotate without downtime. The application refuses to start without its keys.
  2. Layer 3 · Who you are

    Password hashing

    Argon2id

    $argon2id$v=19$m=102400,t=2,p=8$c2FsdHNhbHQ…

    • Temporary passwords must be changed on first sign-in
    • Reset links are single-use, stored only as a hash, and expire after 2 hours
    • Client sessions end after 1 hour. Disabled logins are cut off immediately.
    • Multi-factor authentication Coming
  3. Layer 2 · What you may see

    Access by assignment

    Server-side checks

    • Row-level security is enabled on every database table, as a second layer behind the application’s own checks
    • Team members see only the clients allocated to them, enforced on every request
    • Client logins are separate from team accounts and scoped to one employer
  4. Layer 1 · The front door

    Headers & rate limits

    CSP · HSTS · 429

    • Rate limiting and lockout on all logins, resets, paid lookups and uploads
    • HSTS, Referrer-Policy, Permissions-Policy and no-store on sensitive responses; Content-Security-Policy (report-only while the last inline scripts are migrated)
    • Uploaded active content (HTML, SVG) is forced to download in a sandbox, never rendered inline

02 · Access control

The right people, and only them.

Every action is checked on the server against who you are and which clients you are allocated to. The person who prepares a payroll can never be the one who approves it.

View as
Who can do what in Shardhan, by role
Action Administrator Team member allocated to the client Team member not allocated Client portal user one employer
See the client's records, calendar and vaultYesYesNoOwn employer only
Prepare and compute payrollYesYesNoNo
Approve payroll Maker ≠ checkerYes, if they did not compute itYes, if they did not compute itNoYes, when client approval is on
Send back with a reasonYesYesNoYes, when client approval is on
Finalize and release statutory filesYesNoNoNo
Reopen a finalized month (until any return for it is filed)Yes, with a reasonNoNoNo
Add clients, payroll settings and paid GST/MCA lookupsYesNoNoNo

Every cross-client access attempt in our internal security review was denied.

03 · Audit trail

A lasting answer to “who did this?”.

  • Sign-ins and sign-outs, uploads, downloads, previews, filings, edits, approvals and payroll steps are all logged
  • Before and after values on master-data and billing changes
  • Retained for 3 years
  • Payroll log entries never contain salary amounts

10 categories

  • Compliance
  • Document
  • Company Data
  • System
  • Client
  • Employee
  • Assignment
  • Authentication
  • Billing
  • Payroll & HR

04 · DPDP Act 2023

Your obligations under DPDP, supported by the platform.

For your employees' data, you (the employer) are the Data Fiduciary and Shardhan processes on your instruction. For portal users, Shardhan is the Fiduciary.

How the platform lines up with the DPDP Act 2023
DPDP requirementWhat the platform does
Notice and consent s.5–6Privacy notice shown at sign-in. Consent recorded per login with the notice version. A new version asks again.
Reasonable security safeguards s.8(5)Encryption at rest, access control, rate limiting, security headers, audit trail
Breach notification s.8(6)Written breach-response runbook covering CERT-In 6-hour reporting and notice to the Board and affected people
Erasure when purpose is served s.8(7)Retention schedule with automated purge. Payroll and invoice records are held for 8 financial years as the law requires; contact data is erased on request.
Access and correction s.11–12Machine-readable export of a person's data. Correction and erasure tooling.
Grievance redressal s.8(9), s.13Grievance officer contact on the privacy notice

Engineering interpretation of the Act, pending review by counsel. Not legal advice.

05 · Application security

Tested, then tested again.

  • Internal security review against OWASP ASVS Level 2 controls: 15 findings, none critical (3 high); 12 fixed, 1 mitigated, 2 tracked as deployment actions
  • Django's production deployment check: 0 warnings
  • No known vulnerable dependencies at review (pip-audit)
  • 800+ automated tests across the platform
  • Accessibility checked against WCAG 2.2 AA with axe-core: 0 serious or critical issues on audited screens
  • Payslip PDFs are password-protected with AES-256 by default

06 · Responsible disclosure

Found something? Tell us.

Write to our privacy and security desk. Please include the steps to reproduce, and give us a reasonable time to fix it before you share it. We will acknowledge your report.

legal@shardhanconsultants.com