Trust Center

We host sensitive deal flow, member networks, and payment data. Here's how we protect it — and what you can verify before you join.

Last updated 12 Feb 2026

DPDPA 2023

India compliant

bcrypt + JWT

Auth hardened

HTTPS only

TLS 1.3 enforced

30-day grace

Deletion window

Compliance & Certifications

  • Digital Personal Data Protection Act, 2023 (India) — full compliance. Read policy / Exercise your rights
  • GDPR-aligned — international members benefit from the same data rights as Indian Data Principals.
  • PCI DSS via Razorpay — payment card data never touches our servers. Razorpay handles tokenization end-to-end.

Security Practices

Password storage

bcrypt with per-user salt + adaptive cost factor. Never logged, never returned in API responses or exports.

Authentication

JWT with HttpOnly secure cookies. Rate-limited login + password reset endpoints (slowapi). 24-hour token expiry with refresh.

Transport security

TLS 1.3 enforced. Strict-Transport-Security headers. HTTP requests auto-redirect to HTTPS.

Audit logging

Every admin action recorded with actor, target, timestamp + IP. Available on legal request.

Database

MongoDB Atlas with encryption-at-rest (AES-256). Daily backups, point-in-time restore within 7 days.

Infrastructure

Hosted on AWS Mumbai (ap-south-1) for data residency. Cloudflare WAF + DDoS mitigation at the edge.

Subprocessors

Service providers we share limited personal data with — all bound by data processing agreements:

Razorpay

India

Payment processing (PCI DSS Level 1)

Payment metadata only — no card numbers ever stored by us

Resend

USA (SOC 2 certified)

Transactional email delivery

Recipient email + message content

MongoDB Atlas

AWS Mumbai (ap-south-1)

Primary database hosting

All operational data — encrypted at rest

Cloudflare

Global edge

CDN, WAF, DDoS protection

Request metadata — IP, user agent, URLs (TLS-terminated)

Sentry (optional)

USA

Error tracking — opt-in only

Stack traces with PII scrubbed at source

Vulnerability Disclosure

Found a security issue? We follow 90-day responsible disclosure and reward valid reports with public credit (and occasionally swag).

In scope: ibclub.org and *.ibclub.org domains.
Out of scope: DoS / DDoS, social engineering, physical attacks, automated scanner output without manual verification.

security@ibclub.orgPGP key on request

Data Residency

All personal data of Indian Data Principals is processed and stored on servers located in India (AWS Mumbai, ap-south-1 region). Email delivery and error tracking use US-based subprocessors, but only with explicit consent and bound by data processing agreements.

Request SOC 2 / DPA / Custom Compliance Docs

We typically respond within 2 business days. No marketing emails — only your direct request.

Want our SOC 2 attestation, audit logs, or a custom DPA? Email trust@ibclub.org.

Your privacy matters

We use cookies for essential functionality + optional analytics. Per India's DPDP Act 2023, you choose what's stored. Privacy Policy.