We host sensitive deal flow, member networks, and payment data. Here's how we protect it — and what you can verify before you join.
Last updated 12 Feb 2026
DPDPA 2023
India compliant
bcrypt + JWT
Auth hardened
HTTPS only
TLS 1.3 enforced
30-day grace
Deletion window
Password storage
bcrypt with per-user salt + adaptive cost factor. Never logged, never returned in API responses or exports.
Authentication
JWT with HttpOnly secure cookies. Rate-limited login + password reset endpoints (slowapi). 24-hour token expiry with refresh.
Transport security
TLS 1.3 enforced. Strict-Transport-Security headers. HTTP requests auto-redirect to HTTPS.
Audit logging
Every admin action recorded with actor, target, timestamp + IP. Available on legal request.
Database
MongoDB Atlas with encryption-at-rest (AES-256). Daily backups, point-in-time restore within 7 days.
Infrastructure
Hosted on AWS Mumbai (ap-south-1) for data residency. Cloudflare WAF + DDoS mitigation at the edge.
Service providers we share limited personal data with — all bound by data processing agreements:
Razorpay
India
Payment processing (PCI DSS Level 1)
Payment metadata only — no card numbers ever stored by us
Resend
USA (SOC 2 certified)
Transactional email delivery
Recipient email + message content
MongoDB Atlas
AWS Mumbai (ap-south-1)
Primary database hosting
All operational data — encrypted at rest
Cloudflare
Global edge
CDN, WAF, DDoS protection
Request metadata — IP, user agent, URLs (TLS-terminated)
Sentry (optional)
USA
Error tracking — opt-in only
Stack traces with PII scrubbed at source
Found a security issue? We follow 90-day responsible disclosure and reward valid reports with public credit (and occasionally swag).
In scope: ibclub.org and *.ibclub.org domains.
Out of scope: DoS / DDoS, social engineering, physical attacks, automated scanner output without manual verification.
All personal data of Indian Data Principals is processed and stored on servers located in India (AWS Mumbai, ap-south-1 region). Email delivery and error tracking use US-based subprocessors, but only with explicit consent and bound by data processing agreements.
Want our SOC 2 attestation, audit logs, or a custom DPA? Email trust@ibclub.org.
We use cookies for essential functionality + optional analytics. Per India's DPDP Act 2023, you choose what's stored. Privacy Policy.