Security & Trust

Your data, protected by design

Security and privacy aren't add-ons at Verdeshell — every control on this page is built into the platform, aligned with GDPR, India's DPDP Act and ISO 27001 control practices.

Encryption at rest

Sensitive health and financial fields are encrypted in the database — never stored in plain text.

Encryption in transit

HTTPS/HSTS everywhere. File downloads use short-lived, access-controlled links rather than public URLs.

Row-level tenant isolation

Postgres row-level security enforces every query — one organization can never read another's data, even under an application bug.

Two-factor authentication

Optional TOTP 2FA on every account, plus rotating refresh tokens and the ability to revoke individual sessions.

Role-based access control

Owner, manager, executive, staff and viewer roles, enforced per organization and (on paid tiers) per individual module.

GDPR & DPDP alignment

Data export and erasure (DSAR), consent capture and configurable retention are built into the platform, not bolted on.

Audit logging

Sensitive actions are recorded to an audit trail you can review — who did what, and when.

India-hosted by default

Data is primarily stored and processed on AWS in Mumbai (ap-south-1).

Frequently Asked

Security & compliance questions

Is Verdeshell CRM GDPR compliant?

Verdeshell's data handling is aligned with GDPR: we support data subject access requests (export and erasure), capture and record consent, and enforce configurable data retention. Our Data Processing Agreement sets out the specific commitments we make as a data processor.

Is Verdeshell CRM compliant with India's DPDP Act?

Yes — our privacy practices, consent handling and grievance-redressal process are built around the Digital Personal Data Protection Act, 2023, alongside GDPR, since most of our customer base and hosting is India-based.

Where is my data hosted?

Primarily on Amazon Web Services in Mumbai, India (ap-south-1). Where data is transferred outside India or the EEA, we rely on Standard Contractual Clauses or an equivalent transfer mechanism — see our Data Processing Agreement for the full sub-processor list.

Is my organization's data isolated from other customers?

Yes. Verdeshell is multi-tenant, and every database query is scoped by Postgres row-level security tied to your organization — a defence that holds even if an application-layer check is missed, not just an application-level filter.

Do you support two-factor authentication?

Yes, TOTP-based 2FA is available on every account (web and mobile), alongside rotating refresh tokens and the ability to see and revoke individual active sessions.

Is sensitive data (like health records in the Nutrition module) encrypted?

Yes. Sensitive fields — health information, financial data and similar — are encrypted at the database column level, not stored as plain text, and are never included in searchable/indexed columns.

Can I export or delete my organization's data?

Yes. Data subject access requests (export and erasure) are a built-in capability across every module, not a manual process handled by support.

What happens to my data if I cancel my subscription?

You can export your data for up to 90 days after cancellation or termination. After that window, data is permanently deleted except where the law requires us to retain it — see our Refund & Cancellation Policy and Data Processing Agreement.

Do you notify customers of a data breach?

Yes — our Data Processing Agreement commits to notifying affected customers without undue delay, and within 72 hours of becoming aware of a breach likely to affect personal data.

Read the full detail in our Privacy Policy, Data Processing Agreement and Acceptable Use Policy.

Have a security questionnaire to fill out?

Our team can walk your security or procurement team through the details.