Trust

Security at BizlumoAI

Your employees' personal data is on our servers. Here's exactly how we protect it — no marketing fluff, just the technical specifics.

Last updated: 15 May 2026
The summary All data stored in India. Encrypted in transit. Face recognition for attendance; biometric and photo data kept access-controlled. Razorpay handles payments (we never see card data). Automated daily backups, 30-day retention. Responsible disclosure rewards available.

Infrastructure

Our servers are located in India, and no customer data leaves Indian jurisdiction.

Specifically:

Encryption

In transit

All connections use modern TLS encryption, with HTTP automatically redirected to HTTPS. Certificates are issued by a trusted authority and renewed automatically.

Data at rest

Customer data is stored on servers in India with restricted access. Payment card details never touch our servers (handled by Razorpay); biometric and photo data is kept access-controlled.

Sensitive fields

Access to sensitive fields (Aadhaar, PAN, bank account details) is restricted to authorized roles and is not exposed through general employee-facing views.

Access control

Customer side

Internal access

Face data — how it works

We use face recognition for attendance. Biometric face data is treated as sensitive personal information.

What we store: attendance check-in / check-out photos, employee profile pictures, and admin-uploaded ID documents. These are stored on our servers in India, are access-controlled, and are visible only to authorised admins. Access is restricted, and data is deleted when an account is closed (subject to any legally required retention).

Liveness detection runs at recognition time to prevent photo/video spoofing — you can't fool the kiosk by holding up a phone screen with someone's photo.

Payments

All payments are processed through Razorpay, which is PCI-DSS Level 1 certified. We never see your card data — Razorpay handles tokenisation and we only receive a payment status callback.

We store the Razorpay subscription ID and the last 4 digits of your card (for display purposes only). No CVV, no full card number, no expiry date.

Monitoring & alerting

Backups & disaster recovery

Incident response

If a security incident occurs that affects customer data, our incident response process is to:

  1. Begin investigation immediately upon detection and work to contain the incident as quickly as practicable
  2. Notify affected customers via email within the timelines required by applicable law (within 72 hours of becoming aware of a personal data breach, per DPDP Act 2023)
  3. File required notifications with the Data Protection Board of India and other applicable authorities
  4. For significant incidents, share a post-incident summary with affected customers covering timeline, root cause, and corrective actions taken

Subscribe to security notifications by emailing security-list@bizlumoai.com with subject "subscribe". You'll get notified of any security advisory we publish (we hope this list stays empty).

Compliance & certifications

We're a young company. We don't have certifications that take 18+ months to achieve. We do have the underlying controls in place; certifications will follow as we scale.

Responsible disclosure

Found a security vulnerability? Report it to security@bizlumoai.com. We aim to:

We don't run a formal bug bounty program, but we do reward valid critical and high-severity findings at our discretion — typically with BizlumoAI account credits, swag, or cash for high-impact reports. Rewards depend on severity, exploit quality, and report clarity. Tell us about your finding first; we'll discuss recognition after triage.

Out of scope


Need a copy of this page as a PDF for vendor security review? Email security@bizlumoai.com — we'll send a signed PDF version with our security questionnaire.

Ready to secure your HR data?

Start your 14-day free trial. No credit card required.

Start free trial