Infrastructure
Our servers are located in India, and no customer data leaves Indian jurisdiction.
Specifically:
- Application servers: isolated, access-controlled compute in India
- Database: not publicly exposed — reachable only from the application layer over a private network interface
- Backups: automated daily backups with 30-day retention, stored with restricted access
- Static assets: only marketing pages and JS bundles are served publicly — your data is never among them
Encryption
In transit
All connections use modern TLS encryption, with HTTP automatically redirected to HTTPS. Certificates are issued by a trusted authority and renewed automatically.
Data at rest
Customer data is stored on servers in India with restricted access. Payment card details never touch our servers (handled by Razorpay); biometric and photo data is kept access-controlled.
Sensitive fields
Access to sensitive fields (Aadhaar, PAN, bank account details) is restricted to authorized roles and is not exposed through general employee-facing views.
Access control
Customer side
- Enforced password-strength requirements
- Industry-standard password hashing — we never store plaintext passwords
- Session tokens expire and are stored securely
- Granular role-based access control — HR sees payroll, department heads see only their team, finance gets reports without people-data
Internal access
- Infrastructure access is limited to authorised team members using secure authentication
- No shared accounts. No password-based SSH.
- Customer data access is logged. Engineers can only view a customer's data with explicit support ticket reference.
Face data — how it works
We use face recognition for attendance. Biometric face data is treated as sensitive personal information.
What we store: attendance check-in / check-out photos, employee profile pictures, and admin-uploaded ID documents. These are stored on our servers in India, are access-controlled, and are visible only to authorised admins. Access is restricted, and data is deleted when an account is closed (subject to any legally required retention).
Liveness detection runs at recognition time to prevent photo/video spoofing — you can't fool the kiosk by holding up a phone screen with someone's photo.
Payments
All payments are processed through Razorpay, which is PCI-DSS Level 1 certified. We never see your card data — Razorpay handles tokenisation and we only receive a payment status callback.
We store the Razorpay subscription ID and the last 4 digits of your card (for display purposes only). No CVV, no full card number, no expiry date.
Monitoring & alerting
- Application errors: Sentry alerts to engineering on-call within 60 seconds
- Infrastructure metrics: CloudWatch with PagerDuty escalation
- Database query anomalies: alert on unusual access patterns (e.g. sudden export of large data volumes)
- Repeated failed login attempts are rate-limited and temporarily blocked
- Audit logs of admin actions (60-day retention on Enterprise plan)
Backups & disaster recovery
- Automated daily database backups, 30-day retention
- Backups stored with restricted access; restored on request
- Quarterly restore-from-backup drills to verify recovery procedures
Incident response
If a security incident occurs that affects customer data, our incident response process is to:
- Begin investigation immediately upon detection and work to contain the incident as quickly as practicable
- Notify affected customers via email within the timelines required by applicable law (within 72 hours of becoming aware of a personal data breach, per DPDP Act 2023)
- File required notifications with the Data Protection Board of India and other applicable authorities
- For significant incidents, share a post-incident summary with affected customers covering timeline, root cause, and corrective actions taken
Subscribe to security notifications by emailing security-list@bizlumoai.com with subject "subscribe". You'll get notified of any security advisory we publish (we hope this list stays empty).
Compliance & certifications
- Digital Personal Data Protection Act 2023 (India): we align our practices with the Act — data is localised in India and we honour access/correction/deletion requests. A formal compliance programme is in progress.
- Information Technology Act 2000 (India): compliant with reasonable security practices under Section 43A.
- GST: Registered. GSTIN 09AARCM4870C1Z5. All invoices issued per GST regulations under HSN 998314.
We're a young company. We don't have certifications that take 18+ months to achieve. We do have the underlying controls in place; certifications will follow as we scale.
Responsible disclosure
Found a security vulnerability? Report it to security@bizlumoai.com. We aim to:
- Acknowledge your report within 48 hours
- Triage within 5 business days
- Patch critical issues as quickly as practicable — typically within 7 days for high-severity, exploitable findings
- Credit you publicly (if you wish) once the fix is deployed
We don't run a formal bug bounty program, but we do reward valid critical and high-severity findings at our discretion — typically with BizlumoAI account credits, swag, or cash for high-impact reports. Rewards depend on severity, exploit quality, and report clarity. Tell us about your finding first; we'll discuss recognition after triage.
Out of scope
- Marketing site (this site) — only the application matters
- Theoretical issues without practical exploit
- Issues requiring physical access to victim's device
- Social engineering of BizlumoAI employees
- DoS/DDoS — please don't
Need a copy of this page as a PDF for vendor security review? Email security@bizlumoai.com — we'll send a signed PDF version with our security questionnaire.