Trust & Security

Security at SanmigGRC

Engineering, monitoring and operational controls designed for BFSI, NBFC and HFC procurement.

Encryption

TLS 1.2+ in transit. At-rest encryption on managed cloud storage and database.

Identity & Access

Role-based access control with separate admin, sales and client roles. MFA on all admin accounts.

Audit Logging

Immutable audit trail on all lead and engagement records, accessible only to admins.

Secrets Management

Service credentials stored in a managed secret vault. Never embedded in source.

Incident Response

Documented runbook with SLA-bound notification. Templates aligned to DPDP breach reporting.

Vulnerability Management

Dependency scanning on every change. Critical advisories triaged within 72 hours.

Backups & DR

Continuous database backups with point-in-time recovery on the managed cloud tier.

Sub-processors

Limited to vetted, contract-bound providers for cloud, email and calendaring.

Report a vulnerability

Responsible-disclosure reports are welcome. Email sanjeev1911@gmail.com with reproduction steps. We acknowledge within two business days.