Last updated: 01 Aug 2026

Security Policy

Security controls for web, mobile, data and integrations.

Access control

Role-based access separates super admin, tenant admin and tenant staff. Tenant data must remain tenant-scoped.

Secrets

API keys, Google tokens, SMTP credentials and payment credentials are stored server-side and are not hardcoded in mobile apps.

Transport and browser safety

Siwach runs on HTTPS with secure cookies, CSRF protection, strong session configuration and security headers.

Auditability

Approval actions, deletion requests, automation runs, mail sends and sensitive admin actions should be logged for accountability.

Incident response

Suspected data incidents should be triaged, contained, investigated, documented and notified according to applicable law and platform requirements.

Contact and updates

For privacy, deletion, security, billing or compliance requests, use the Data Rights page. Siwach keeps these policies updated whenever app behavior, SDKs, vendors, permissions or data processing practices change.