Trust Centre

How we secure our platform and your data.

What we do, what we do not do, and how you can check it yourself. Updated as our practices change; last reviewed 3 October 2026.

Platform security

  • Edge protection. arventiqlabs.com and our API are served through Cloudflare with TLS 1.2+ only, HSTS, DNSSEC and CAA records that restrict which certificate authorities may issue for our domain.
  • Browser hardening. Every page ships an enforced Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, a strict Referrer-Policy and a Permissions-Policy that disables camera, microphone and location.
  • Administrative access. Admin sessions use hashed, HttpOnly, Secure cookies that expire after eight hours. Sign-in is rate-limited and every state-changing admin request is checked for origin.
  • Abuse controls. Public forms and tools are rate-limited per network and protected by Cloudflare Turnstile. Only a one-way hash of your IP address is stored, for 24 hours.
  • Payments. Event payments are processed by Razorpay. Card and UPI details never touch our servers; we verify each payment with a signed callback.

Data handling

  • Hosting. Website data is stored in Cloudflare D1 and email is delivered through Resend. Product data for FortifyHub and our other platforms is hosted in India.
  • Free tools. Attachments and passwords are processed in your browser and never uploaded. For breach checks we send five characters of a hash. Links and IP addresses you check are fetched from our servers so the target never sees you.
  • What we keep. Contact-form enquiries, event registrations, job applications, newsletter subscriptions (double opt-in) and scam reports, for as long as needed to act on them. See the privacy policy for details and your rights under the DPDP Act 2023.
  • What we do not do. We do not sell data, run third-party advertising trackers or embed analytics that profile visitors across sites.

Email authentication

Mail from arventiqlabs.com is authenticated with SPF, DKIM and a DMARC policy of quarantine, moving to reject. If you receive an email claiming to be from us that fails these checks, it is not from us: report it.

Vulnerability disclosure

We welcome reports from security researchers and respond within three business days. Read the disclosure policy or fetch /.well-known/security.txt.

Check it yourself

Everything above is verifiable from the outside. Run our own domain security check on arventiqlabs.com: it reads the live DNS, email and header configuration and says what it found. The website and tools are open source on GitHub, so the code behind every statement here can be read.

Contacts

Security: [email protected] (subject “Security”). Privacy and data requests: [email protected]. Registered office: BMS Innovation Centre, Yelahanka, Bengaluru, Karnataka 560119. Arventiq Labs LLP, incorporated 17 September 2026.