Security posture
Vyapar Genie

Security is treated as controlled access, auditability, and platform integrity.

The public posture is built around scoped sessions, role-aware access, webhook verification, audit records, file controls, and operator visibility.

Auth and sessions
Email/password login, refresh-session handling, password recovery, and secure entry flows.
Access and governance
RBAC, company-scoped access, internal admin roles, and audit visibility.
Platform integrity
Webhook verification, queue-backed jobs, file controls, and environment validation.
Public summary

This is a posture statement, not a decorative trust page.

Security pages should help a serious buyer or operator understand the discipline around access, auditability, and platform safeguards. The design stays closer to an institutional brief than a SaaS brochure.

Control areas

Three layers define the security model.

IdentityLogin, reset-password, session restoration, and protected-route behavior.
AuthorizationTenant roles, permissions, admin roles, and route-level access enforcement.
Platform controlsFiles, queues, webhooks, notifications, audit logs, and release validation.