Enterprise-grade Security

Your Data,
Protected.

Always.

Aakruti Infra RMC is built with security at its core. From encrypted databases to OTP authentication and role-based access, every layer of your RMC plant data is protected against unauthorized access, cyber threats, and data breaches.

AES-256 EncryptedOTP LoginRBAC EnforcedZero Trust APISOC 2 Infrastructure

Identity Verified — Encrypted Channel Active

Security Architecture

Multi-Layer Protection

Every request, every record, every session is guarded by multiple independent security layers.

Encrypted Data at Rest

All plant, user, and order data is encrypted using AES-256 at the database layer. No plain-text sensitive data ever stored.

OTP Authentication

All logins use one-time passwords delivered via SMS or WhatsApp. Passwords are bcrypt-hashed. No plain passwords stored.

Role-Based Access Control

Every API query checks your role. Plant Managers can only see their plant data. Clients see only their orders. Drivers see only assigned trips.

Brute Force Protection

Account is locked after 5 failed OTP attempts. Suspicious activity triggers notifications to Plant Manager and system admin.

Secure Cloud Infrastructure

Hosted on Convex cloud with SOC 2 Type II compliant infrastructure. Automatic backups, geo-redundant storage, and uptime SLAs.

Session Security

Each login generates a unique session token. Device limits enforced per plan. Remote session kick available to Plant Managers.

Data Isolation

Each RMC Plant's data is logically isolated. Cross-plant data access is architecturally impossible. No data leaks between plants.

Secure API Layer

All backend functions validate authentication and authorization before any database operation. Zero trust model at the API layer.

Threat Matrix

Known Threats & Mitigations

ThreatStatusMitigation
Unauthorized Access ProtectedOTP + session token + device limits
Data Interception ProtectedTLS 1.3 in transit, AES-256 at rest
Brute Force Attack ProtectedLockout after 5 attempts + alert
SQL Injection ProtectedParameterized queries, no raw SQL
Cross-site Scripting ProtectedReact's built-in XSS protection
Privilege Escalation ProtectedRBAC enforced server-side always
Data Flow

Encrypted End-to-End

Your DeviceOTP Verified
TLS 1.3In Transit
API GatewayRBAC Check
Cloud DBAES-256

Questions about Data Security?

Contact our team for a security briefing or to request our full data protection documentation.