Security

Your data security is our top priority

Dribble Books is built with security-first principles. We protect your financial data with enterprise-grade encryption, Indian data residency, and continuous security monitoring.

Encryption at Every Layer

Your data is encrypted both in transit and at rest using industry-leading standards.

  • AES-256 encryption for all stored data
  • TLS 1.3 for all data in transit
  • Encrypted database backups
  • Secure key management with AWS KMS

Data Centers in India

All data is stored and processed in India, ensuring compliance with data localization requirements.

  • Primary infrastructure on AWS Mumbai (ap-south-1)
  • Disaster recovery in AWS Hyderabad (ap-south-2)
  • No data leaves Indian borders
  • 99.99% infrastructure uptime SLA

SOC 2 Compliance Roadmap

We are actively pursuing SOC 2 Type II certification to formally validate our security controls.

  • SOC 2 Type I audit scheduled for Q3 2026
  • Type II certification targeted for Q1 2027
  • Controls aligned with Trust Services Criteria
  • Annual third-party audits planned

Regular Security Audits

We continuously test and improve our security posture through internal and external assessments.

  • Quarterly penetration testing by third-party firms
  • Automated vulnerability scanning (weekly)
  • Code security reviews on every pull request
  • Dependency vulnerability monitoring with automated alerts

Additional Security Practices

Access Control

Role-based access control (RBAC), multi-factor authentication (MFA), and session management with automatic timeout for inactive sessions.

Backup & Recovery

Automated daily backups with point-in-time recovery. Backups are encrypted and stored in geographically separate locations within India.

Employee Security

Background checks for all employees, mandatory security training, least-privilege access policies, and NDA agreements for all team members.

Incident Response

Documented incident response plan with defined escalation procedures. We commit to notifying affected users within 72 hours of a confirmed breach.

Responsible Disclosure Program

We value the work of security researchers. If you discover a vulnerability in Dribble Books, we encourage you to report it responsibly. We commit to:

  • Acknowledging your report within 24 hours
  • Providing regular updates on remediation progress
  • Not pursuing legal action against good-faith researchers
  • Public credit (with your permission) after the fix is deployed
Report a Vulnerability

Trusted by thousands of Indian businesses

Join 50,000+ businesses that trust Dribble Books with their financial data. Start your free trial today.

View Pricing