Least privilege and MFA
Access is granted on need, reviewed regularly and protected with multi-factor authentication.
We build and operate systems that other people depend on. These are the principles we hold ourselves to, and how this website practises them.
Access is granted on need, reviewed regularly and protected with multi-factor authentication.
Data is encrypted in transit, and at rest where the platform supports it. Keys are managed, not shared.
Peer review, dependency checks and testing are part of delivery, with security requirements set at design time.
We minimise the personal data we collect and design engagements with the Digital Personal Data Protection Act, 2023 in mind.
Defined roles, escalation paths and recovery steps, practised through drills for managed services.
We choose partners and components deliberately, keep an inventory and apply updates on a schedule.
We design and review engagements with reference to ISO/IEC 27001 controls, the OWASP Top 10 and ASVS, the NIST Cybersecurity Framework and CIS Benchmarks.
We do not claim third-party certification on this site. If your procurement team needs a security questionnaire or current attestations, ask us and we will respond directly.
If you believe you have found a security issue in this website, email info@stravion.co.in with the subject “Security report” and enough detail to reproduce it. Please do not access data that is not yours, and give us reasonable time to fix the issue before sharing it. Our contact details are also published in security.txt.
Ask for our questionnaire response, or start with an independent audit of your own environment.
Your privacy, your call
We use no tracking or advertising cookies. If you agree, we save your brief and visit streak in your browser so they are here when you come back. Nothing is sent to us. Privacy Policy and Cookie Policy.