Security and trust

We build and operate systems that other people depend on. These are the principles we hold ourselves to, and how this website practises them.

Principles

How we approach
security

Least privilege and MFA

Access is granted on need, reviewed regularly and protected with multi-factor authentication.

Encryption

Data is encrypted in transit, and at rest where the platform supports it. Keys are managed, not shared.

Secure development

Peer review, dependency checks and testing are part of delivery, with security requirements set at design time.

Privacy by design

We minimise the personal data we collect and design engagements with the Digital Personal Data Protection Act, 2023 in mind.

Incident readiness

Defined roles, escalation paths and recovery steps, practised through drills for managed services.

Supplier care

We choose partners and components deliberately, keep an inventory and apply updates on a schedule.

Reference frameworks

What we build
against

We design and review engagements with reference to ISO/IEC 27001 controls, the OWASP Top 10 and ASVS, the NIST Cybersecurity Framework and CIS Benchmarks.

We do not claim third-party certification on this site. If your procurement team needs a security questionnaire or current attestations, ask us and we will respond directly.

This website

Practised here first

  • HTTPS only, with HSTS.
  • A strict Content Security Policy that allows no third-party scripts.
  • No tracking, advertising or analytics cookies.
  • No third-party fonts or trackers loaded from other sites.
  • Optional browser storage only after you accept, with a one-click decline.
Report a vulnerability

Found something?
Tell us.

If you believe you have found a security issue in this website, email info@stravion.co.in with the subject “Security report” and enough detail to reproduce it. Please do not access data that is not yours, and give us reasonable time to fix the issue before sharing it. Our contact details are also published in security.txt.

Let’s talk

Need a security review?

Ask for our questionnaire response, or start with an independent audit of your own environment.

Innovate. Transform. Succeed.