Plain English Verified

Security

Last updated: February 25, 2026

Security and privacy are built into BimaHaq by design. This page describes the controls we have in place today and the programme we are building as we grow. We aim to be accurate — we describe what we actually do, and flag what is a commitment or a work in progress.

Regulatory alignment

We align our practices with the IRDAI Information and Cyber Security Guidelines, 2023 and BIS IS 19493:2025, and we are working toward ISO/IEC 27001:2022. We are aligned with these frameworks; we are not yet independently certified, and we will say so here when that changes.

Technical controls in place

Passwords are hashed with bcrypt and never stored in plain text. Access uses short-lived, signed tokens (with separate refresh, magic-link, verification, and password-reset tokens) and sessions can be revoked server-side per device. Uploads are validated by server-side content sniffing against an allow-list of file types with a size limit, and private documents are served only through short-lived signed links. We rate-limit sensitive endpoints, allow only an explicit list of origins (no wildcards) with secure, same-site cookies, and audit-log security-relevant actions (sign-in, consent, data requests, case changes).

Encryption and hosting

Traffic is encrypted in transit over HTTPS/TLS, and our database is encrypted at rest at the platform layer (MongoDB Atlas). Hosting is configured in India, in line with IRDAI data-localisation principles; documents are stored on our own servers by default. Our error monitoring is configured never to receive personal data.

Access and operational controls

Access to personal data is limited to those who need it, on a least-privilege basis, and is logged. As we grow, our programme adds formal, documented controls — background checks for staff who handle personal data, mandatory security training, change management, backup and disaster-recovery testing, and independent penetration testing. We will describe these as 'in place' here only once they are.

Breach response

We report cyber-security incidents to CERT-In within 6 hours of becoming aware of them, as the CERT-In Directions (2022) require. We also notify affected individuals and the Data Protection Board of India of personal-data breaches without undue delay, as the DPDP Act and its Rules require.

Report a vulnerability

If you find a security issue, email security@bimahaq.com with the details. We respond within 48 hours and will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable chance to fix the issue before disclosing it.

Questions about this page?

Write to info@bimahaq.com. We respond within one working day.