01
Identity & access
Protected application areas require authenticated access, with roles and permissions used to control what each user can do.
Security & Compliance
Prastav is designed to protect business information through controlled access, secure application practices, auditability and responsible cloud operations.
01
Protected application areas require authenticated access, with roles and permissions used to control what each user can do.
02
Business information is handled through authorised application workflows and protected service-side controls rather than exposed through the public website.
03
Production configuration, secrets, deployment controls, logging and monitoring are handled separately from public website content.
04
Relevant administrative and application activity is recorded to support traceability, review and investigation.
Prastav uses authenticated access, workspace-aware controls and permission-based authorisation to help keep business information available only to users who should have access to it.
Protected areas of Prastav require an authenticated user session before workspace information can be accessed.
Role-based permissions help administrators control which modules and actions are available to individual users.
Access decisions can be tied to defined roles and permissions rather than relying on broad, all-or-nothing user access.
Prastav supports secure authentication and verification flows, including additional verification mechanisms where enabled for the account or environment.
Data security
Prastav may hold customer and contact information, products and services, pricing, proposal content, documents, site-visit information, follow-up activity and workspace configuration. Access to that information is governed through authenticated workspace access and the permissions available to the user.
The platform is hosted on Microsoft Azure and uses managed cloud infrastructure and protected service-side configuration to support secure operation without placing sensitive infrastructure details in the public website.
Cloud platform
Microsoft Azure
Cloud infrastructure is configured and operated separately from public-facing website content.
Sensitive application configuration and service credentials are not intended to be embedded in public static pages or client-side website code.
Operational controls are designed so that application data is accessed through authorised services and workflows.
Compliance & Governance
Prastav includes practical controls that help organisations govern who can access business information, define what users are allowed to do and maintain traceability around relevant activity.
Maintain traceable records of relevant activity so administrators can review important actions, investigate issues and understand when recorded changes or events occurred.
Access to workspace information is tied to authenticated users and the permissions assigned to them, helping limit business information to the people who are meant to use it.
Define what users can view, create, edit, manage or administer according to their responsibilities, rather than giving every user the same level of access.
Use roles to apply consistent permission sets across users, making access easier to administer and review as teams and responsibilities change.
Payments
Prastav uses Razorpay as its payment gateway for supported subscription payments. Payment processing is handled through Razorpay's payment environment rather than through the public marketing website.
The public website does not act as the system of record for payment credentials, subscription activation or final billing state. Authoritative billing and subscription actions are handled through Prastav's authenticated application and backend services.
Learn more about RazorpaySecurity is maintained through repeated operational and development practices rather than a one-time configuration exercise.
Security considerations are included in application design, authentication, authorisation and deployment work.
Administrative and user access controls are reviewed and adjusted as platform requirements evolve.
Application dependencies, platform components and production configuration are maintained as part of normal operations.
Operational and security-relevant events are logged and monitored where appropriate to support investigation and service reliability.
Reported or detected issues are investigated using the available application, audit and operational evidence.
Confirmed security weaknesses are prioritised for correction based on their impact, exploitability and relevance to the platform.
Found a security issue or have a security concern?
Please include enough information for us to understand the issue, reproduce it where appropriate, and contact you if additional details are required.
Security contact
The Chief Security Officer PRASTAV TECHNOLOGIES (OPC) PRIVATE LIMITED Survey No. 258/1, Sasalapura, Honniganahalli Post, Sathanur Hobli, Kanakapura Taluk, Bengaluru South – 562126, Karnataka, India. Email: support@prastav.io