Skip to main content

Security & Compliance

Security is part of how Prastav is built.

Prastav is designed to protect business information through controlled access, secure application practices, auditability and responsible cloud operations.

Data protection Access control Auditability Operational safeguards

Protect the data. Control the access. Keep activity accountable.

01

Identity & access

Protected application areas require authenticated access, with roles and permissions used to control what each user can do.

02

Data protection

Business information is handled through authorised application workflows and protected service-side controls rather than exposed through the public website.

03

Operational security

Production configuration, secrets, deployment controls, logging and monitoring are handled separately from public website content.

04

Auditability

Relevant administrative and application activity is recorded to support traceability, review and investigation.

Access belongs to the right user and the right workspace.

Prastav uses authenticated access, workspace-aware controls and permission-based authorisation to help keep business information available only to users who should have access to it.

Authenticated application access

Protected areas of Prastav require an authenticated user session before workspace information can be accessed.

Roles & permissions

Role-based permissions help administrators control which modules and actions are available to individual users.

Role-Based Access Control (RBAC)

Access decisions can be tied to defined roles and permissions rather than relying on broad, all-or-nothing user access.

Verification & account security

Prastav supports secure authentication and verification flows, including additional verification mechanisms where enabled for the account or environment.

Data security

Business information stays protected throughout the application workflow.

Prastav may hold customer and contact information, products and services, pricing, proposal content, documents, site-visit information, follow-up activity and workspace configuration. Access to that information is governed through authenticated workspace access and the permissions available to the user.

The platform is hosted on Microsoft Azure and uses managed cloud infrastructure and protected service-side configuration to support secure operation without placing sensitive infrastructure details in the public website.

Cloud platform

Microsoft Azure

Cloud infrastructure is configured and operated separately from public-facing website content.

Sensitive application configuration and service credentials are not intended to be embedded in public static pages or client-side website code.

Operational controls are designed so that application data is accessed through authorised services and workflows.

Compliance & Governance

Controls that help you manage access, accountability and auditability.

Prastav includes practical controls that help organisations govern who can access business information, define what users are allowed to do and maintain traceability around relevant activity.

Audit Logs

Maintain traceable records of relevant activity so administrators can review important actions, investigate issues and understand when recorded changes or events occurred.

User Access Controls

Access to workspace information is tied to authenticated users and the permissions assigned to them, helping limit business information to the people who are meant to use it.

Roles & Permissions

Define what users can view, create, edit, manage or administer according to their responsibilities, rather than giving every user the same level of access.

Role-Based Access Control (RBAC)

Use roles to apply consistent permission sets across users, making access easier to administer and review as teams and responsibilities change.

These controls support internal governance, access management and audit readiness. Formal certifications or attestations will be published only when they have been completed, are applicable to the relevant scope and can be verified.

Payments

Payments are processed securely through Razorpay.

Prastav uses Razorpay as its payment gateway for supported subscription payments. Payment processing is handled through Razorpay's payment environment rather than through the public marketing website.

The public website does not act as the system of record for payment credentials, subscription activation or final billing state. Authoritative billing and subscription actions are handled through Prastav's authenticated application and backend services.

Learn more about Razorpay

Security is an ongoing process.

Security is maintained through repeated operational and development practices rather than a one-time configuration exercise.

Secure development

Security considerations are included in application design, authentication, authorisation and deployment work.

Access review

Administrative and user access controls are reviewed and adjusted as platform requirements evolve.

Platform updates

Application dependencies, platform components and production configuration are maintained as part of normal operations.

Logging & monitoring

Operational and security-relevant events are logged and monitored where appropriate to support investigation and service reliability.

Incident investigation

Reported or detected issues are investigated using the available application, audit and operational evidence.

Remediation

Confirmed security weaknesses are prioritised for correction based on their impact, exploitability and relevance to the platform.

Found a security issue or have a security concern?

Tell us directly.

Please include enough information for us to understand the issue, reproduce it where appropriate, and contact you if additional details are required.

Security contact

The Chief Security Officer PRASTAV TECHNOLOGIES (OPC) PRIVATE LIMITED Survey No. 258/1, Sasalapura, Honniganahalli Post, Sathanur Hobli, Kanakapura Taluk, Bengaluru South – 562126, Karnataka, India. Email: support@prastav.io