1. Our approach
Security is built into CargoYatra by design, not bolted on. We combine secure engineering practices with platform controls to protect Customer Data.
2. Access control
The platform uses role-based access control so each user only sees what their role permits. Administrative actions are recorded in audit trails.
3. Tenant isolation
CargoYatra is multi-tenant by design. Each customer’s data is logically isolated and scoped per tenant so one customer cannot access another’s data.
4. Encryption
Traffic is encrypted in transit using industry-standard TLS. Sensitive secrets, such as third-party integration credentials, are encrypted at rest.
5. Authentication
Accounts are protected with secure authentication and short-lived, app-scoped session tokens. Administrative sign-in supports additional verification.
6. Monitoring & resilience
We monitor the Service and apply updates to address security issues. We operate on reputable cloud infrastructure with backups designed to support recovery.
7. Responsible disclosure
If you believe you have found a security vulnerability, please report it to hello@lacspace.com. We appreciate responsible disclosure and will work with you to validate and address legitimate issues. Please do not access or modify data that is not yours, or degrade the Service, while testing.
Questions?
If anything here is unclear, reach our team at hello@lacspace.com.