Security at Disha One

Your financial data deserves the highest level of protection. We employ bank-grade security measures to keep your information safe.

How We Protect Your Data

End-to-End Encryption

All data is encrypted using TLS 1.3 during transit and AES-256 at rest. Your financial data is never stored in plain text.

Secure Infrastructure

Our servers are hosted in SOC 2 Type II certified data centers with 24/7 monitoring, DDoS protection, and regular security audits.

Zero-Knowledge Architecture

We never store your banking credentials. All bank authentication happens directly with your financial institution.

Access Controls

Strict role-based access controls ensure that only authorized personnel can access systems, with all access logged and audited.

Regular Audits

We conduct regular penetration testing and security audits by independent third-party security firms.

Compliance

We comply with GDPR, PSD2, and regional data protection regulations, following industry best practices for financial data handling.

Certifications & Compliance

  • ISO 27001 Information Security
  • SOC 2 Type II Compliance
  • GDPR Compliant
  • PSD2 Compliant
  • PCI DSS Certified

Our Security Practices

Secure Development

  • Secure coding practices following OWASP guidelines
  • Regular code reviews and static analysis
  • Dependency vulnerability scanning
  • Automated security testing in CI/CD pipeline

Data Protection

  • Data minimization - we only collect what's necessary
  • Automatic data purging based on retention policies
  • Encrypted backups with geo-redundancy
  • Secure key management using HSMs

Incident Response

  • 24/7 security monitoring and alerting
  • Documented incident response procedures
  • Regular disaster recovery drills
  • Transparent breach notification policy

Open Banking Security

When you connect your bank through Open Banking:

  • Your bank credentials are never shared with us
  • Authentication happens directly with your bank
  • Data is encrypted end-to-end during transfer
  • You can revoke access at any time

Report a Security Vulnerability

We take security seriously. If you discover a vulnerability, please report it responsibly. We appreciate your help in keeping Disha One secure.

Email: security@dishaone.com