Legal

Security Policy

How Cehpoint protects the data you give us, what we ask of you, and how to report a vulnerability.

Last updated: 5 September 2026 Applies to all Cehpoint systems

1. In transit and at rest

Every connection to Cehpoint is encrypted with TLS; we do not serve any part of the product over plain HTTP. Data at rest sits on encrypted volumes. Passwords are stored as bcrypt hashes and are never recoverable — not by you, not by us, not by anyone with database access.

2. Who can see your data

Access is limited to the people who need it to do the work, and administrative actions on accounts are logged with who did them and when. Our staff cannot read your password. Where a member of our team views verification material, that view is part of a recorded process with your name on it.

3. Holding less, on purpose

The strongest control we apply is not holding things. Uploaded documents are reduced to text and the originals discarded. Aadhaar and long card-like numbers are masked before the first write, so the full values are never in the database to be stolen. We do not store card details; card payments are handled by the payment gateway, not by us.

4. Credentials and keys

API keys and integration secrets are held in server-side configuration, never in anything sent to a browser. Third-party keys (maps, models, mail) are never exposed to client code. Keys you generate for our APIs are shown once and can be replaced by you at any time.

5. What we ask of you

Use a password you do not use anywhere else. Keep your API keys secret and rotate them if you suspect exposure. Tell us immediately if you think someone else has access to your account. If you are a firm, remove team members promptly when they leave.

6. What we will never ask you for

No one at Cehpoint will ever ask you for your password, an OTP, a card CVV, a UPI PIN or net-banking credentials — not by email, not by phone, not in chat, not during a verification call. If anyone asks, it is not us. Stop, and write to grievance@cehpoint.co.in.

7. Reporting a vulnerability

We are a security company; we would genuinely rather hear it from you. Email grievance@cehpoint.co.in with “security” in the subject with enough detail to reproduce it. We will acknowledge within 48 hours and keep you informed. Please give us reasonable time to fix it before publishing, do not access or alter data that is not yours, and do not degrade the service for anyone else. We will not pursue action against research conducted in good faith along those lines.

8. If something goes wrong

If a breach affects your personal data we will notify you and the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires, with what happened, what was affected, and what you should do. We will not wait until we have a complete picture to tell you that something has happened.

Write to grievance@cehpoint.co.in about anything in this document, or support@cehpoint.co.in for day-to-day help.

Cehpoint · West Bengal, India — registered office address available on request. Questions about this document? Email support@cehpoint.co.in. This page is provided for general information and forms part of the agreement between you and Cehpoint; it is not a substitute for independent legal advice.