SaaS Security & Data Integrity Standard
Review the technical encryption, cloud architecture, and organizational security audits of AccoNova.
1. Technical Encryption Standards
All communications between your browser, mobile app, and the AccoNova database are secured using TLS 1.3 (Transport Layer Security) with SHA-256 cryptographic signatures.
Stored employee profiles, salary sheets, document vault PDFs, and location records are encrypted at rest using AES-256. Sensitive information such as passwords and selfie hashes are salted and hashed using secure bcrypt algorithms.
2. Indian Cloud Infrastructure & Resiliency
AccoNova uses secure cloud infrastructure and access controls for the platform. Customers should request current infrastructure, certification and data-processing details from the AccoNova team during procurement.
Daily database backups are executed and stored in encrypted, geographically isolated backup instances to ensure instant data recovery in the event of disaster recovery operations.
3. Organizational Access Control & Audits
AccoNova operates on a Zero-Trust internal security model. Our engineering team has no access to subscriber salary documents or bank detail vault tables unless explicitly authorized in writing during support diagnostics.
We recommend all workspace administrators enable Multi-Factor Authentication (MFA/2FA) to add an extra layer of authentication security.
4. Responsible Vulnerability Reporting & Bug Bounty
We welcome reports from independent security researchers to safeguard our infrastructure. If you discover a vulnerability, please report it privately to our security team. We investigate all verified concerns and award bounties for critical system exploits.
Testing against our servers must be non-destructive and must not interfere with standard subscriber operations.
5. Security Standard Audits & Compliance Reviews
Our codebase, cloud networks, and access logs undergo annual external audits to verify compliance with industry standards. We run automated vulnerability scans weekly to prevent common web attacks.
Subscribers may request summary PDF copies of our infrastructure audit reviews under a confidentiality agreement.