Your data is safe.
We take that seriously.
Travnet is built on a security-first architecture. Every byte of your agency data is encrypted, stored in India, and protected by multiple independent layers of controls.
AES-256
Encryption at rest
AWS Mumbai
ap-south-1 region
2FA / MFA
All accounts
Zero data export
Never sold or shared
99.9% uptime SLA
Enterprise guarantee
Six layers of protection
Security isn't a feature — it's the foundation. We build every layer so your agency data is safe even if any one layer is compromised.
Encryption
Every file, record, and message stored in Travnet is encrypted at rest using AES-256. All data in transit is protected by TLS 1.3 — the same standard used by major banks.
India Data Residency
All customer data for Indian accounts is stored exclusively in AWS Mumbai (ap-south-1). Your data never crosses international boundaries — in full compliance with the IT Act and DPDP Act 2023.
Access Control
Granular role-based permissions ensure users only see what they need. Multi-factor authentication protects every account, and single sign-on is available for enterprise teams.
Infrastructure Security
Our infrastructure runs on AWS with private VPCs, WAF protection, DDoS mitigation, and automated vulnerability scanning. No public database exposure — ever.
Backups & Recovery
Automated daily backups with point-in-time recovery up to 30 days. In the unlikely event of a regional outage, your data fails over to a secondary availability zone within minutes.
Privacy & Compliance
We follow privacy-by-design principles. Your data is never sold, never used for advertising, and never shared with third parties without explicit consent. You own your data — period.
How your data flows
Every request passes through multiple security checkpoints before touching your data.
Browser / Mobile App
HTTPS / TLS 1.3 enforced
AWS WAF + CloudFront CDN
DDoS protection · rate limiting · geo-rules
Auth Gateway (JWT + 2FA)
Token validation · session management · RBAC
API Server (Private VPC)
Input validation · no public DB exposure
Encrypted Database (AWS Mumbai)
AES-256 · Multi-AZ · daily backups · India-only
Compliance & certifications
We adhere to recognised frameworks so you don't have to worry about regulatory risk.
IT Act 2000
Compliant with India's Information Technology Act covering data protection and electronic records.
DPDP Act 2023
Ready for India's Digital Personal Data Protection Act 2023 — consent management, data principal rights, and breach notification.
SOC 2 Type II Practices
We operate under SOC 2 security, availability, and confidentiality principles — formal certification in progress.
PCI DSS (Payment Data)
Travnet never stores card data. All payment processing is delegated to Razorpay (PCI DSS Level 1 certified).
Annual Pen Testing
Third-party penetration tests are conducted annually. Critical findings are remediated within 72 hours.
Incident Response SLA
Security incidents are triaged within 1 hour. Affected customers are notified within 72 hours of confirmed breaches.
Responsible Disclosure
Found a security vulnerability in Travnet? We appreciate responsible disclosure. Please report it privately and we commit to responding within 48 hours. We do not pursue legal action against good-faith researchers.
Security FAQs
Can Travnet employees see my agency data?
What happens to my data if I cancel?
Is my client's personal data (names, passports, etc.) safe?
Do you have a status page?
Security you can trust.
Pricing you can afford.
Start your 14-day free trial — no card required. Enterprise-grade security on every plan.
IT Act compliant DPDP Act 2023 ready India data residency