Security Overview — India

Your data is safe.
We take that seriously.

Travnet is built on a security-first architecture. Every byte of your agency data is encrypted, stored in India, and protected by multiple independent layers of controls.

AES-256

Encryption at rest

AWS Mumbai

ap-south-1 region

2FA / MFA

All accounts

Zero data export

Never sold or shared

99.9% uptime SLA

Enterprise guarantee

Six layers of protection

Security isn't a feature — it's the foundation. We build every layer so your agency data is safe even if any one layer is compromised.

Encryption

Every file, record, and message stored in Travnet is encrypted at rest using AES-256. All data in transit is protected by TLS 1.3 — the same standard used by major banks.

AES-256 encryption at rest
TLS 1.3 for all data in transit
Encrypted database backups
Keys rotated every 90 days

India Data Residency

All customer data for Indian accounts is stored exclusively in AWS Mumbai (ap-south-1). Your data never crosses international boundaries — in full compliance with the IT Act and DPDP Act 2023.

AWS ap-south-1 (Mumbai)
IT Act 2000 compliant
DPDP Act 2023 ready
No cross-border data transfers

Access Control

Granular role-based permissions ensure users only see what they need. Multi-factor authentication protects every account, and single sign-on is available for enterprise teams.

Role-based access control (RBAC)
2FA / MFA on all accounts
SSO (Google, Microsoft)
Session timeout & IP allow-listing

Infrastructure Security

Our infrastructure runs on AWS with private VPCs, WAF protection, DDoS mitigation, and automated vulnerability scanning. No public database exposure — ever.

AWS WAF & Shield DDoS protection
Private VPC — no public DB endpoints
Automated vulnerability scanning
Penetration tested annually

Backups & Recovery

Automated daily backups with point-in-time recovery up to 30 days. In the unlikely event of a regional outage, your data fails over to a secondary availability zone within minutes.

Daily automated backups
30-day point-in-time recovery
Multi-AZ failover (< 2 min RTO)
99.9% uptime SLA (Enterprise)

Privacy & Compliance

We follow privacy-by-design principles. Your data is never sold, never used for advertising, and never shared with third parties without explicit consent. You own your data — period.

Data never sold or shared
DPDP Act 2023 compliant
Data export on request or cancellation
Privacy-by-design architecture

How your data flows

Every request passes through multiple security checkpoints before touching your data.

Browser / Mobile App

HTTPS / TLS 1.3 enforced

Layer 1

AWS WAF + CloudFront CDN

DDoS protection · rate limiting · geo-rules

Layer 2

Auth Gateway (JWT + 2FA)

Token validation · session management · RBAC

Layer 3

API Server (Private VPC)

Input validation · no public DB exposure

Layer 4

Encrypted Database (AWS Mumbai)

AES-256 · Multi-AZ · daily backups · India-only

Layer 5

Compliance & certifications

We adhere to recognised frameworks so you don't have to worry about regulatory risk.

IT Act 2000

Compliant with India's Information Technology Act covering data protection and electronic records.

DPDP Act 2023

Ready for India's Digital Personal Data Protection Act 2023 — consent management, data principal rights, and breach notification.

SOC 2 Type II Practices

We operate under SOC 2 security, availability, and confidentiality principles — formal certification in progress.

PCI DSS (Payment Data)

Travnet never stores card data. All payment processing is delegated to Razorpay (PCI DSS Level 1 certified).

Annual Pen Testing

Third-party penetration tests are conducted annually. Critical findings are remediated within 72 hours.

Incident Response SLA

Security incidents are triaged within 1 hour. Affected customers are notified within 72 hours of confirmed breaches.

Responsible Disclosure

Found a security vulnerability in Travnet? We appreciate responsible disclosure. Please report it privately and we commit to responding within 48 hours. We do not pursue legal action against good-faith researchers.

Security FAQs

Can Travnet employees see my agency data?

What happens to my data if I cancel?

Is my client's personal data (names, passports, etc.) safe?

Do you have a status page?

Security you can trust.
Pricing you can afford.

Start your 14-day free trial — no card required. Enterprise-grade security on every plan.

IT Act compliant DPDP Act 2023 ready India data residency