Encryption & residency
AES-256 at rest, TLS 1.2+ in transit, India-hosted by default with customer-managed key options.
Unbeatable security is a promise we make on the homepage. This is what stands behind it.
AES-256 at rest, TLS 1.2+ in transit, India-hosted by default with customer-managed key options.
SSO (SAML/OIDC), MFA, role-based access, least privilege and full session logging.
ISO 27001 aligned controls; SOC 2 Type II programme; annual VAPT by CERT-In empanelled auditors. [Confirm current status]
Built for regulated lenders: outsourcing guidelines, data localisation, audit trails and regulatory reporting.
Multi-AZ deployment, RPO 15 min / RTO 1 hr targets, tested DR runbooks.
Threat modelling, dependency scanning, code review and staged releases.
If you believe you have found a vulnerability in a GTFHUB system, email security@gtfhub.com. We acknowledge within 2 business days and do not pursue good-faith researchers.
A current list of infrastructure and service providers is available on request under NDA.
Policies, pen-test summaries and architecture diagrams under NDA.
Request security packHigh value transactions deserve a conversation. Tell us what you are trying to do and we will route you to the right desk.