Your clients trust you with their homes. Here is how we keep that trust.
KalpaNele holds drawings, photos of finished homes, payment records and staff locations. This page explains, without marketing language, how that data is kept apart and who can see it. Data is stored in India, on Google Cloud in the Mumbai region.
Isolation / Row-level security
Every firm is walled off in the database
Each firm's projects, drawings, photos, payments and team live in shared tables, but every row carries the firm it belongs to and PostgreSQL row-level security is switched on and forced for those tables.
Each request runs inside a database session that is set to the signed-in firm, with a restricted role. Even a missing filter in our own code cannot return another firm's rows; the database refuses.
Clients / Unit-level access
Clients see only their own home
A client is tied to the unit they own. The owner of Flat 202 sees Flat 202 and the shared areas of the building, and never the photos, comments, payments, issues or hidden services of any other flat.
The same check runs on every list and every single record, including file downloads, which use short-lived signed links.
Location / DPDP Act 2023
Location with consent, as the DPDP Act expects
Staff location is recorded only during a site visit, from the moment someone starts the journey until they arrive or end it. It is used for the arrival time shown to the client, for detecting arrival at the site boundary and for attendance.
Each person is asked once, in plain words, before any location is recorded, and the time of that consent is stored. There is no background tracking outside visits.
Sign-in / One-time codes
Sign-in without passwords
People sign in with a one-time code sent to their email address. Codes expire in minutes and attempts are limited. Each sign-in is a separate device session that can be ended on its own.
Secrets / AES-256-GCM
Secrets are encrypted
Payment gateway keys, email server passwords and similar secrets are encrypted with AES-256-GCM before they are stored, and the console never shows them again after saving.
Subscription payments are handled by Razorpay. Card and UPI details never reach our servers, and payments between firms and their clients do not pass through the platform at all.
Audit / Device telemetry
An audit log with device details
Every change is written to an activity log with who did it, when, and from where: web or mobile app, app version, operating system and version, device model, IP address and a request id.
When a firm reports a problem, support can trace the exact request from the exact phone, instead of guessing.
Found a problem?
If you believe you have found a security issue, write to info@modhruti.com with the details. We will confirm we have received it and keep you informed until it is fixed. Please do not access data that is not yours while testing.