Security at Saptta
Protecting HR, payroll, and financial data is central to Saptta. We combine infrastructure safeguards, application controls, and operational practices designed for Indian businesses handling sensitive employee and statutory information.
Infrastructure & encryption
- TLS 1.2+ encryption for data in transit across web and API connections
- Encryption at rest for databases and backups on cloud infrastructure
- Network segmentation and firewall controls on production environments
- Regular patching and vulnerability management on servers and dependencies
- Automated backups with tested restore procedures
Access control
- Role-based access control (RBAC) with least-privilege defaults
- Organisation-level data isolation between customer tenants
- Strong password policies and support for secure session management
- Administrative actions logged for audit and investigation
- Employee self-service limited to own records and approved workflows
Application security
- Secure development practices and code review for critical changes
- Protection against common web vulnerabilities (OWASP-aligned controls)
- Rate limiting and monitoring for abnormal authentication patterns
- Separation of production and non-production environments
Compliance & statutory data
Saptta is designed to support Indian compliance workflows including PF, ESI, TDS, GST, and related registers. Compliance outcomes depend on correct configuration and data entered by your organisation.
- Audit trails for payroll runs, approvals, and key configuration changes
- Configurable retention aligned with your policies and legal requirements
- Data export capabilities for migration and record-keeping
Privacy & data handling
We process personal data as described in our Privacy Policy. Customer organisations act as controllers for employee data; Saptta acts as a processor when handling that data on your instructions.
Incident response
We maintain procedures to detect, contain, and remediate security incidents. Affected customers will be notified without undue delay when their data is likely impacted, in line with applicable law.
Report security concerns to security@saptta.com. Please include steps to reproduce and avoid public disclosure until we have assessed the issue.
Your responsibilities
- Use strong, unique passwords and revoke access for departing staff promptly
- Configure roles and approvals appropriate to your organisation size
- Keep integration credentials (payment, biometric devices) secure
- Review audit logs and access permissions periodically
Questions? Contact legal@saptta.com or info@saptta.com · WhatsApp +91 9900007072

