Legal
Security Practices
AgentKart implements reasonable security practices and procedures as required under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, aligned with IS/ISO/IEC 27001.
Data encryption
Sensitive data at rest is encrypted using AES-256-GCM. Documents stored in S3 use server-side encryption (SSE-S3). All data in transit between your device and our servers is protected by TLS.
Access control
User sessions are managed with HMAC-signed JSON Web Tokens (JWT) with time-bound expiry and sliding refresh. Sessions can be revoked at any time. Administrative access to production systems follows the principle of least privilege.
Network security
API endpoints are rate-limited with a fail-closed default — when limits are exceeded, requests are blocked rather than allowed through. Cross-origin resource sharing (CORS) is restricted to production origins only. Security headers are enforced via Helmet middleware.
Document security
Identity documents (Aadhaar, PAN, liveness photographs) uploaded during the AK Verified process are stored in private S3 buckets. Access is granted only through ownership-verified, time-limited signed URLs. Documents are never served publicly.
Infrastructure
All data is stored in AWS ap-south-1 (Mumbai, India). Database storage is encrypted at rest. Backups are encrypted and stored in the same region.
Incident response
If you discover a security vulnerability or have a concern about the security of your data, contact our Grievance Officer at dicson@agentkart.com. We acknowledge security reports within 24 hours and provide an initial assessment within 72 hours.
Data minimisation
We collect only the data necessary to operate the platform. Identity-verification documents are subject to automated purging after 180 days from the date of upload. For details on what data we collect and how it is used, see our Privacy Policy.
