Trust
Security & data protection
You're trusting us with your shipments and your customers' COD cash. Here's exactly how we protect both — capabilities we can show today, and certifications we'll publish the moment they're earned.
Encrypted in transit & at rest
TLS everywhere; sensitive data encrypted at rest.
Data residency in India
Your shipment and COD data stays in-region.
GST-compliant billing
Compliant invoices, credit notes and reports out of the box.
Export & delete anytime
Full data-export APIs and deletion on request — your data is yours.
Our practices, in plain language
Encryption
TLS for all data in transit; sensitive fields encrypted at rest. Secrets are stored in a managed vault, never in code.
Data residency in India
Shipment, buyer and COD data is stored in-region, consistent with Indian data-handling expectations.
Access control
Role-based access with least privilege, audited actions (every model is audit-logged), and scoped API keys per environment.
Key isolation
Separate sk_test_ and sk_live_ keys; sandbox traffic can never touch production. Rotate or revoke instantly.
Signed webhooks
Every webhook is HMAC-signed so you can verify authenticity, with retries, a dead-letter queue and replay.
Your data is yours
Full export APIs and deletion on request. No lock-in, no export friction — leaving is a right, not a negotiation.
See our SLA, status page and trust center for more.
Frequently asked questions
In-region in India. Your shipment, buyer and COD data stays within the country's data boundary.
COD movements are recorded on a double-entry ledger with every debit tied to a shipment and reason code. Remittance is D+2 as standard and fully auditable.
We build to those controls and will publish certifications here once formally audited. We'd rather show the practices honestly today than claim a badge we haven't earned.
Email our security contact and we'll acknowledge quickly. We welcome responsible disclosure and won't pursue good-faith researchers.