Skip to main content
UUraikkal

Trust

Security

How Uraikkal protects your data.

Encryption in transit and at rest

All traffic to and from Uraikkal is encrypted in transit over TLS. Our production environment enforces this at the infrastructure level and cannot be configured to accept unencrypted or unverified connections.

Data at rest is encrypted using our infrastructure providers' standard encryption for data stored in our database.

Tenant isolation

Every customer's data is isolated at the database level using row-level security policies scoped to your organisation on every table that stores customer data — not application-layer filtering alone. This isolation is continuously verified: a dedicated automated test suite runs real integration tests against a live database on every change to confirm one organisation's data can never be read or written by another.

Authentication and MFA

Access to Uraikkal requires an authenticated account (email and password). Multi-factor authentication is on our roadmap and not yet available — if MFA is a requirement for your organisation, contact us and we'll let you know timelines.

Role-based access control

Every user is assigned a role — read-only, analyst, or admin — and every action in the product is checked server-side against that role before it's allowed. Role checks rely on server-verified session identity, not client-side trust.

Audit logging

Uraikkal logs security-relevant events — sign-ins, role changes, team membership changes, and data-affecting actions — with the acting user, organisation, action, and before/after values where applicable. Organisation admins can review this history from within the product.

Hosting and data locations

Uraikkal is built on established cloud infrastructure providers for hosting, database, and application services. If your organisation has specific data-residency requirements, contact us and we'll confirm current hosting regions for your account.

Vulnerability management, penetration testing, and incident response

Formal automated dependency/vulnerability scanning, third-party penetration testing, and a documented incident-response programme are on our roadmap and not yet in place. We take security reports seriously — if you believe you've found a vulnerability or are affected by an incident, contact our security team below and we will investigate and respond.

Reporting a vulnerability

We welcome good-faith security research against effata.in, app.effata.in, uraikkal.com, and app.uraikkal.com, and will not pursue legal action against anyone who reports a vulnerability in line with this policy.

In scope: effata.in, app.effata.in, uraikkal.com, app.uraikkal.com, and their subdomains. Out of scope: any customer, employee, or third-party account you don't own or have explicit permission to test, and any third-party service we integrate with (report those to the vendor directly).

Please don't: run automated scanners that generate high volumes of traffic, attempt denial-of-service, access or modify data that isn't yours, perform social engineering or phishing against our staff or customers, or publicly disclose a report before we've had a chance to address it.

To report, email hello@uraikkal.com with steps to reproduce, the affected URL(s), and any proof-of-concept needed to confirm the issue. We don't yet support encrypted email — please avoid including sensitive customer data in a report.

We aim to acknowledge reports within 3 business days and to keep you updated as we investigate and remediate. We'll credit researchers who ask to be credited once a fix ships, and ask that you give us reasonable time to fix an issue before disclosing it publicly.

Data retention and deletion

We retain your data for the duration of your engagement with Uraikkal. Deleting an organisation's account removes its associated data. There is currently no self-service deletion option — contact us to request deletion of your account or organisation's data, and we will action it promptly.

Security contact and DPA requests

Report a suspected vulnerability or security concern, or request a Data Processing Agreement (DPA), by emailing hello@uraikkal.com. We respond to security reports directly.