An overview of the controls protecting the platform and the data in it. Written plainly, so a procurement or IT team can assess us without a sales call.
Effective 26 July 2026 · Dryshades Private Limited · CIN U47912HR2025PTC137850
All traffic to netrecx.com and the portals is served over HTTPS with TLS. Application databases are held outside the public web root so they cannot be requested directly over the web, and are not included in application deployments.
Credentials are never stored in readable form — passwords are hashed with a modern adaptive algorithm. API keys and provider secrets are held outside the web root and are not present in the application package.
Critical actions — account approvals, verification, deletions, quotation acceptance, purchase order issue and staff sign-in — are written to an append-only audit log recording the actor, their role, the record affected, a summary of the change, the source IP and an IST timestamp.
The identity broker model means buyer and supplier data are stored in separate record sets with separate rendering paths. This is the same control described in our confidentiality policy, and it is a security boundary as much as a commercial one.
Databases are held on managed hosting with provider-level redundancy and are backed up on a rolling basis. Reference counters and transactional records are stored so that a redeployment of the application cannot reset or overwrite them.
If we become aware of a breach affecting your data, we will investigate immediately, contain it, and notify affected customers and the relevant authority as required under Indian law, with the facts as we know them and the steps we are taking.
To report a vulnerability, write to info@netrecx.com with the words "security disclosure" in the subject. We will acknowledge within two working days and will not pursue action against good-faith research that avoids privacy violations and service disruption.
We are a growing company and we would rather be accurate than impressive. We do not currently hold ISO 27001 or SOC 2 certification. If your procurement process requires either, tell us and we will be straight with you about timelines rather than imply otherwise.
Questions about this page? Write to info@netrecx.com.
Terms · Privacy · Confidentiality · Security · Cookies · Acceptable use · Disclaimer · NDA