Encrypted & hashed
Passwords are stored with salted PBKDF2-SHA256. API keys are stored only as hashes — never in plaintext.
Secure by default
Strict Content-Security-Policy, CSRF protection on every write, HttpOnly + SameSite cookies and path-traversal guards.
Access control
Role-based access separates admins from users, with a full audit trail of sensitive actions.
Data sovereignty
Offline-first and self-hostable, so your data stays in your environment. Built around India's DPDP Act.
Rate limited
Sensitive endpoints are rate-limited to blunt brute-force and abuse.
Durable storage
SQLite locally or Neon PostgreSQL in production, with pooled connections for reliability.
Built for India's DPDP Act
Data minimisation, consent, the right to access and erase, and clear grievance handling — designed in from the start. Read our privacy notice.