SHUBHRA IRP holds a jeweller’s most sensitive business records, so security is part of how the product is built, not a layer added afterwards. This page is a plain-language summary of the practices we follow.
Encryption in transit
All traffic to this website and to SHUBHRA IRP travels over HTTPS.
Encryption at rest for sensitive identifiers
Aadhaar numbers collected during KYC are encrypted before they are stored. Screens that display a saved Aadhaar show only the last four digits; the full number is decrypted only for a specific, permission-checked action.
Private file storage
Identity documents, payment proofs and signed agreements are kept in a private storage bucket with no public access. Every time one of these files is viewed, we mint a short-lived, single-purpose link — valid for minutes, never persisted, and expired automatically.
Role-based access
Access inside our team follows role-based permissions: an employee’s role determines what they can see and do. Sensitive actions — such as editing a signed agreement’s text or the company’s own payment details — are restricted to admin roles specifically.
Payments
We never see or store your card, UPI PIN or net-banking credentials. Payments are collected directly by Razorpay, a licensed payment aggregator; our servers only receive a payment confirmation, verified with a cryptographic signature, once Razorpay has processed it.
Electronic signatures
Agreements that require an Aadhaar-based digital signature are signed through SignYu, powered by eMudhra, a Controller of Certifying Authorities (CCA)-licensed Electronic Signature Provider. Every signed document carries a verifiable audit trail — signer, timestamp and document hash.
Account access
SHUBHRA IRP accounts are protected by authenticated, session-based login. Each shop’s data is isolated from every other shop’s, at both the database and application level.
Responsible disclosure
If you believe you’ve found a security issue with our website or product, email contact@shubhrajewels.com with details. We take reports seriously and will respond.
What this page is not
We do not hold a specific security certification, such as ISO 27001 or SOC 2, today. This page is a description of our current practices, not a certification or compliance claim, current as of the date at the top.