HomeLegal

Security

Last updated August 2026

SHUBHRA IRP holds a jeweller’s most sensitive business records, so security is part of how the product is built, not a layer added afterwards. This page is a plain-language summary of the practices we follow.

Encryption in transit

All traffic to this website and to SHUBHRA IRP travels over HTTPS.

Encryption at rest for sensitive identifiers

Aadhaar numbers collected during KYC are encrypted before they are stored. Screens that display a saved Aadhaar show only the last four digits; the full number is decrypted only for a specific, permission-checked action.

Private file storage

Identity documents, payment proofs and signed agreements are kept in a private storage bucket with no public access. Every time one of these files is viewed, we mint a short-lived, single-purpose link — valid for minutes, never persisted, and expired automatically.

Role-based access

Access inside our team follows role-based permissions: an employee’s role determines what they can see and do. Sensitive actions — such as editing a signed agreement’s text or the company’s own payment details — are restricted to admin roles specifically.

Payments

We never see or store your card, UPI PIN or net-banking credentials. Payments are collected directly by Razorpay, a licensed payment aggregator; our servers only receive a payment confirmation, verified with a cryptographic signature, once Razorpay has processed it.

Electronic signatures

Agreements that require an Aadhaar-based digital signature are signed through SignYu, powered by eMudhra, a Controller of Certifying Authorities (CCA)-licensed Electronic Signature Provider. Every signed document carries a verifiable audit trail — signer, timestamp and document hash.

Account access

SHUBHRA IRP accounts are protected by authenticated, session-based login. Each shop’s data is isolated from every other shop’s, at both the database and application level.

Responsible disclosure

If you believe you’ve found a security issue with our website or product, email contact@shubhrajewels.com with details. We take reports seriously and will respond.

What this page is not

We do not hold a specific security certification, such as ISO 27001 or SOC 2, today. This page is a description of our current practices, not a certification or compliance claim, current as of the date at the top.