Security
Trust, engineered in
This page is maintained by Pallav Burnwal to answer common questions about BillKaro's security and privacy practices. It reflects controls in use today, and is not a certification.
Encryption in transit & at rest
TLS 1.3 for every request. AES-256 for stored data and backups.
Role-based access
Granular roles, per-branch scopes, and MFA available on every account.
Audit logs
Every login, edit and export is logged with actor, IP and timestamp.
Isolated tenants
Your data is logically isolated per organisation with row-scoped queries.
Geo-redundant backups
Point-in-time backups across regions, tested regularly for restore.
Least-privilege infra
Zero-trust networking. Production access requires break-glass approval.
Shared responsibility
BillKaro secures the platform, infrastructure and services described above. As a customer, you're responsible for the accounts, credentials, roles and integrations you configure inside BillKaro. If you have specific compliance requirements or want to report a vulnerability, email us at founder.eve.ai@gmail.com.