Security
Security is foundational to how we build and operate the Service.
Phronesis AI Lab Private Limited builds Social Media Digital Marketer ("the Service") with security as a first-class concern. This page summarises our security posture. For legal detail see our Privacy Policy and Data Processing Addendum.
Infrastructure and hosting
The Service runs on Cloudflare's global infrastructure, where customer data is stored and served. Cloudflare provides network-edge security, DDoS protection, and a globally distributed platform. We use managed, hardened services and infrastructure-as-code to keep configuration consistent and auditable.
Encryption
- In transit: all connections use TLS. HTTP requests are redirected to HTTPS.
- At rest: data stored on our infrastructure is encrypted at rest.
- Secrets and tokens: connected-account OAuth tokens and other secrets are stored using managed secret storage with restricted access.
Access control
- Least-privilege access to production systems, granted on a need-to-know basis.
- Strong authentication for administrative access, including multi-factor authentication.
- Audit logging of access to sensitive systems.
Application security
- Secure software-development practices and code review.
- Dependency monitoring and timely patching.
- Input validation and protections against common web vulnerabilities.
Payments
Payment card data is handled by our PCI-DSS-compliant processors, Razorpay (INR) and Stripe (USD). We do not store full card numbers on our systems.
Subprocessors
| Subprocessor | Purpose |
|---|---|
| Cloudflare | Hosting, storage, CDN, network security |
| Razorpay | Payments (INR) |
| Stripe | Payments (USD, global) |
| Resend | Transactional email |
| Anthropic | AI model provider |
| OpenAI | AI model provider |
A current list is maintained in our Trust Center.
Data residency
Data is stored on Cloudflare's global platform and may be processed in multiple regions. Where we transfer personal data internationally, we rely on Standard Contractual Clauses and equivalent safeguards, as described in our GDPR Statement.
Business continuity
We maintain regular backups and tested recovery procedures to protect against data loss and to restore the Service in the event of disruption.
Compliance posture
We design our practices to align with the GDPR, the UK GDPR, the Indian DPDP Act, 2023, and the CCPA/CPRA. We continue to mature our security programme as we grow.
Reporting a vulnerability
Please report security issues under our Responsible Disclosure Policy at [email protected].
Contact
Security team: [email protected].
Last updated: 20 September 2026.