Security Policy
Effective: 1 January 2026
Our commitment
We treat brewery data — recipes, production logs, sales and compliance records — as high-sensitivity. Our controls reflect that.
Controls in place
· Encryption in transit (TLS 1.2+) and at rest (AES-256).
· Row-level security scoped to your brewery on every query.
· Role-based access control with least-privilege defaults.
· Immutable audit logs on every mutation.
· Daily backups retained for 30 days; disaster-recovery tested quarterly.
· Managed cloud infrastructure with hardened baselines.
Responsible disclosure
Report suspected vulnerabilities to security@brewtally.in. Please give us reasonable time to remediate before public disclosure. We do not pursue legal action against good-faith researchers.
Incident response
If a security incident materially affects your data, we will notify affected customers without undue delay along with the facts we know, the impact, and our remediation.
Contact
security@brewtally.in · PGP available on request.
