Security & trust
Trust at Auditaar.
Auditaar audits public websites from a URL, with no access to your servers, analytics or accounts. This page sets out how the service itself is secured, the little data it holds, and how to reach the security contact.
What protects your data
Security built into the service.
The data Auditaar holds
- Account and order data: your name and email, the URLs you submit, the reports Auditaar generates, and a record of each payment (no card numbers).
- Usage data: server logs and privacy-respecting analytics, loaded only after you accept analytics cookies.
- No access to your site's servers, analytics or private accounts. Auditaar reads only what is public.
Encryption
- All traffic is served over TLS 1.2 and 1.3.
- Off-site backups are encrypted before they leave the server, then stored on Cloudflare R2.
- Passwords are stored as bcrypt hashes, never in plain text.
Payment security
- Payments run through Razorpay: PCI-DSS Level 1, ISO 27001 certified and RBI-regulated.
- Card details go straight to Razorpay's secure checkout. Auditaar never sees or stores your card number.
- Every payment is encrypted over TLS.
Email authentication
- SPF, DKIM and DMARC are published, with DMARC set to reject.
- The DMARC policy asks receiving mail servers to reject messages that fail authentication for auditaar.com, which makes the domain harder to spoof.
Infrastructure
- Hosted on ISO/IEC 27001-certified infrastructure.
- Server access is SSH key-only, with root login and password login disabled.
- A host firewall and automatic security patching are in place.
Accounts and access
- Sign in with email and password (rate-limited against guessing) or with Google or LinkedIn.
- Administrative access is limited to authorized Auditaar personnel by role.
Backups and recovery
- Backups run automatically every night, encrypted before they leave the server.
- They are stored off-site on Cloudflare R2 and kept on a rolling retention window.
- Restores are tested, so the data can actually be recovered.
GDPR compliance
- A published Privacy Policy covers what is collected, why, and for how long.
- A Data Processing Agreement and EU Standard Contractual Clauses are available on request.
- Cookie consent is denied by default via Google Consent Mode v2.
Assurance and compliance
Assurance you can verify.
Auditaar's security and privacy controls are documented in the Cloud Security Alliance CAIQ and listed on the public STAR Registry.
CSA STAR Level 1 self-assessmentYour data
What Auditaar keeps, and for how long.
- Audit reports and dashboard access are removed after six months, so download the report within that window to keep it; a minimal score record is retained.
- You can request deletion of your account and all associated data at any time.
- Auditaar does not sell personal data, and shares it only with the service providers needed to run an audit.
- Full detail is in the Privacy Policy, Terms of Service and Refund Policy.
Have a question or a vulnerability to report? Email info@auditaar.com. For a security report, include the affected URL and the steps to reproduce it.





