Security
Last Updated: August 20, 2026
Our Commitment to Security
At CartsManager, security is not an afterthought—it's fundamental to everything we do. We understand that you're trusting us with your business data, and we take that responsibility seriously. This page outlines the comprehensive security measures we employ to protect your information.
Data Encryption
Encryption in Transit
All data transmitted between your browser and our servers is encrypted using industry-standard TLS (Transport Layer Security) 1.3 protocol with 256-bit encryption. This ensures that your data cannot be intercepted or read by unauthorized parties during transmission.
Encryption at Rest
All sensitive data stored in our databases is encrypted at rest using AES-256 encryption. This includes passwords, API keys, payment information, and other sensitive business data.
Authentication & Access Control
- Multi-Factor Authentication (MFA): Optional 2FA via TOTP (Time-based One-Time Password) for enhanced account security
- Strong Password Requirements: Minimum password complexity standards enforced
- Session Management: Secure session handling with automatic timeout on inactivity
- Role-Based Access Control (RBAC): Granular permission system ensuring users only access what they need
- Failed Login Protection: Account lockout after multiple failed login attempts
- OAuth Integration: Secure third-party authentication via Google, Microsoft, and other providers
Infrastructure Security
Hosting & Network
- Hosted on enterprise-grade cloud infrastructure with 99.9% uptime SLA
- Distributed Denial of Service (DDoS) protection
- Web Application Firewall (WAF) to filter malicious traffic
- Network segmentation and isolation for different service components
- Regular security patches and updates applied to all systems
Data Centers
Our data centers feature 24/7 physical security, biometric access controls, redundant power systems, and environmental monitoring. All facilities comply with industry security standards.
Application Security
- Input Validation: All user inputs are validated and sanitized to prevent injection attacks
- Cross-Site Scripting (XSS) Protection: Content Security Policy (CSP) headers and output encoding
- Cross-Site Request Forgery (CSRF) Protection: Token-based CSRF protection on all forms
- SQL Injection Prevention: Parameterized queries and ORM usage throughout the application
- Rate Limiting: API and login rate limiting to prevent brute force attacks
- Secure Coding Practices: Development follows OWASP Top 10 security guidelines
Data Backup & Recovery
We maintain comprehensive backup and disaster recovery procedures:
- Automated daily database backups with encryption
- Continuous replication to geographically distributed locations
- Point-in-time recovery capability
- Regular disaster recovery testing and drills
- 30-day backup retention policy
Security Monitoring & Incident Response
Continuous Monitoring
- 24/7 automated security monitoring and alerting
- Real-time intrusion detection and prevention systems
- Comprehensive audit logging of all system activities
- Anomaly detection for unusual access patterns
Incident Response
We maintain a formal incident response plan with defined procedures for identifying, containing, and remediating security incidents. In the event of a data breach affecting your account, we will notify you promptly as required by applicable laws.
Compliance & Audits
We are committed to meeting industry security standards and regulatory requirements:
- Regular third-party security audits and penetration testing
- Vulnerability scanning and remediation
- Compliance with data protection regulations (GDPR, Indian IT Act)
- PCI DSS compliance for payment processing
Employee Security
- Background checks for all employees with system access
- Regular security awareness training
- Strict access control policies with principle of least privilege
- Non-disclosure agreements (NDAs) for all personnel
- Immediate access revocation upon employee departure
Third-Party Security
We carefully vet all third-party service providers to ensure they meet our security standards. All vendors undergo security assessments and are required to maintain appropriate security controls for any data they process on our behalf.
Best Practices for Users
While we implement robust security measures, you play a crucial role in keeping your account secure:
- Use a strong, unique password for your CartsManager account
- Enable two-factor authentication (2FA) for an extra layer of security
- Never share your login credentials with others
- Log out when using shared or public computers
- Keep your browser and operating system updated
- Be cautious of phishing emails claiming to be from CartsManager
- Review your account activity regularly for unauthorized access
- Use our role-based permissions to limit staff access appropriately
Reporting Security Issues
If you discover a security vulnerability or have concerns about the security of our service, please report it to us immediately. We take all security reports seriously and will investigate promptly.
Security Team Contact:
Email: security@havteq.com
Please do not publicly disclose security vulnerabilities until we have had an opportunity to address them.
Security Updates
We continuously improve our security posture and will update this page as we implement new security measures. For questions about our security practices, please contact us:
Havteq Solutions Private Limited
Email: info@havteq.com
Your security is our priority. We are committed to maintaining the highest standards of security to protect your business data. If you have any security concerns or questions, please don't hesitate to reach out to our security team.