Security

Last Updated: August 20, 2026

Our Commitment to Security

At CartsManager, security is not an afterthought—it's fundamental to everything we do. We understand that you're trusting us with your business data, and we take that responsibility seriously. This page outlines the comprehensive security measures we employ to protect your information.

Data Encryption

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using industry-standard TLS (Transport Layer Security) 1.3 protocol with 256-bit encryption. This ensures that your data cannot be intercepted or read by unauthorized parties during transmission.

Encryption at Rest

All sensitive data stored in our databases is encrypted at rest using AES-256 encryption. This includes passwords, API keys, payment information, and other sensitive business data.

Authentication & Access Control

  • Multi-Factor Authentication (MFA): Optional 2FA via TOTP (Time-based One-Time Password) for enhanced account security
  • Strong Password Requirements: Minimum password complexity standards enforced
  • Session Management: Secure session handling with automatic timeout on inactivity
  • Role-Based Access Control (RBAC): Granular permission system ensuring users only access what they need
  • Failed Login Protection: Account lockout after multiple failed login attempts
  • OAuth Integration: Secure third-party authentication via Google, Microsoft, and other providers

Infrastructure Security

Hosting & Network

  • Hosted on enterprise-grade cloud infrastructure with 99.9% uptime SLA
  • Distributed Denial of Service (DDoS) protection
  • Web Application Firewall (WAF) to filter malicious traffic
  • Network segmentation and isolation for different service components
  • Regular security patches and updates applied to all systems

Data Centers

Our data centers feature 24/7 physical security, biometric access controls, redundant power systems, and environmental monitoring. All facilities comply with industry security standards.

Application Security

  • Input Validation: All user inputs are validated and sanitized to prevent injection attacks
  • Cross-Site Scripting (XSS) Protection: Content Security Policy (CSP) headers and output encoding
  • Cross-Site Request Forgery (CSRF) Protection: Token-based CSRF protection on all forms
  • SQL Injection Prevention: Parameterized queries and ORM usage throughout the application
  • Rate Limiting: API and login rate limiting to prevent brute force attacks
  • Secure Coding Practices: Development follows OWASP Top 10 security guidelines

Data Backup & Recovery

We maintain comprehensive backup and disaster recovery procedures:

  • Automated daily database backups with encryption
  • Continuous replication to geographically distributed locations
  • Point-in-time recovery capability
  • Regular disaster recovery testing and drills
  • 30-day backup retention policy

Security Monitoring & Incident Response

Continuous Monitoring

  • 24/7 automated security monitoring and alerting
  • Real-time intrusion detection and prevention systems
  • Comprehensive audit logging of all system activities
  • Anomaly detection for unusual access patterns

Incident Response

We maintain a formal incident response plan with defined procedures for identifying, containing, and remediating security incidents. In the event of a data breach affecting your account, we will notify you promptly as required by applicable laws.

Compliance & Audits

We are committed to meeting industry security standards and regulatory requirements:

  • Regular third-party security audits and penetration testing
  • Vulnerability scanning and remediation
  • Compliance with data protection regulations (GDPR, Indian IT Act)
  • PCI DSS compliance for payment processing

Employee Security

  • Background checks for all employees with system access
  • Regular security awareness training
  • Strict access control policies with principle of least privilege
  • Non-disclosure agreements (NDAs) for all personnel
  • Immediate access revocation upon employee departure

Third-Party Security

We carefully vet all third-party service providers to ensure they meet our security standards. All vendors undergo security assessments and are required to maintain appropriate security controls for any data they process on our behalf.

Best Practices for Users

While we implement robust security measures, you play a crucial role in keeping your account secure:

  • Use a strong, unique password for your CartsManager account
  • Enable two-factor authentication (2FA) for an extra layer of security
  • Never share your login credentials with others
  • Log out when using shared or public computers
  • Keep your browser and operating system updated
  • Be cautious of phishing emails claiming to be from CartsManager
  • Review your account activity regularly for unauthorized access
  • Use our role-based permissions to limit staff access appropriately

Reporting Security Issues

If you discover a security vulnerability or have concerns about the security of our service, please report it to us immediately. We take all security reports seriously and will investigate promptly.

Security Team Contact:

Email: security@havteq.com

Please do not publicly disclose security vulnerabilities until we have had an opportunity to address them.

Security Updates

We continuously improve our security posture and will update this page as we implement new security measures. For questions about our security practices, please contact us:

Havteq Solutions Private Limited

Email: info@havteq.com

Your security is our priority. We are committed to maintaining the highest standards of security to protect your business data. If you have any security concerns or questions, please don't hesitate to reach out to our security team.