Zaroori Jini OMS · Powered by Zaroori Retail
Trust & Security

Security at Zaroori Jini OMS

Last updated 1 Feb 2026

We treat your operational data — orders, inventory, credentials, and customers — with the same seriousness as your bank does its ledger. Security is engineered into every module, not bolted on.

Encryption
TLS 1.2+ in transit and AES-256 at rest for all customer data, backups, and credentials.
Tenant Isolation
Every API call is scoped to a tenant. No cross-tenant queries or joins are permitted.
Secrets Management
Marketplace, courier, and ERP tokens are encrypted at rest and rotated per policy.
Role-Based Access
Granular RBAC across users, warehouses, marketplaces, and modules.
Audit Logs
Every configuration & data change is captured in an immutable audit trail.
Continuous Monitoring
24×7 monitoring of infrastructure, application, and integration health.
Backups & DR
35-day rolling backups with tested point-in-time recovery and disaster recovery drills.
Incident Response
24/7 on-call rotation with published SLAs, RCAs, and postmortems.
Least Privilege
Zero standing production access. Break-glass access is logged and time-boxed.
Cloud Security
Hardened cloud posture — private VPCs, WAF, DDoS protection, secure image baselines.
Vulnerability Mgmt
Continuous SCA, SAST, and periodic third-party penetration tests.
Compliance-Ready
SOC-ready architecture; DPDP-aligned; GDPR-friendly data processing controls.
Reporting

Responsible Disclosure

We welcome coordinated disclosure from security researchers. Vulnerabilities can be reported confidentially and will be acknowledged within 24 hours.

Email: security@zaroorijini.com
Please include reproduction steps, impact, and any proof of concept. We do not initiate legal action against good-faith researchers who follow this policy.