Documentation

Security & Compliance

How Desi Assets protects your account, your organization, and your listings — and the standards we hold ourselves to.

Our commitment to security

Desi Assets is built for asset owners, agents, and buyers who share sensitive information — property details, documents, pricing, and contact data. Protecting that data is fundamental to how we build and operate the platform. This page describes the security and access controls in place today, how tenant data is isolated, and the compliance topics we track as the platform evolves.

Security is a shared responsibility: we secure the platform, and every organization secures its own accounts. We explain both sides below.

Authentication and account protection

We follow current authentication best practices across the platform:

  • Passwords are never stored in plaintext. They are hashed with a salted, industry-standard algorithm, so they cannot be read by anyone — including platform administrators — and are checked without ever being revealed.
  • A minimum password strength is enforced (at least 8 characters), and we encourage every user to choose a unique password and not reuse one from another site.
  • API sessions use short-lived tokens. Access tokens expire quickly (default 30 minutes), and refresh tokens are rotated and invalidated after use, limiting the window in which a stolen credential can be abused.
  • Password changes require the current password before a new one is accepted, so a compromised but unlocked session cannot silently change account credentials.

Role-based access control

Every user has a role that determines what they can see and do. Permissions are enforced on the server for every API request — hiding a button in the interface is never the only line of defense.

  • Site visitors can browse the public asset marketplace but cannot view or change any organization’s private data.
  • Tenant Users can manage their dashboard and edit the assets they are assigned to.
  • Tenant Admins manage their organization’s members, assets, and subscription — but only within their own organization.
  • Platform administrators operate the platform itself and do not reach into individual organizations’ day-to-day data.

Organization and data isolation

Desi Assets is a multi-tenant platform: each customer is a separate organization (tenant) with its own members and asset portfolio. Access is scoped by role and by tenant membership, so users of one organization cannot read or modify another organization’s listings.

The public marketplace is intentionally shared: anything you publish as a listing is visible to site visitors, while management actions (creating, editing, deleting, member administration) are available only to authorized users of the listing organization. Cross-organization write access is rejected by the server.

Listing media safeguards

Uploaded media is validated server-side before it is accepted. Files are checked against platform limits and rejected if they exceed them:

  • Images up to 10 MB each, with a maximum of 10 images per asset
  • Videos up to 50 MB each, with a maximum of 5 videos per asset
  • Only supported image and video formats are accepted

These limits protect the platform and all users from oversized or unexpected uploads while keeping listings fast to load.

Data protection in transit and at rest

  • In transit: all traffic to and from the platform is encrypted using TLS (HTTPS). [Confirm production is HTTPS-only and note any HSTS/redirect policy.]
  • At rest: databases and media storage are encrypted at rest using provider-managed encryption keys. [Confirm with your hosting provider.]
  • Backups: production data is backed up on a regular schedule with tested restore procedures. [State your cadence, retention period, and RPO/ RTO targets.]
  • Access: production infrastructure access is restricted to named, authorized engineers and audited. [Confirm your access review process.]

Compliance

Desi Assets operates in India, where asset records and personal data are subject to applicable law — including the Digital Personal Data Protection Act, 2023 (DPDP Act) once fully in force. We handle personal data (names, contact details, account credentials) only for the purpose of providing the service, and we do not sell personal data.

  • [Certifications / audits held — e.g. ISO 27001, SOC 2. Remove this item if none are held.]
  • [Add your data-processing agreement (DPA) or terms reference, and where users can access them.]
  • Legal documents: see our Privacy Policy and Terms of Service, and our Cookie Policy.

Data retention and your control

You control the data your organization publishes. Listing content can be edited or removed by your organization’s administrators at any time, and account data is not shared with third parties for marketing purposes.

What we ask of you

  • Use a strong, unique password for your Desi Assets account and change it if you suspect compromise
  • Never share your login credentials; each member should have their own account
  • Keep contact details and organization information up to date so notices reach you
  • Report suspected security issues or unusual activity promptly (see below)

Reporting a security concern

If you believe you have found a security issue in the platform, or you notice unusual activity on your account, contact us immediately at contact@desiassets.com. Please include as much detail as you can — what you observed, when, and any steps to reproduce it. We treat reports confidentially and acknowledge them promptly.

This page will be updated as our security and compliance practices evolve. [Last reviewed: add a date when you finalize the content.]

Have questions?

Our team is happy to talk through how Desi Assets protects your data.