Security
What we do to keep your account and records safe, and how to tell us about a problem.
This page lists the measures Openn Invoice actually uses today. We do not hold an ISO 27001 or SOC 2 certification, and we don’t claim to.
Connections
- Every page and request uses HTTPS. HTTP Strict Transport Security tells browsers never to connect without it.
- A strict Content Security Policy limits which scripts can run: our own, Cashfree’s checkout, and Google Analytics only after you accept it.
- Our pages cannot be framed by other sites, and browsers are told not to guess file types or send full page addresses to other sites.
Signing in
- Passwords are hashed with scrypt and a unique salt. We never store or see them in plain text.
- Two-step sign-in sends a one-time code to your email. Codes are stored hashed and expire within minutes.
- Sessions live in secure, http-only cookies that page scripts cannot read. We store only a hash of each session token, and sessions end after 30 days.
- Each person has a device limit, and we email you when a new device signs in.
- Sign-in, code and other sensitive requests are rate limited to slow down guessing and abuse.
Your records
- Every database query is scoped to the business it belongs to, so one business can never read another’s records.
- Payment proof files are stored outside the public web folder and shown only to signed-in members of the business that uploaded them.
- Shared invoice and statement links use long random tokens and are hidden from search engines.
- We never receive card numbers, UPI PINs or bank log-ins. Payments are handled by Cashfree.
Operations
- Our servers are hosted by Hostinger in India.
- The database and uploaded files are backed up every night, and backups are kept for 30 days.
- Only Amit Singh Rawat can reach the production servers and database. Our operator console runs on a separate address with its own sign-in and emailed codes.
- Sensitive account changes are written to an audit log.
If a breach affects your data, we tell you as our privacy policy and data processing addendum set out.
Report a vulnerability
If you find a security problem, email hello@theopenngroup.com with the steps to reproduce it. We will confirm receipt, keep you updated, and fix confirmed issues as fast as we can. Please give us reasonable time to fix it before telling anyone else.
While testing, only use your own account, don’t access or change other people’s data, and don’t run tests that slow down or disrupt the service. We will not take legal action against research done in good faith within these rules.