Security & Trust

How IVMS protects the data it collects.

IVMS handles personal data on behalf of every company that uses it — visitor photographs, ID numbers, and Aadhaar numbers among them. This page explains, in plain language rather than legal boilerplate, exactly how that data is protected.

Data Protection

Personal data is protected by design, not as an afterthought.

Encrypted at rest

Visitor photographs and government ID numbers, including Aadhaar, are encrypted in the database. They cannot be read directly — only the application, holding the encryption key, can decrypt them for an authorised request.

A fresh photo, every time

A returning visitor's name and ID details can be reused to speed up their next visit — their photograph never is. Every single check-in captures a live photo, with no exceptions.

A permanent audit trail

Every check-in, check-out, cancellation, and edit is recorded against the specific person who performed it, with a timestamp. Nothing happens anonymously inside IVMS.

Access Control

Every user sees only what their role requires.

IVMS enforces role-based access control on every single request — not just by hiding buttons in the interface, but at the point where data is actually read or written. A user without a permission cannot reach that data, even by calling the system directly rather than through the screens they're shown.

Employee
Sees and manages only the visitors they personally invited. Nothing company-wide.
Security Guard
Sees today's expected visitors and gate activity only. No access to company settings, staff records, or historical reports.
HR Manager
Full visibility into company-wide visitor history and compliance reporting, without access to platform-level administration.
Company Admin
Full control of their own company — staff, departments, gates, and branding — with no visibility into any other company on the platform.
Platform Team
Secret Weapon's own operations role, used only to provision and support customer accounts. Platform staff do not have standing access to any customer's visitor data.
Multi-Tenant Isolation

Your data is walled off from every other company on IVMS.

IVMS is a multi-tenant system: many companies use the same application, but every company's visitors, appointments, staff, and records are strictly scoped to that company alone. This isolation is enforced at the data-access layer itself, not only in the user interface — one company can never see, search, or export another company's data, structurally, regardless of role.

Authentication & Abuse Prevention

Accounts are protected against guessing, not just protected by a password.

Passwords are never stored in plain text

Every password is hashed using bcrypt, an industry-standard one-way hashing algorithm. IVMS itself cannot see or recover a user's actual password.

Short-lived, signed sessions

Sessions use signed, short-lived tokens rather than long-lived cookies — a stolen token has a limited window in which it could ever be used.

Automatic alerts on repeated failures

Login attempts are rate-limited, and repeated failed attempts against a single account — even spread across different networks — trigger an automatic security alert. Every other authenticated action is rate-limited per user, not per office network, so staff sharing one internet connection never throttle each other.

Infrastructure

The platform itself is locked down, not just the application.

All traffic to IVMS is encrypted in transit over HTTPS. The database and cache that store your data are not directly reachable from the public internet under any circumstance — only the application server itself can reach them, and every credential protecting that connection is rotated and held outside the application's own source code.

Compliance & Our Roadmap

Built with India's data protection law in mind, and honest about where we are.

IVMS is designed around the core principles of India's Digital Personal Data Protection Act (DPDP), 2023 — collecting only what's needed, using it only for the stated purpose, and encrypting personal data as a default, not an add-on.

We are a growing company, and we'd rather tell you that directly.

IVMS does not yet hold formal certifications such as ISO 27001 or SOC 2. Achieving them is on our roadmap as we scale. If your organisation requires a completed security questionnaire, a specific certification, or a signed data processing agreement before onboarding, please reach out — we will work through it with you directly rather than ask you to take our word for it.

Found a security issue?

If you believe you've found a security vulnerability in IVMS, please tell us directly at support@secretweapon.in. We take every report seriously and will respond promptly.

Talk To Us

Have a specific security or compliance requirement?

Tell us what your procurement or IT team needs — a completed questionnaire, a specific clause in the agreement, or a walkthrough of how a particular control works — and we'll go through it with you directly.

Secret Weapon Trading Solution Pvt. Ltd. support@secretweapon.in  ·  +91 70837 18306 (call or WhatsApp)