Legal

Security Policy

Effective: 1 January 2026

Our commitment

We treat brewery data — recipes, production logs, sales and compliance records — as high-sensitivity. Our controls reflect that.

Controls in place

· Encryption in transit (TLS 1.2+) and at rest (AES-256).

· Row-level security scoped to your brewery on every query.

· Role-based access control with least-privilege defaults.

· Immutable audit logs on every mutation.

· Daily backups retained for 30 days; disaster-recovery tested quarterly.

· Managed cloud infrastructure with hardened baselines.

Responsible disclosure

Report suspected vulnerabilities to security@brewtally.in. Please give us reasonable time to remediate before public disclosure. We do not pursue legal action against good-faith researchers.

Incident response

If a security incident materially affects your data, we will notify affected customers without undue delay along with the facts we know, the impact, and our remediation.

Contact

security@brewtally.in · PGP available on request.