Security and your data

A club holds members' addresses, their families' details and their payment history. Here is what happens to it.

Read this first

This product is in build and holds no club’s real data yet. The demo on this site stores everything in your own browser and sends nothing to us. What follows separates the controls already running on the platform Snilld operates from the ones this product is being built to.

Already in place across our platforms

These are running today on the club platform we operate, and this product inherits the same architecture.

Where your data lives

Production systems run in the India region — Oracle Cloud, Hyderabad — on infrastructure we operate. Data residency is a configuration we can state precisely rather than a claim we imply, and we will put it in a contract.

One tenant can never read another

Isolation is enforced at the database with Postgres row-level security, not by application code alone. That distinction matters: an application bug cannot widen the boundary, because the boundary is not in the application.

Access is role-based, down to the record

Roles run from platform owner through site administrator to end user, and permissions are checked on the server on every request rather than hidden in the interface. Sign-in is passwordless — a provider account or a one-time link — so there are no shared passwords to rotate or leak.

We do not train on your data

Your documents and records are processed to produce your output and for no other purpose. Nothing you give us is used to train a model, ours or anyone else’s, and nothing is pooled across clients. This goes in the contract, not just on this page.

Getting your data out

Export is in open formats — CSV, XLSX, PDF and the original files you gave us — available on request and on exit, not as a paid migration. If you leave, you leave with everything, and we would rather agree that up front than negotiate it later.

What this product is being built to

Specified and partly built. Stated as design rather than as a control you can rely on today.

Corrections add. They never overwrite.

Records that matter are written to an append-only trail. A correction is a new entry that supersedes the old one, so the question "what did this say in March, and who changed it" has an answer. Audit trails that allow edits are not audit trails.

Built for Indian data protection law

Consent is versioned, so we can show what a person agreed to and when. Personal identifiers are kept separate from the records that get searched. Access, correction and erasure requests are handled as a process with an owner, and erasure reaches every store a record touched, including derived indexes.

Send us your security questionnaire

We will complete it. If your procurement process has a standard form, a supplier assurance pack or a set of clauses you need answered, send it over and we will fill it in properly rather than returning a brochure. If the honest answer to a question is "we do not do that yet", that is what you will get.

Send it over

This page describes what is in place today. It is reviewed quarterly, and anything we cannot evidence does not appear on it. Last reviewed 2026-09-27. The full picture across everything Snilld operates is on the studio’s trust page.