Security and your data
A club holds members' addresses, their families' details and their payment history. Here is what happens to it.
Already in place across our platforms
These are running today on the club platform we operate, and this product inherits the same architecture.
Where your data lives
Production systems run in the India region — Oracle Cloud, Hyderabad — on infrastructure we operate. Data residency is a configuration we can state precisely rather than a claim we imply, and we will put it in a contract.
One tenant can never read another
Isolation is enforced at the database with Postgres row-level security, not by application code alone. That distinction matters: an application bug cannot widen the boundary, because the boundary is not in the application.
Access is role-based, down to the record
Roles run from platform owner through site administrator to end user, and permissions are checked on the server on every request rather than hidden in the interface. Sign-in is passwordless — a provider account or a one-time link — so there are no shared passwords to rotate or leak.
We do not train on your data
Your documents and records are processed to produce your output and for no other purpose. Nothing you give us is used to train a model, ours or anyone else’s, and nothing is pooled across clients. This goes in the contract, not just on this page.
Getting your data out
Export is in open formats — CSV, XLSX, PDF and the original files you gave us — available on request and on exit, not as a paid migration. If you leave, you leave with everything, and we would rather agree that up front than negotiate it later.
What this product is being built to
Specified and partly built. Stated as design rather than as a control you can rely on today.
Corrections add. They never overwrite.
Records that matter are written to an append-only trail. A correction is a new entry that supersedes the old one, so the question "what did this say in March, and who changed it" has an answer. Audit trails that allow edits are not audit trails.
Built for Indian data protection law
Consent is versioned, so we can show what a person agreed to and when. Personal identifiers are kept separate from the records that get searched. Access, correction and erasure requests are handled as a process with an owner, and erasure reaches every store a record touched, including derived indexes.
Send us your security questionnaire
We will complete it. If your procurement process has a standard form, a supplier assurance pack or a set of clauses you need answered, send it over and we will fill it in properly rather than returning a brochure. If the honest answer to a question is "we do not do that yet", that is what you will get.
Send it overThis page describes what is in place today. It is reviewed quarterly, and anything we cannot evidence does not appear on it. Last reviewed 2026-09-27. The full picture across everything Snilld operates is on the studio’s trust page.