Legal
Security Policy
Encryption, OAuth, access control, and operational security for marketplace partner review.
Last updated: July 2026
1. Overview
Khodi Mart never asks for Amazon, Flipkart, or Meesho seller passwords. Marketplace access uses official OAuth / API-key partner flows. Refresh tokens and API secrets are encrypted at rest and never exposed to the browser. This Policy summarises controls relevant to marketplace partnerships and enterprise buyers.
2. Encryption standards
- TLS for data in transit on production HTTPS endpoints.
- AES-256-GCM (or equivalent) for sensitive credentials at rest (marketplace OAuth refresh tokens, API secrets).
- Application secrets loaded from environment / secret manager — never committed to source control.
3. HTTPS everywhere
Production web and API traffic is served over HTTPS. Mixed-content and plaintext credential transport are not used for authenticated flows.
4. Secure authentication
- JWT session authentication for seller, supplier, warehouse, and admin APIs.
- Email-based account registration and login with hashed passwords.
- Role-based portals — users only reach routes allowed for their role.
- 2FA / MFA: roadmap for future enterprise hardening (documented as planned).
5. OAuth only (marketplaces)
Marketplace connections use OAuth or official partner credential exchange. We do not store marketplace passwords. Consent scopes follow least privilege (Orders, Inventory, Listings, Returns, Settlement as applicable). Disconnect wipes encrypted credential material and stops sync.
6. Password hashing
Account passwords are stored using modern one-way hashing (not reversible encryption). Password reset flows invalidate prior credentials appropriately.
7. Access control
- Seller-scoped queries — marketplace and ops rows filtered by seller_id.
- Supplier anonymity enforced in seller product views.
- Admin and warehouse roles separated from seller/supplier capabilities.
- Least-privilege internal access to production systems.
8. Audit logs
Connect / disconnect / sync / export and other sensitive actions are recorded in audit trails without logging secrets or full tokens.
9. Infrastructure security
- Cloud hosting with network firewall / security group controls.
- Redis-backed rate limiting for marketplace API workers.
- Background sync with retry and failure isolation.
- Monitoring and alerting on critical service health.
10. Database security
- Access restricted to application and authorised operators.
- Sensitive columns for integration credentials encrypted.
- Backups stored with restricted access.
11. Backup strategy
We maintain regular database backups for disaster recovery. Backup restoration is tested as part of operational readiness. Retention periods balance recovery needs with data minimisation.
12. Disaster recovery
Recovery objectives prioritise restoring authentication, catalogue, order, and integration services. Enterprise customers may receive enhanced RTO/RPO commitments under a signed SLA.
13. Vulnerability management
We track dependency and infrastructure updates, review high-severity issues promptly, and accept responsible disclosure reports from security researchers.
14. Responsible disclosure
Report vulnerabilities to security@khodi.in. Do not include live tokens or exploit public users. See Responsible Disclosure for safe harbour expectations.
15. Security contact
Security: security@khodi.in. General support: support@khodimart.com. Also visit Security Center and Trust Center.
Also see Trust Center, Privacy, Terms, Security, Compliance, Cookies, DPA, Disclosure, and Help.
