Security Center

How we protect marketplace tokens and seller data

OAuth-only marketplace access, encrypted credentials, seller-scoped queries, and operational monitoring — designed for partner due diligence.

Security diagram — Seller → OAuth → Marketplace → Encrypted API → Khodi Mart → Encrypted DB → Dashboard

SellerAuthenticated seller session (JWT) in the Khodi Mart dashboard.

↓

OAuth LoginSeller starts official marketplace OAuth / partner consent — no password sharing with us.

↓

MarketplaceAmazon / Flipkart / Meesho issues scoped tokens under their partner terms.

↓

Encrypted APIWorkers call marketplace APIs over HTTPS using encrypted stored credentials.

↓

Khodi MartSeller-scoped business logic, rate limits, and audit logs (no secrets in logs).

↓

Encrypted DatabaseTokens at rest with AES-256-GCM; operational rows filtered by seller_id.

↓

DashboardOrders, inventory, health, and Global OPS views for that seller only.

Authentication

Account access is role-based. Sellers, suppliers, warehouse staff, and admins use separate portals with JWT sessions. Marketplace access is never username/password stored by Khodi Mart — only OAuth / partner credentials.

  • •Email verification on account registration
  • •JWT session security for dashboards and APIs
  • •Role-based portals (seller, supplier, warehouse, admin)
  • •Session expiry / logout clears dashboard access
  • •2FA / MFA — planned for enterprise hardening

Encryption

Sensitive integration material is encrypted so that a database backup alone is not enough to call marketplace APIs. Passwords for Khodi Mart accounts use one-way hashing.

  • •TLS in transit for production HTTPS
  • •AES-256-GCM encryption at rest for marketplace OAuth tokens and API secrets
  • •Passwords hashed with modern one-way algorithms
  • •Secrets loaded from environment / secret manager — never committed to source control

Infrastructure

Production runs on cloud infrastructure with network restrictions, worker isolation for marketplace sync, and regular backups for recovery.

  • •Cloud hosting with firewall / security group controls
  • •Redis-backed rate limiting for marketplace API workers
  • •Background sync with retry and failure isolation
  • •Regular database backups and DR readiness for core services

Monitoring & incident response

We monitor critical services and keep audit trails for sensitive integration actions. Security issues should be reported to security@khodi.in.

  • •Application and worker logs for diagnostics (no live tokens)
  • •Alerts on critical service health
  • •Audit logs for connect / disconnect / sync / export
  • •Incident response via support + security@khodi.in
  • •Public status notes on /status for multi-tenant events

Need a security questionnaire for Amazon / Flipkart / enterprise procurement? We respond under NDA via support.

Compliance overview