Trust
Security
How Effata protects your data.
Encryption in transit and at rest
All traffic to and from Effata is encrypted in transit over TLS. Our production environment enforces this at the infrastructure level and cannot be configured to accept unencrypted or unverified connections.
Data at rest is encrypted using our infrastructure providers' standard encryption for data stored in our database.
Tenant isolation
Every customer's data is isolated at the database level using row-level security policies scoped to your organization on every table that stores customer data — not application-layer filtering alone. This isolation is continuously verified: a dedicated automated test suite runs real integration tests against a live database on every change to confirm one organization's data can never be read or written by another.
Authentication and MFA
Access to Effata requires an authenticated account (email and password). Multi-factor authentication is on our roadmap and not yet available — if MFA is a requirement for your organization, contact us and we'll let you know timelines.
Role-based access control
Every user is assigned a role — read-only, analyst, or admin — and every action in the product is checked server-side against that role before it's allowed. Role checks rely on server-verified session identity, not client-side trust.
Audit logging
Effata logs security-relevant events — sign-ins, role changes, team membership changes, and data-affecting actions — with the acting user, organization, action, and before/after values where applicable. Organization admins can review this history from within the product.
Hosting and data locations
Effata is built on established cloud infrastructure providers for hosting, database, and application services. If your organization has specific data-residency requirements, contact us and we'll confirm current hosting regions for your account.
Vulnerability management, penetration testing, and incident response
Formal automated dependency/vulnerability scanning, third-party penetration testing, and a documented incident-response program are on our roadmap and not yet in place. We take security reports seriously — if you believe you've found a vulnerability or are affected by an incident, contact our security team below and we will investigate and respond.
Data retention and deletion
We retain your data for the duration of your engagement with Effata. Deleting an organization's account removes its associated data. There is currently no self-service deletion option — contact us to request deletion of your account or organization's data, and we will action it promptly.
Security contact and DPA requests
Report a suspected vulnerability or security concern, or request a Data Processing Agreement (DPA), by emailing hello@effata.in. We respond to security reports directly.