Hostel & Property Management Platform

Document Security Practices
Last Updated March 15, 2026
Compliance IT Act 2000 & DPDP Act 2023

At MoveTara, we take the security of your data seriously. As a B2B SaaS platform managing sensitive hostel operations, tenant records, and financial data, we implement industry-standard security measures to protect your information. This page describes our security practices and infrastructure.

MoveTara follows "reasonable security practices and procedures" as required under the Information Technology (Reasonable Security Practices and Procedures) Rules, 2011 and the Digital Personal Data Protection Act, 2023.

1. Infrastructure Security

Encrypted Data at Rest

Encrypted Data in Transit

Managed Cloud Infrastructure

2. Authentication & Access Control

Security Measure Implementation
OTP authentication Mobile OTP verification via SMS — one-time codes expire after use, never stored permanently
MPIN storage MPIN codes are stored as cryptographic hashes — never stored in plaintext
Session management JWT-based authentication tokens with automatic expiry and refresh rotation
Role-based access (RBAC) Strict role separation: Owner, Warden, Tenant — each role can only access authorized data
Row-Level Security (RLS) Database enforces row-level security policies — users can only query their own data
API authorization Every API request is authenticated and authorized before processing

3. Application Security

4. Data Protection

5. Operational Security

6. Mobile App Security

7. Compliance

Regulation Status
Information Technology Act, 2000 (India) Compliant — reasonable security practices implemented per IT Rules 2011
Digital Personal Data Protection Act, 2023 (India) Compliant — data processing with consent, Grievance Officer appointed, deletion rights honored
OWASP Top 10 Followed — application security best practices implemented

8. Responsible Disclosure

If you discover a security vulnerability in the MoveTara platform, we encourage you to report it responsibly. Please email us at security@movetara.com with details of the vulnerability. We request that you:

We will acknowledge your report within 48 hours and aim to resolve confirmed vulnerabilities within 14 days.

Security Contact

Security Reports: security@movetara.com

Privacy Requests: privacy@movetara.com

General Support: support@movetara.com

MoveTara — Hostel & Property Management Platform
Hyderabad, Telangana 500019, India