Home / Security

Security & trust

How we protect your data across the Thunder suite and platform.

Encrypted & hashed

Passwords are stored with salted PBKDF2-SHA256. API keys are stored only as hashes — never in plaintext.

Secure by default

Strict Content-Security-Policy, CSRF protection on every write, HttpOnly + SameSite cookies and path-traversal guards.

Access control

Role-based access separates admins from users, with a full audit trail of sensitive actions.

Data sovereignty

Offline-first and self-hostable, so your data stays in your environment. Built around India's DPDP Act.

Rate limited

Sensitive endpoints are rate-limited to blunt brute-force and abuse.

Durable storage

SQLite locally or Neon PostgreSQL in production, with pooled connections for reliability.

Compliance

Built for India's DPDP Act

Data minimisation, consent, the right to access and erase, and clear grievance handling — designed in from the start. Read our privacy notice.