Security at AgatePro
Your leads and buyers are your business. Here's how we keep them that way.
Tenant isolation at the database layer
Every table is protected by PostgreSQL Row-Level Security. Your rows are scoped to your account by the database itself — not just by application code — so one seller can never read another seller's leads, buyers, orders or messages.
Encryption
All traffic is TLS-encrypted in transit. Data is encrypted at rest by our infrastructure providers. Your third-party API keys (e.g. marketplace integrations) are additionally encrypted with AES-256-GCM before storage, and inbound routing tokens are stored only as SHA-256 hashes.
Payments
Payments are processed by Razorpay (PCI DSS Level 1). Card and UPI details never touch our servers. Webhook events are signature-verified and idempotent.
Access & auditing
Passwordless sign-in (phone OTP, Google, email link) — no password database to breach. Admin actions on seller accounts are logged with before/after state. Sessions are invalidated server-side on logout.
Your data, portable
Export your leads, contacts, orders and products any time from Dashboard → Settings → Data export. Disconnecting a channel stops all processing of new data from it; deletion requests are honoured per our Privacy Policy and Data Deletion page.
Responsible disclosure
Found a vulnerability? Email support@mbglobalagate.com (see /.well-known/security.txt). We acknowledge within 2 business days and won't take legal action against good-faith research.
More detail: Privacy Policy · Data Processing Agreement · Data Deletion