Security is foundational to Easy Procure. Because we run the supply chain and generate statutory compliance documents, the integrity and confidentiality of your data are non-negotiable. This page summarises our practices.
Data protection
- Encryption in transit. All traffic to and from the platform is encrypted using TLS.
- Encryption at rest. Data is encrypted at rest using industry-standard algorithms.
- Tenant isolation. Each brand's data is logically isolated, with strict access boundaries — especially important for multi-brand groups.
Access control
- Role-based access control (RBAC). Permissions are scoped to roles, so people see only what they need.
- SSO for Enterprise. SAML/OIDC single sign-on and SCIM provisioning are available on Enterprise plans.
- Least privilege. Internal access to production systems is limited, logged and reviewed.
Auditability
Our inventory is event-sourced and our order lifecycle is a strict state machine. Every meaningful change is an immutable, attributable event. This means you can replay and audit exactly what happened — to a position, an order or a compliance document — and reconcile registers to the rupee.
Compliance documents
E-invoices and e-way bills are generated through a GST Suvidha Provider licensed by GSTN, an authorised channel. IRNs, signed QR codes and supporting documents are stored and linked to their orders for audit.
Infrastructure and availability
- Hosted on reputable cloud infrastructure with redundancy and monitoring.
- Regular backups with tested restore procedures.
- Continuous monitoring and alerting for availability and anomalies.
Secure development
- Code review and automated checks in our delivery pipeline.
- Dependency monitoring and timely patching.
- Separation of environments for development, staging and production.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you've found a security issue, please email admineasyprocure@gmail.com with details and steps to reproduce. We'll acknowledge your report and work with you on a resolution. Please do not publicly disclose an issue until we've had a reasonable opportunity to address it.
Questions
For security questions, due-diligence requests or to request our latest documentation, contact admineasyprocure@gmail.com.