Security is built into how Entrio is designed — tenant isolation, encryption, one-way credential hashing, and passes that can't be duplicated.
Entrio is multi-tenant: every organiser's data is scoped to that organiser and separated from every other. Data access is tenant-scoped at the query layer so one organiser can never read or write another's records.
All traffic runs over encrypted connections (TLS). Sensitive organiser secrets — payment gateway keys and pass-signing keys — are encrypted at rest. Passwords and one-time passcodes (OTPs) are stored only as one-way hashes and are never kept in readable form.
Every pass carries a cryptographically unique code. Each entry is verified exactly once at the gate; already-used, revoked, or expired passes are refused, and duplicates are blocked — so a forwarded or forged QR can't be admitted twice.
Access is restricted to an organiser's authorised staff and the specific delivery partner assigned to an order, by role. Sensitive actions are recorded in an audit trail.
Your data is hosted in India (DigitalOcean, Bangalore). Where a limited amount of data is processed by our service providers (for payments, messaging, or maps), it is done only as permitted under our agreements and applicable law.
Personal data is handled in line with the Digital Personal Data Protection Act, 2023. See our Privacy Policy & DPDP Notice for what we collect, why, and your rights.
If you believe you've found a security issue, please email [email protected] or call +91 89802 98564. We appreciate responsible disclosure and will work with you to confirm and fix the issue.