Trust & Security

Enterprise-grade security, trusted at scale

India's largest developers run their pipelines, bookings and customer ledgers on Sell.Do. We protect that data with an ISO/IEC 27001:2022 certified ISMS, encryption everywhere and capability-driven access.

Built to the standards enterprise real estate demands

ISO/IEC 27001:2022 certifiedAES-256 at restTLS 1.2+ in transitDPDP Act 2023GDPR-ready (DPA)RERA-aware recordsSSO + 2FAAudit logs
Compliance & certifications

Standards we hold ourselves to

Real estate moves serious money and sensitive personal data. Our compliance posture is designed for developer InfoSec, legal and audit teams — not marketing.

ISO/IEC 27001:2022 — Information Security

Certified

Sell.Do is ISO/IEC 27001:2022 certified — operating a formal Information Security Management System (ISMS) audited against the global standard for the confidentiality, integrity and availability of customer data. Policies, risk assessments and Annex A controls are maintained and reviewed on a defined cadence.

India DPDP Act, 2023

Compliant

We process personal data in line with India's Digital Personal Data Protection Act — purpose limitation, consent capture, data-principal rights (access, correction, erasure) and breach notification workflows are built into the platform.

GDPR-ready

DPA available

For developers and partners with EU/UK data subjects, we offer a Data Processing Agreement, standard contractual clauses and tooling to honour subject-access and erasure requests.

SOC 2 — Trust Services

Aligned

Controls are mapped to the SOC 2 Trust Services Criteria (security, availability, confidentiality), with reports and supporting evidence shared with enterprise customers under NDA during procurement.

OWASP secure development

Followed

Application security follows OWASP standards — secure-by-design coding practices, regular vulnerability assessment and penetration testing, and remediation tracking across releases.

RERA-aware by design

Built in

Booking records, cost sheets, demand letters and customer ledgers are modelled to support RERA disclosure and audit needs across Indian states — not bolted on after the fact.

Data protection

Your data, encrypted and isolated

Encryption in transit

All traffic is encrypted with TLS 1.2+. HSTS is enforced and weak ciphers are disabled.

Encryption at rest

Customer data, backups and attachments are encrypted at rest with AES-256.

Key management

Encryption keys are managed in a dedicated KMS with rotation and strict access separation.

Data isolation

Strict tenant scoping isolates every developer's leads, bookings and customer records.

Resilient cloud hosting

Hardened, isolated cloud infrastructure with network segmentation and controlled access.

Backups & DR

Automated, encrypted backups with tested restore procedures and a documented disaster-recovery plan.

Data masking

Sensitive fields — buyer phone numbers, emails and identifiers — can be masked by role, so representatives and channel partners act on leads without exposing raw PII.

Data retention policy

Defined retention and deletion schedules govern how long leads, recordings and documents are kept — with controlled, audited purge on expiry or request.

Data-subject deletion (DSAR)

Honour right-to-erasure with export-and-delete: a data subject's record can be exported for evidence and then purged, satisfying DPDP and GDPR requests.

Access governance

Permission-driven from the ground up

No role is hardcoded. Access flows from a capability matrix and custom roles, so owners decide exactly what every user — internal or external — can see and do.

Capability-driven RBAC

Permissions flow from a capability matrix and custom roles — no access is hardcoded. Owners control exactly what each user, team or channel partner can see and do.

SSO & OTP-based 2FA

SAML and Google SSO for single sign-on, with OTP-based two-factor authentication enforceable across the whole tenant.

IP-based access restrictions

Restrict logins to approved office, VPN or location IP ranges per role or tenant — so data can only be reached from where you allow.

Tenant-scoped partner access

Channel partners and external users log in through white-labelled sub-domains with their own scoped identities — never your internal console.

Immutable audit logs

Every sensitive action — exports, edits, permission changes, logins — is logged with actor, time and context, and is exportable for review.

Field-view audit

Even who viewed which sensitive field is recorded — so PII access is accountable, not just PII changes.

Hierarchy-scoped data access

Visibility flows from your reporting hierarchy — managers see their tree, representatives see their own, channel partners see only what's granted. No flat, all-can-see-everything access.

Least-privilege operations

Internal access to production follows least-privilege, is time-bound, logged, and reviewed. Customer data is never accessed without a logged business reason.

Anomaly & abuse controls

Rate limiting, bulk-export guards and alerting protect against scraping, credential stuffing and data exfiltration.

Dedicated security team & DPO

A dedicated data-security & privacy team and a named Data Protection Officer own policy, reviews and breach response — security is somebody's full-time job, not an afterthought.

99.9%
Uptime target
AES-256
Encryption at rest
24×7
Monitoring & alerting
India
Data residency
Application & infrastructure

Secure by engineering practice

Secure SDLC. Security review is part of how we ship — code review, dependency scanning, secrets management and a CI pipeline that gates releases. Compliance controls are enforced in code paths, not left to documentation.

Vulnerability management. We run regular vulnerability scans and engage third-party penetration testers for major releases. Findings are triaged by severity and tracked to closure with defined SLAs.

Network & infrastructure. Production runs on hardened cloud infrastructure with network segmentation, firewalls, WAF, DDoS protection and isolated environments for development, staging and production.

Logging & monitoring. Centralised logging, uptime monitoring and alerting give us 24×7 visibility, with audit trails retained for investigation and compliance.

Business continuity. Encrypted backups, tested restores and a documented disaster-recovery plan keep your pipeline running through launch-day spikes and beyond.

Transparency

Sub-processors

We use a vetted set of sub-processors to deliver the platform. Each is assessed for security and data-protection posture, and a current list is maintained for customers under contract.

Cloud hosting
Application & database hosting (India regions)
Cloud telephony
Calling, IVR, call recording
WhatsApp Business API (BSP)
Official WhatsApp messaging
Email / SMS gateways
Transactional & marketing delivery
Error & uptime monitoring
Reliability and incident detection
AI / LLM providers
Jarvis AI scoring, voice & content (scoped, no training on your data)

Responsible disclosure

Security researchers are valued partners. If you believe you've found a vulnerability in Sell.Do, please report it to security@sell.do with steps to reproduce. We commit to acknowledging reports, investigating promptly, and working with you in good faith. Please do not access customer data or disrupt service while testing.

Documentation

See the certificate for yourself

ISO/IEC 27001:2022, issued by InterCert to K2V2 Technologies Private Limited — registration IC-IS-2503270, covering the Sell.Do and IRIS platforms.

Request the certificate

Get our ISO/IEC 27001:2022 certificate

Tell us who you are and we'll give you the certificate straight away — registration number, scope and validity dates included.

Security FAQ

Yes. Sell.Do is ISO/IEC 27001:2022 certified and operates a formal ISMS. The certificate — registration IC-IS-2503270, issued by InterCert to K2V2 Technologies Private Limited and covering the Sell.Do and IRIS platforms — can be downloaded from this page. Supporting documentation, including the Statement of Applicability, is shared with enterprise InfoSec teams under NDA during procurement.

Need a security review, DPA or completed questionnaire?

Our team will walk your InfoSec, legal and audit teams through controls, hosting, sub-processors and compliance — and turn around questionnaires fast.