Skip to content
Security and privacy

What we do to protect your data,stated plainly.

Hotels, PGs and coworking spaces hold identity documents and payment records. Below is what EkamOS does about that today, and what it does not do yet. There are no compliance badges on this page because EkamOS has not been independently audited.

The short answer

EkamOS keeps identity documents and other uploads private to signed-in staff with access, masks Aadhaar numbers to their last four digits, offers two-factor sign-in, logs who viewed or changed personal data, records marketing consent, and backs up the database daily with encryption, stored off the server. It is hosted on Amazon Web Services in Singapore. It has not been independently audited or certified.

Principles

Three things we do not compromise on

  • Private by default

    Identity documents and personal records are visible only to signed-in staff with access to that location.

  • The owner stays in control

    Prices, refunds and privacy settings are owner-only, and the owner can see who looked at personal data.

  • Nothing claimed that is not true

    This page lists what is built, and what is not. EkamOS has no certifications, so it shows none.

Documents and identity

Your files and your guests’ IDs

  • Private uploads stay private

    Identity documents, tenant and member paperwork and other private files are never served from a public address. They are handed out only to a signed-in user with access to that property, and each download is written to a server log.

  • Aadhaar numbers are masked

    On guest and visitor records, an Aadhaar number is stored and shown with only its last four digits. Records saved before masking was added were masked too.

Signing in

Accounts and sessions

  • Two-factor sign-in

    Staff can turn on two-factor authentication with an authenticator app.

  • Sign out everywhere

    Signing out ends the session on the server, not just in the browser. You can sign out of all devices at once, and the token that keeps you signed in is held in a cookie that page scripts cannot read.

  • Rate limiting

    Sign-in, two-factor codes, password resets and public forms are rate-limited per network address, and two-factor codes and password resets per account as well. This slows down password guessing and spam.

Access

Who can see and change what

  • Roles, and prices only the owner can change

    Staff see what their role allows. Rates, menu prices, deposit deductions and refunds are owner-only, checked by the server as well as hidden in the app.

  • Each location’s data is separate

    Staff are given access per location, and the server checks that access on requests that read or change a location’s data.

  • A log of who looked at guest data

    Opening, changing or downloading a guest, occupant, tenant, member, visitor or invoice record is written to an access log the owner can read, with who did it and when.

Privacy tools

Help with your obligations under India’s data protection law

These tools are meant to help you meet your obligations under India’s Digital Personal Data Protection Act, 2023. Whether your setup meets them is for you and your advisers to judge.

  • Marketing only with consent

    EkamOS keeps a record of each person’s marketing consent and its withdrawal, and will not send a marketing message to someone without it. Booking confirmations, invoices and reminders are not affected.

  • Access and erasure requests

    When a guest asks for a copy of their data or for it to be erased, the owner logs the request, previews what it covers, exports it, or erases it. Records the law may require you to keep, such as recent invoices and guest-register entries, are held back and shown as held.

  • Retention you switch on deliberately

    Set how long to keep ID document scans, guest details and access logs. A dry run first reports what would be removed; nothing is deleted until the owner turns enforcement on.

Infrastructure

Where your data lives

  • Connection secrets encrypted at rest

    Keys and tokens you give EkamOS for other services, such as messaging, accounting and channel connections, and two-factor secrets, are encrypted in the database.

  • Encrypted backups, kept off the server

    The database is backed up every day. Backups are encrypted before they leave the server, with a key that is not kept on the server, and are stored outside it. We have a written restore procedure and have tested it.

  • Where your data is hosted

    EkamOS runs on Amazon Web Services in the Singapore region, and backups are stored in the same region.

What we do not claim yet

Roadmap
  • An owner-facing history of money edits, such as voids, discounts and rate changes
  • A page where guests file access or erasure requests themselves (today the owner records them)
  • Scanning an Aadhaar QR code instead of storing a copy of the card
  • An independent security audit or certification. EkamOS has not been certified by any third party.

Found a security issue?

Please tell us through the contact form or at hello@ekamos.in, and we will get back to you.

Questions

Security questions, answered

Is EkamOS certified, for example ISO 27001 or SOC 2?

No. EkamOS has not been independently audited or certified by any third party, so this site shows no certification badges. This page lists what the product does today instead.

Is EkamOS compliant with the Digital Personal Data Protection Act, 2023?

There is no certificate that makes software compliant. EkamOS gives owners tools that help with their obligations: a consent record that blocks marketing without consent, access and erasure requests, retention settings and an access log. Whether your setup meets the Act is for you and your advisers to judge.

Where is my data stored?

On Amazon Web Services in the Singapore region. Daily encrypted backups are stored in the same region, outside the server that runs EkamOS.

Who on my team can see guest IDs?

Only signed-in staff with access to that location. Uploaded documents are never served from a public address, each download is logged, Aadhaar numbers are masked to their last four digits, and the owner can read an access log of who opened, changed or downloaded a record.

Can a guest ask for their data to be deleted?

Yes. The owner logs the request, previews what it covers and exports or erases it. Records the law may require you to keep, such as recent invoices and guest-register entries, are held back and shown as held.

Does EkamOS support two-factor sign-in?

Yes. Staff can turn on two-factor authentication with an authenticator app, and sign-in attempts and codes are rate-limited.

Questions about how your data is handled?

Ask us on a demo call. We will show you where each of these lives in the product.