CleverfindLegal & trust

Cleverfind policy

Data Security Policy

Cleverfind applies layered technical and organisational controls, while recognising that no online service can guarantee absolute security.

Effective
Applies to
Cleverfind systems, accounts, integrations, and stored data
Jurisdiction
India

Cleverfind's approach to account security, encryption, access control, broker credentials, incident response, and responsible reporting.

Security principles

Cleverfind designs controls around confidentiality, integrity, availability, least privilege, secure defaults, and recovery. Controls are selected according to the sensitivity of the data, the service architecture, credible threats, and applicable Indian law.

This policy describes our approach and is not a certification, audit report, warranty, or guarantee that every attack or failure will be prevented.

Authentication and access control

  • Authentication is handled through established authentication infrastructure and protected session mechanisms.
  • User-scoped application data is separated through database access policies and server-side ownership checks.
  • Administrative and service access is intended to follow least-privilege and need-to-know principles.
  • Active sessions can be identified and revoked through supported account controls.
  • Sensitive operations may require re-authentication or additional validation.

Encryption and secrets

Cleverfind uses encrypted network transport for production services where supported and appropriate. Broker access tokens stored by the application are encrypted before database storage. Passwords, broker PINs, and one-time passwords should never be sent to Cleverfind support or entered into research chat.

Encryption reduces risk but does not remove it. Security also depends on endpoint protection, key management, access control, software updates, monitoring, and user behaviour.

Broker integrations and uploaded files

Supported broker authorisations are used for the requested data-access feature. Cleverfind does not need or request your broker password, trading PIN, or one-time password and does not use broker access to execute orders.

Uploaded holdings files are validated for supported type and size, processed through a temporary workflow, and intended to be removed from temporary storage after completion or expiry. Extracted portfolio records may remain in your account as described in the Privacy Policy.

Application and infrastructure safeguards

  • Separation of public and authenticated routes and server-side validation of authenticated requests.
  • Input validation, file restrictions, rate limits, and error handling for supported workflows.
  • Restricted environment configuration and secret handling rather than embedding production credentials in client code.
  • Logging intended to support reliability and security investigation without deliberately recording passwords or access tokens.
  • Dependency, configuration, backup, and recovery practices appropriate to an evolving cloud service.

Monitoring and incident response

Cleverfind monitors service health and security-relevant events to the extent reasonably available. Suspected incidents are assessed for scope, containment, remediation, recovery, and lessons learned.

Where an incident creates a notification or reporting duty, Cleverfind will notify affected users and competent authorities in the manner and timeframe required by applicable law, including applicable CERT-In directions and data-protection requirements.

Service-provider risk

Cleverfind depends on cloud, database, authentication, storage, AI, network, and other service providers. We select and configure providers with regard to their role and the sensitivity of data, but cannot guarantee the security or continuous availability of an independent third party.

Provider access is limited to what is reasonably required for the service and is governed by contractual or platform controls where available.

Your security responsibilities

  • Use a secure device, current software, and a protected email account and mobile number.
  • Review active sessions and revoke any you do not recognise.
  • Never share a password, access token, trading PIN, one-time password, or remote-screen access with anyone claiming to represent Cleverfind.
  • Verify that you are using cleverfind.in before entering account information.
  • Report suspected compromise promptly and contact the relevant broker directly if a broker account may also be affected.

Security limitations

No internet transmission, software, storage system, encryption method, or organisational process is completely secure. Unknown vulnerabilities, supply-chain failures, phishing, compromised user devices, third-party outages, and sophisticated attacks can defeat controls.

Do not use Cleverfind as the sole repository for information you must retain. Keep authoritative broker, depository, tax, and transaction records separately.

Responsible security reporting

If you believe you found a vulnerability, email support@cleverfind.in with a clear description, affected URL or feature, reproduction steps, and impact. Do not access another user's data, disrupt the service, use social engineering, perform denial-of-service testing, or publicly disclose an unresolved issue.

We will acknowledge and assess good-faith reports. This policy does not authorise activity that violates law or third-party rights and does not promise a reward.