Security Principles & Architecture
We believe financial privacy and enterprise security should be transparent, straightforward, and built into every layer.
1. Zero-Custody Model
MicroInvestments.in NEVER holds your investment money, manages client bank balances, or executes trades on your behalf. We provide purely educational tools, calculators, and research snapshots. Your capital remains safe in your own regulated bank or brokerage accounts.
2. End-to-End Transport Security & Zero Card Storage
All data transmitted between your browser and our servers is encrypted with TLS 1.3 / HTTPS. All ₹1 transactions are processed directly through PCI-DSS Level 1 certified payment gateways (Razorpay). We never see, handle, or store your debit card numbers, CVVs, or bank passwords.
3. Server-Side Hardening & Rate Limiting
Every API endpoint is protected against brute-force attacks via token-bucket rate limiting. All database operations use parameterized Prisma ORM queries to prevent SQL injections. Strict Content Security Policies (CSP) and frame-ancestors headers block cross-site scripting (XSS) and clickjacking.