Home › Security
Security
Last updated: 24 September 2026
How we protect your data
- TLS everywhere; HSTS on all domains; security headers (CSP, frame-ancestors, referrer-policy).
- Passwords hashed with strong adaptive hashing; secrets in vaults, never in code or images.
- Least-privilege access, per-service database credentials, pooled TLS connections.
- Nightly encrypted backups with tested restores; bounded log retention.
- Payments fully delegated to our payment processor — card/UPI credentials never touch our servers.
Responsible disclosure
We welcome good-faith research on destrocorp.com, kirvyn.com, auditscan.sh and buildopsy.com. Rules: no data destruction, no exfiltration beyond proof-of-concept, no social engineering, no DoS. Report to grievance@destrocorp.com with steps to reproduce, impact and your contact.
- Acknowledgement: 24 hours. Triage: 5 business days. Fix SLA: 90 days for validated issues.
- Safe harbor: we will not pursue legal action for good-faith research within these rules, and we ask you to give us the fix window before public disclosure.