Growarth Capita
Security & Compliance

Your Data Is Safe With Us

At Growarth Capita, we treat your personal and financial data with the highest level of security and confidentiality. Our practices meet or exceed industry standards and regulatory requirements.

Security Measures

Every layer of our infrastructure is designed to protect your information from unauthorised access, disclosure, or loss.

256-Bit Encryption

All data transmitted between your browser and our servers is encrypted using TLS 1.3 with 256-bit AES encryption — the same standard used by leading financial institutions.

Secure Infrastructure

Our systems are hosted in ISO 27001-certified data centres with 24/7 monitoring, biometric access controls, redundant power, and multi-layered firewalls.

Access Controls

Strict role-based access controls ensure that only authorised personnel with a legitimate business need can access your data. All access is logged and audited.

Regulatory Compliance

We comply with applicable data protection regulations including the IT Act, 2000 and its amendments. We follow RBI guidelines on data storage and outsourcing of financial services.

Regular Audits

Our security infrastructure undergoes regular vulnerability assessments, penetration testing, and compliance audits by independent third-party firms.

Data Backup & Recovery

Automated encrypted backups are performed daily with redundant storage across geographically separate locations. Our RPO is under 1 hour and RTO under 4 hours.

Regulatory Compliance

We operate in full compliance with Indian data protection and financial services regulations. Our compliance framework is reviewed quarterly and updated to reflect regulatory changes.

  • Information Technology Act, 2000 and IT (Reasonable Security Practices) Rules, 2011
  • RBI Master Direction on Outsourcing of Financial Services
  • RBI Guidelines on Data Localisation and Storage
  • ISO 27001:2022 aligned information security practices
  • PCI DSS compliant data handling for payment information
  • GDPR principles applied to EU customer data

Confidentiality Commitment

Confidentiality is the foundation of our customer relationship. Every individual and organisation that handles your data is bound by strict confidentiality obligations.

Non-Disclosure

All employees and contractors sign comprehensive NDAs. Customer data access is granted strictly on a need-to-know basis.

Data Minimisation

We collect only the information necessary for loan processing. We do not retain data beyond the legally mandated retention period.

Third-Party Vetting

All partner banks and NBFCs undergo security due diligence before integration. Data-sharing agreements mandate equivalent security standards.

Breach Notification

In the unlikely event of a data breach, affected customers will be notified within 72 hours along with remediation steps.

Our Commitment

We continuously invest in our security infrastructure, train our team on data protection best practices, and engage independent auditors to validate our controls. If you have any questions about our security practices, please contact our Data Protection Officer at info@growarthcapita.com.