Skip to content
SaudaFlow
Get a demo
Pricing
Sign inDownload the Android app

SaudaFlow is sold through a short call — we set up your workspace, your projects and your team with you. No card, no self-serve signup.

Security and privacy

Where your data sits, and who can reach it.

Your leads are your business. A CRM asks you to hand over every buyer name, every phone number and every negotiation your firm has going, so the only reasonable posture is to be specific about what happens to them.

This is the short version. The full posture — pillar by pillar, with the sub-processors named — is on the security page, and the legal instruments that bind us to it are in the legal section.

The full security and privacy posture lives at saudaflow.in/security. This page is the Resources doorway to it.

The short version

Six things are true of every SaudaFlow workspace today. None of them are roadmap items.

  • Mumbai data residency — application, database and object storage all sit in the Mumbai region. Nothing leaves India without your explicit instruction.
  • Encrypted at rest with AES-256, in transit over TLS 1.2 or better. Backups carry a separate key envelope.
  • Per-workspace isolation enforced in the database with row-level security, so one tenant cannot read another tenant even through a bug in application code.
  • No standing staff access. Support or legal access is deliberate, scoped, and writes an append-only audit row that you can read in your own workspace.
  • DPDP Act 2023 compliance built into the product — consent capture, data-principal rights workflow and breach notification, not just a policy page.
  • India-first compliance around it: TRAI-compliant recording disclosures in the language your buyer chose, DLT registration support, and GST-correct invoicing on every receipt.

What we deliberately do not claim

A lot of CRMs in this market say "bank-grade" and "military-grade" and stop there. Those phrases mean nothing, so here is what we will not tell you.

We will not tell you SaudaFlow staff are cryptographically incapable of reading your data. Under the architecture we actually run, an authorised, policy-gated, audited access path exists — that is how support fixes your workspace at 9pm and how we answer a lawful order. What we will tell you is that the path is narrow, that nobody stands inside it by default, and that every use of it leaves a row in an audit log you can read without asking us.

We also do not hold certifications we have not earned. If you need a specific attestation for your procurement process, ask on the demo call and we will tell you honestly whether we have it, when we expect it, or that we do not.

Your rights, and how to use them

Under the DPDP Act 2023 your firm is the Data Fiduciary for the buyer data you hold, and AB Corp is your Data Processor. That distinction decides who answers a data-principal request, and the product is built so you can answer one without filing a ticket with us.

Access, correction and erasure requests are handled in-product from your own workspace. Export is yours whenever you want it, in a format you can open — leaving is a supported operation, not a retention tactic.

Security questionnaire, or a specific question?

If your firm has a vendor assessment to run, send it over. We answer questionnaires directly rather than pointing you at a trust-centre portal, and we say "no" to the questions where the answer is no.

Email support@saudaflow.in

For a suspected vulnerability, use the same address with “Security disclosure” in the subject line and we will reply the same working day.

Bring the hard questions to the call

Residency, audit trails, exit terms, whatever your CA or your IT person wants to know. Twenty minutes, straight answers, no card.

Security and privacy — Mumbai-hosted, encrypted, DPDP-compliant · SaudaFlow