Security & Data Protection
Last Updated: June 20, 2026
Mining logistics involves high-density operations and confidential financial data. At KhadaanExpress, we treat information security as our highest priority. Below is a breakdown of our technical defenses and data protection policies.
1. Data Encryption
We implement comprehensive encryption protocols to ensure security of your files and records:
- In Transit: All data exchanged between your browser, mobile PWA, and our cloud API is encrypted using secure TLS 1.3 protocol.
- At Rest: We utilize secure database systems with built-in AES-256 block encryption for physical disks.
2. Database Isolation & Row-Level Security
To prevent cross-tenant leakages, we enforce strict Row-Level Security (RLS) policies within our PostgreSQL database. Every query executed by the backend services requires validation of your unique `user_id`. One contractor can never view or modify records belonging to another company.
3. Granular Role-Based Permissions
The platform enables account owners (the transport contractor) to set specific functional privileges for sub-accounts. You can customize rights (view, add, edit, delete) per module:
- Supervisors: Allowed to add daily challans and attendance without access to financial ledger balances.
- Accountants: Allowed to edit transaction sheets and export invoice summaries.
- Fleet Managers: Allowed to review mechanical service logs and document renewals.
4. Backup and Disaster Recovery
We perform automated nightly backups of our database clusters, which are replicated across separate availability zones. In the event of a cloud hardware failure, our recovery plan allows us to restore full operational services with minimal data loss.
5. Reporting Vulnerabilities
If you identify a security issue or susceptibility in our software API, please report it to our engineering team at:
KhadaanExpress Security Audit Desk
Email: khadaanexpress@gmail.com
