Security
How SkinsIndia Solutions protects the ShivMail platform and the data you trust us with.
Last updated: 19 May 2026
1. Our approach to security
Security is foundational to ShivMail. We design, build, and operate the platform with defence-in-depth principles so that the email you send — and the data behind it — stays protected. This page describes the technical and organisational measures we use. It is provided for transparency and does not form part of any contract.
2. Data encryption
- In transit — all connections to the dashboard and API are encrypted with TLS 1.2+; outbound email is delivered over opportunistic TLS where the receiving server supports it.
- At rest — databases, backups, and stored assets are encrypted using strong, industry-standard algorithms.
- Secrets — API keys are shown once and stored only as hashes; passwords are stored as salted bcrypt hashes and are never logged.
3. Infrastructure security
The platform runs on hardened, regularly patched servers protected by network firewalls and segmentation between public, application, and data tiers. Administrative access is restricted to authorised engineers over encrypted channels, and production systems are isolated from development and testing environments.
4. Access control
- access to production systems follows the principle of least privilege;
- internal access is granted on a need-to-know basis and reviewed periodically;
- multi-factor authentication is required for administrative accounts; and
- access events are logged for accountability and audit.
5. Application security
We follow secure-development practices including code review, dependency scanning, and input validation. The application enforces authentication on every protected endpoint, applies rate limiting, and validates and sanitises user-supplied content to mitigate injection and cross-site scripting risks.
6. Email authentication and deliverability
ShivMail helps you authenticate your sending domains with DKIM, SPF, and DMARC, and guides you through publishing the required DNS records. We process bounces and complaints automatically, maintain suppression lists, and monitor sending reputation to protect both your deliverability and the health of the platform.
7. Monitoring and incident response
We continuously monitor the availability, performance, and integrity of the platform. Security-relevant events are logged and reviewed. We maintain an incident-response process to triage, contain, and remediate issues, and we will notify affected customers of incidents that materially impact their data without undue delay.
8. Backups and business continuity
Critical data is backed up regularly, and backups are encrypted and tested. Our operational practices are designed to recover service quickly in the event of a disruption while preserving data integrity.
9. Compliance
Our practices are aligned with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the GDPR. See our Privacy Policy, GDPR page, and Data Processing Agreement for details on how we handle personal data.
10. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in ShivMail, please report it privately to privacy@skinsindiasolutions.in with enough detail to reproduce the issue. Please do not access or modify data that is not yours, and give us a reasonable opportunity to remediate before public disclosure. We will acknowledge valid reports and keep you informed of our progress.
11. Contact us
- Security: privacy@skinsindiasolutions.in
- Support: support@shivmail.skinsindiasolutions.in
- Post: SkinsIndia Solutions, KATJURIDANGA, KENDUADIHI, BANKURA, West Bengal, PIN: 722102, India
Questions about this policy?
Contact our team at privacy@skinsindiasolutions.in or write to SkinsIndia Solutions, KATJURIDANGA, KENDUADIHI, BANKURA, West Bengal, PIN: 722102, India.