Last Updated: June 2026
Our Commitment to Security
Security is foundational to everything we build at Mellite. We understand that our platform handles sensitive real estate project data, financial information, and personal details of buyers, developers, and vendors. We are committed to protecting this data with industry-leading security practices.
Our security program is built on three core principles: confidentiality, integrity, and availability. Every feature we ship undergoes security review, and we continuously monitor our infrastructure for threats.
Infrastructure Security
Our platform is hosted on enterprise-grade cloud infrastructure with multiple layers of physical and network security:
Cloud Provider Security
Our infrastructure is hosted on SOC 2 Type II certified cloud platforms with 99.9% uptime SLA and built-in DDoS protection.
Network Security
All network traffic is protected by firewalls, intrusion detection systems, and Web Application Firewalls (WAF).
DDoS Protection
We employ enterprise-grade DDoS mitigation to ensure platform availability during high-traffic periods and potential attacks.
Geographic Redundancy
Our infrastructure spans multiple availability zones to ensure service continuity even during regional outages.
Regular Backups
Automated encrypted backups are performed daily and stored in geographically separate data centers.
Data Encryption
We use encryption to protect data at every stage - from your browser to our servers and in our databases:
Encryption in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.3. We disable older, insecure protocols and cipher suites.
Encryption at Rest
All data stored in our databases is encrypted using AES-256 encryption. Backup data is also encrypted with the same standards.
Key Management
Encryption keys are managed using secure key management systems with regular key rotation and strict access controls.
End-to-End Encryption
Sensitive communications, including payment data and authentication tokens, use end-to-end encryption where applicable.
Access Controls & Authentication
We implement strict access controls to ensure that only authorized personnel can access sensitive data:
Role-Based Access Control
Access to platform features and data is controlled by role-based permissions. Users only have access to the data and features necessary for their role.
Multi-Factor Authentication
Multi-factor authentication (MFA) is available and recommended for all users. We support TOTP-based authenticator apps and SMS-based OTP.
Session Management
User sessions are managed with secure tokens. Sessions expire after periods of inactivity and can be terminated remotely by administrators.
Password Security
Passwords are hashed using bcrypt with high cost factors. We never store passwords in plain text and do not transmit them in an unencrypted form.
Privileged Access
Access to production systems and sensitive data by Mellite employees is governed by a strict privilege management policy with just-in-time access.
Application Security
We follow secure software development practices to ensure our applications are built with security in mind from the ground up:
Secure Development Lifecycle
All code undergoes security review before deployment. We follow OWASP guidelines and conduct regular security assessments.
Dependency Scanning
We continuously scan our dependencies for known vulnerabilities and apply patches promptly.
Static & Dynamic Analysis
Our codebase is regularly analyzed using static application security testing (SAST) and dynamic application security testing (DAST) tools.
Penetration Testing
We conduct regular penetration tests by independent security firms to identify and remediate potential vulnerabilities.
Bug Bounty Program
We maintain a responsible disclosure program and encourage security researchers to report vulnerabilities through our bug bounty program.
Data Privacy & Compliance
We are committed to protecting your privacy and complying with all applicable data protection regulations:
Privacy by Design
Privacy considerations are embedded into every stage of product development. We collect only the data we need and minimize data exposure.
Data Minimization
We collect and retain only the minimum personal data necessary to provide our Services. Unnecessary data is not collected or is promptly deleted.
Right to Deletion
Users can request deletion of their personal data at any time. We comply with deletion requests within the timeframes specified by applicable law.
Compliance Audits
We conduct regular compliance audits to ensure adherence to applicable regulations, including the Digital Personal Data Protection (DPDP) Act, 2023.
Data Protection Officer
We have appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and compliance. Contact: [email protected]
Incident Response & Monitoring
We maintain a comprehensive incident response program to detect, respond to, and recover from security incidents:
24/7 Monitoring
Our security operations team monitors our infrastructure and applications 24/7 for suspicious activity and potential threats.
Incident Response Plan
We have a documented incident response plan that defines roles, responsibilities, and procedures for handling security incidents.
Breach Notification
In the event of a data breach that affects your personal information, we will notify you within 72 hours and provide guidance on protective steps you can take.
Forensic Analysis
Security incidents are investigated thoroughly to determine scope, impact, and root cause. Lessons learned are incorporated into our security program.
Regulatory Reporting
We report security incidents to relevant authorities as required by law, including CERT-In for incidents affecting Indian data.
Vendor & Third-Party Security
We carefully evaluate and monitor the security practices of our third-party vendors and service providers:
Vendor Assessment
All vendors undergo security assessments before onboarding. We evaluate their security controls, compliance certifications, and data handling practices.
Contractual Obligations
Vendor contracts include strict data protection and security requirements. Vendors must comply with our security standards and applicable regulations.
Continuous Monitoring
We monitor vendor security posture through periodic reviews, certification renewals, and incident notifications.
Limited Data Access
Vendors are granted access only to the data necessary for their specific function. Access is time-limited and revoked when no longer needed.
Security Certifications & Standards
We adhere to internationally recognized security standards and are pursuing relevant certifications:
SOC 2 Compliance
Our infrastructure and processes are designed to meet SOC 2 Type II criteria for security, availability, and confidentiality.
OWASP Guidelines
We follow OWASP Top 10 and other industry-standard secure coding guidelines in our application development.
ISO 27001
We are working towards ISO 27001 certification to formalize our information security management system.
Regular Audits
Independent third-party audits are conducted annually to assess our security controls and identify areas for improvement.
Employee Security Training
Our employees are our first line of defense. We invest heavily in security awareness and training:
Security Onboarding
All new employees undergo comprehensive security training as part of their onboarding process.
Regular Training
Employees receive regular security awareness training, including phishing simulations and secure coding practices.
Background Checks
All employees undergo background checks before joining. Access to sensitive systems requires additional verification.
Security Culture
We foster a security-first culture where every employee is responsible for protecting customer data and reporting potential security issues.
Security Best Practices for Users
While we implement robust security measures, we also encourage our users to follow security best practices:
Strong Passwords
Use strong, unique passwords for your account. Avoid reusing passwords across multiple services.
Enable MFA
Enable multi-factor authentication to add an extra layer of security to your account.
Secure Networks
Access the Platform only from trusted networks. Avoid using public Wi-Fi for sensitive operations without a VPN.
Keep Software Updated
Keep your browser, operating system, and security software up to date to protect against known vulnerabilities.
Report Suspicious Activity
Report any suspicious activity, unauthorized access, or security concerns to us immediately at [email protected].
Bug Bounty & Responsible Disclosure
We value the security research community and encourage responsible disclosure of vulnerabilities. If you discover a security vulnerability, please report it to us:
Reporting
Email [email protected] with details of the vulnerability, including steps to reproduce and potential impact.
Response Time
We aim to acknowledge receipt of reports within 24 hours and provide an initial assessment within 5 business days.
Scope
Our bug bounty program covers mellite.app and all associated subdomains. Please do not access or modify data that does not belong to you.
Recognition
We recognize and thank security researchers who help us improve our security. Recognition may include public acknowledgment, swag, or monetary rewards based on severity.
Contact Our Security Team
For security-related inquiries, vulnerability reports, or to report a security concern, please contact our security team:
Security Email
Data Protection Officer
Emergency Contact
For critical security incidents requiring immediate attention, please use the subject line "URGENT: Security Incident" in your email.
PGP Key
Our PGP public key is available on request for encrypted communication with our security team.