LEGAL
Security

Last Updated: June 2026

1

Our Commitment to Security

Security is foundational to everything we build at Mellite. We understand that our platform handles sensitive real estate project data, financial information, and personal details of buyers, developers, and vendors. We are committed to protecting this data with industry-leading security practices.

Our security program is built on three core principles: confidentiality, integrity, and availability. Every feature we ship undergoes security review, and we continuously monitor our infrastructure for threats.

2

Infrastructure Security

Our platform is hosted on enterprise-grade cloud infrastructure with multiple layers of physical and network security:

Cloud Provider Security

Our infrastructure is hosted on SOC 2 Type II certified cloud platforms with 99.9% uptime SLA and built-in DDoS protection.

Network Security

All network traffic is protected by firewalls, intrusion detection systems, and Web Application Firewalls (WAF).

DDoS Protection

We employ enterprise-grade DDoS mitigation to ensure platform availability during high-traffic periods and potential attacks.

Geographic Redundancy

Our infrastructure spans multiple availability zones to ensure service continuity even during regional outages.

Regular Backups

Automated encrypted backups are performed daily and stored in geographically separate data centers.

3

Data Encryption

We use encryption to protect data at every stage - from your browser to our servers and in our databases:

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3. We disable older, insecure protocols and cipher suites.

Encryption at Rest

All data stored in our databases is encrypted using AES-256 encryption. Backup data is also encrypted with the same standards.

Key Management

Encryption keys are managed using secure key management systems with regular key rotation and strict access controls.

End-to-End Encryption

Sensitive communications, including payment data and authentication tokens, use end-to-end encryption where applicable.

4

Access Controls & Authentication

We implement strict access controls to ensure that only authorized personnel can access sensitive data:

Role-Based Access Control

Access to platform features and data is controlled by role-based permissions. Users only have access to the data and features necessary for their role.

Multi-Factor Authentication

Multi-factor authentication (MFA) is available and recommended for all users. We support TOTP-based authenticator apps and SMS-based OTP.

Session Management

User sessions are managed with secure tokens. Sessions expire after periods of inactivity and can be terminated remotely by administrators.

Password Security

Passwords are hashed using bcrypt with high cost factors. We never store passwords in plain text and do not transmit them in an unencrypted form.

Privileged Access

Access to production systems and sensitive data by Mellite employees is governed by a strict privilege management policy with just-in-time access.

5

Application Security

We follow secure software development practices to ensure our applications are built with security in mind from the ground up:

Secure Development Lifecycle

All code undergoes security review before deployment. We follow OWASP guidelines and conduct regular security assessments.

Dependency Scanning

We continuously scan our dependencies for known vulnerabilities and apply patches promptly.

Static & Dynamic Analysis

Our codebase is regularly analyzed using static application security testing (SAST) and dynamic application security testing (DAST) tools.

Penetration Testing

We conduct regular penetration tests by independent security firms to identify and remediate potential vulnerabilities.

Bug Bounty Program

We maintain a responsible disclosure program and encourage security researchers to report vulnerabilities through our bug bounty program.

6

Data Privacy & Compliance

We are committed to protecting your privacy and complying with all applicable data protection regulations:

Privacy by Design

Privacy considerations are embedded into every stage of product development. We collect only the data we need and minimize data exposure.

Data Minimization

We collect and retain only the minimum personal data necessary to provide our Services. Unnecessary data is not collected or is promptly deleted.

Right to Deletion

Users can request deletion of their personal data at any time. We comply with deletion requests within the timeframes specified by applicable law.

Compliance Audits

We conduct regular compliance audits to ensure adherence to applicable regulations, including the Digital Personal Data Protection (DPDP) Act, 2023.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and compliance. Contact: [email protected]

7

Incident Response & Monitoring

We maintain a comprehensive incident response program to detect, respond to, and recover from security incidents:

24/7 Monitoring

Our security operations team monitors our infrastructure and applications 24/7 for suspicious activity and potential threats.

Incident Response Plan

We have a documented incident response plan that defines roles, responsibilities, and procedures for handling security incidents.

Breach Notification

In the event of a data breach that affects your personal information, we will notify you within 72 hours and provide guidance on protective steps you can take.

Forensic Analysis

Security incidents are investigated thoroughly to determine scope, impact, and root cause. Lessons learned are incorporated into our security program.

Regulatory Reporting

We report security incidents to relevant authorities as required by law, including CERT-In for incidents affecting Indian data.

8

Vendor & Third-Party Security

We carefully evaluate and monitor the security practices of our third-party vendors and service providers:

Vendor Assessment

All vendors undergo security assessments before onboarding. We evaluate their security controls, compliance certifications, and data handling practices.

Contractual Obligations

Vendor contracts include strict data protection and security requirements. Vendors must comply with our security standards and applicable regulations.

Continuous Monitoring

We monitor vendor security posture through periodic reviews, certification renewals, and incident notifications.

Limited Data Access

Vendors are granted access only to the data necessary for their specific function. Access is time-limited and revoked when no longer needed.

9

Security Certifications & Standards

We adhere to internationally recognized security standards and are pursuing relevant certifications:

SOC 2 Compliance

Our infrastructure and processes are designed to meet SOC 2 Type II criteria for security, availability, and confidentiality.

OWASP Guidelines

We follow OWASP Top 10 and other industry-standard secure coding guidelines in our application development.

ISO 27001

We are working towards ISO 27001 certification to formalize our information security management system.

Regular Audits

Independent third-party audits are conducted annually to assess our security controls and identify areas for improvement.

10

Employee Security Training

Our employees are our first line of defense. We invest heavily in security awareness and training:

Security Onboarding

All new employees undergo comprehensive security training as part of their onboarding process.

Regular Training

Employees receive regular security awareness training, including phishing simulations and secure coding practices.

Background Checks

All employees undergo background checks before joining. Access to sensitive systems requires additional verification.

Security Culture

We foster a security-first culture where every employee is responsible for protecting customer data and reporting potential security issues.

11

Security Best Practices for Users

While we implement robust security measures, we also encourage our users to follow security best practices:

Strong Passwords

Use strong, unique passwords for your account. Avoid reusing passwords across multiple services.

Enable MFA

Enable multi-factor authentication to add an extra layer of security to your account.

Secure Networks

Access the Platform only from trusted networks. Avoid using public Wi-Fi for sensitive operations without a VPN.

Keep Software Updated

Keep your browser, operating system, and security software up to date to protect against known vulnerabilities.

Report Suspicious Activity

Report any suspicious activity, unauthorized access, or security concerns to us immediately at [email protected].

12

Bug Bounty & Responsible Disclosure

We value the security research community and encourage responsible disclosure of vulnerabilities. If you discover a security vulnerability, please report it to us:

Reporting

Email [email protected] with details of the vulnerability, including steps to reproduce and potential impact.

Response Time

We aim to acknowledge receipt of reports within 24 hours and provide an initial assessment within 5 business days.

Scope

Our bug bounty program covers mellite.app and all associated subdomains. Please do not access or modify data that does not belong to you.

Recognition

We recognize and thank security researchers who help us improve our security. Recognition may include public acknowledgment, swag, or monetary rewards based on severity.

13

Contact Our Security Team

For security-related inquiries, vulnerability reports, or to report a security concern, please contact our security team:

Security Email

[email protected]

Data Protection Officer

[email protected]

Emergency Contact

For critical security incidents requiring immediate attention, please use the subject line "URGENT: Security Incident" in your email.

PGP Key

Our PGP public key is available on request for encrypted communication with our security team.

Your data is protected by enterprise-grade security.