Security & Data Protection
How we protect your data and keep the RouteOneX platform reliable — encryption, access control, India data residency and PCI-scoped payments.
Last updated · July 2026
Encryption
All traffic between your browser or systems and RouteOneX is encrypted in transit using TLS 1.2 or higher, with modern cipher suites and HSTS enforced. Data at rest — including shipment records, wallet ledgers and KYC documents — is encrypted using AES-256 on managed, access-controlled storage. Encryption keys are managed through our cloud provider's key-management service and rotated on a defined schedule.
Access control & RBAC
Access to production systems follows the principle of least privilege. Internally, engineers and support staff receive only the access their role requires, protected by single sign-on and mandatory multi-factor authentication. Administrative access is logged and reviewed periodically.
Within your own account, role-based access control (RBAC) lets you give team members scoped permissions — for example, an operations user who can book and track shipments but cannot withdraw wallet funds or change bank details. Sensitive actions are recorded in an audit trail.
Infrastructure & uptime
RouteOneX runs on hardened, industry-leading cloud infrastructure with network isolation, managed firewalls and continuous monitoring. We deploy across multiple availability zones and target 99.9% platform uptime, with automated backups and a tested recovery process so your shipping operations stay resilient. Security patches are applied on a regular cadence, and production changes go through code review and automated testing before release.
Data privacy & residency
Seller, shipment and consignee data is hosted on infrastructure located in India, keeping your data within Indian jurisdiction. We process personal data in line with our Privacy Policy and applicable Indian law, including the Digital Personal Data Protection Act, 2023. Data is shared with courier and banking partners only to the extent needed to deliver shipments and remit COD, and never sold for third-party marketing.
Payments & PCI
Wallet recharges and card payments are processed by a PCI-DSS compliant payment gateway. RouteOneX does not store full card numbers, CVV or other sensitive cardholder data on our systems — card details are captured and tokenised directly by the gateway, keeping the cardholder environment outside our platform's scope. COD remittance flows through regulated banking partners to your verified account.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in RouteOneX, please report it privately to security@routeonex.com with enough detail to reproduce the issue. Please give us reasonable time to investigate and remediate before any public disclosure, and avoid accessing or modifying other users' data, degrading the service, or running automated scanning that could affect availability. We will acknowledge valid reports and keep you updated on the fix.
Contact
For security questions, vulnerability reports or a copy of our security documentation for vendor review, contact security@routeonex.com, or write to RouteOneX Technologies Pvt. Ltd., WeWork Galaxy, 43 Residency Road, Bengaluru, Karnataka 560025, India.