Security
Last updated 19 September 2026
Your CRM holds your customers' details, so we build Bizkar to keep each organization's data separate, to give people only the access their role needs, and to make any access by our own staff visible to you.
Signing in
- Sign-in is handled by a dedicated identity service. Bizkar CRM itself never receives or stores your password.
- Passwords must be at least 8 characters and mix upper-case letters, lower-case letters, digits and a special character; a password that contains your email or username, or is on a list of common passwords, is refused.
- An account must confirm its email address before it can invite anyone or pay for a plan, because invitations are sent in its name.
- Repeated failed sign-in attempts are detected and blocked.
- You can turn on two-factor authentication with an authenticator app, and review and sign out your devices, from your account page.
- In the browser, your access token is kept in memory, not in browser storage.
Keeping organizations apart
- Every record belongs to one organization, and every database query is limited to the organization you are signed in to. The organization is taken from your sign-in, never from anything a browser sends.
- A request for another organization's record is answered as if the record did not exist.
Access inside an organization
- Access is based on permissions granted to roles, such as viewing, creating, updating or deleting each kind of record. The server checks them on every request.
- A role change applies on the member's next request, with nothing to wait for.
- Billing and ownership changes are reserved for organization owners.
Access by Bizkar staff
- Our operator tools are reachable only from our own network, and privileged actions require operators to sign in again.
- Operator actions are recorded in an audit trail.
- Support can enter your organization only while your organization has granted access, for the period you choose; revoking it ends any session at once, and we have no override. Within a grant, the operator must give a reason and the session is time-limited. When it ends, your organization administrators are emailed who accessed it, as whom, when and why.
Payments
Payments are processed by Razorpay. Card and bank details are entered into Razorpay's checkout and never reach our servers. Payment notifications from Razorpay are verified with a shared signature before we act on them.
In transit
All traffic to bizkar.in and its services is served over HTTPS. Our web apps send a strict Content Security Policy and refuse to be embedded in other sites.
Reporting a vulnerability
If you believe you have found a security issue, please emailsecurity@bizkar.in with the details and steps to reproduce it. Please give us reasonable time to fix it before telling anyone else, and do not access or change other people's data, degrade the service, or run automated scans while testing. We will acknowledge your report and keep you updated while we work on it.