Security Standards
Cyber Security & Infrastructure DisclosuresAt FundVerse Wealth LLP (“TheFundVerse”), financial security is embedded into every layer of our technical stack. We maintain enterprise-grade cyber defense protocols to ensure your personal data, identity documents, and mutual fund transaction requests remain fully encrypted and confidential.
1. End-to-End Transport & At-Rest Encryption
- 256-Bit TLS 1.3 Transport Encryption: All data transmitted between your browser and our servers is secured using TLS 1.3 encryption protocols, preventing eavesdropping and tampering.
- AES-256 Storage Encryption: Sensitive e-KYC documents, PAN details, Aadhaar payloads, and bank account IFSC codes are stored using AES-256 cryptographic standards.
- Zero Plaintext Sensitive Storage: User authentication credentials use salted argon2/bcrypt hashing. We never store plain text passwords, payment card CVVs, or net banking passwords.
2. Session Safeguards & Authentication Controls
Our platform incorporates strict session lifecycle controls to prevent unauthorized access:
- Automatic Session Inactivity Timeout: Investor sessions automatically expire after 15 minutes of inactivity to protect unauthorized access on shared devices.
- Multi-Factor Authentication (MFA): Critical transaction approvals and bank mandate modifications require one-time passcode (OTP) verification.
- Strict Role-Based Access Control (RBAC): Administrative access to user records is strictly restricted and audited.
3. Direct SEBI & AMC Integration Pipelines
Mutual fund order processing is routed directly through SEBI-approved settlement infrastructures (BSE StAR MF / NSE NMF II) and official AMCs. Investor funds move directly from your verified bank account to AMC mutual fund collection escrow accounts. TheFundVerse never pools investor monies in proprietary accounts.
4. Vulnerability Disclosure & Responsible Reporting Policy
We welcome collaboration with cybersecurity researchers to safeguard our ecosystem. If you discover a potential vulnerability in our web applications, APIs, or infrastructure, please report it responsibly to our security response team: