Institutional Security & Infrastructure

Trustlink Investor Services enforces bank-grade encryption, presigned S3 document isolation, Multi-Factor Authentication (MFA), and strict SEBI Cyber Resilience Framework protocols.

AWS S3 Presigned Vault

All investor identity documents (COI, PAS-3, PAN, Form ISR) are stored in encrypted AWS S3 buckets using short-lived presigned URLs to prevent unauthorized direct URL guessing.

TLS 1.3 & HSTS Enforced

Full-site SSL encryption with HTTP Strict Transport Security (HSTS) prevents man-in-the-middle attacks and enforces secure HTTPS connections across all endpoints.

VAPT & Audit Logging

Regular Vulnerability Assessment and Penetration Testing (VAPT) conducted by CERT-In empaneled auditors. Every administrative action is logged to an immutable audit ledger.

SEBI Cyber Resilience Framework Compliance

Security StandardImplementation ControlAudit Status
Multi-Factor Authentication (MFA)Enforced TOTP / SMS OTP authentication for administrative loginsCOMPLIANT
Data At Rest EncryptionAES-256 server-side encryption for PostgreSQL & AWS S3 object storeCOMPLIANT
Role-Based Access Control (RBAC)Strict separation between public investor view, client entity desk, and registry adminCOMPLIANT
Annual VAPT CertificationCERT-In certified third-party vulnerability audit executed annuallyVERIFIED