Security Practices for Alert21
Alert21 is a business communication platform operated by Scriza Private Limited. We use a layered security approach designed to protect customer accounts, API access, service data and platform operations. Security controls are reviewed and improved as the platform, threat landscape and regulatory requirements evolve.
1. Security by Design
We design the platform with separation of environments, restricted administrative access, secure credential handling, auditability and defense-in-depth principles. Production access is limited to authorized personnel and should follow least-privilege practices.
2. Data in Transit and at Rest
Alert21 uses encrypted network connections such as HTTPS/TLS for supported web and API traffic. Data at rest is protected using security controls appropriate to the hosting, database and storage systems in use. The exact implementation can vary by service and provider.
3. Account and API Security
- Strong authentication for user and administrative access.
- API keys or credentials scoped to authorized accounts and environments.
- Credential revocation and rotation when compromise is suspected.
- IP restrictions, rate limits or additional controls where the product supports them.
- Protection against brute-force, abuse and automated misuse.
4. Logging, Monitoring and Auditability
We maintain operational and security logging appropriate to the service, including authentication events, API activity, administrative actions, errors and delivery events where applicable. Monitoring is used to investigate failures, detect abnormal activity and support incident response.
5. Secure Software Development
- Review of production changes before release.
- Use of staging/testing before material production changes.
- Dependency and vulnerability management.
- Secret-management practices intended to prevent credentials from being stored in public code or client-side applications.
- Security testing appropriate to the risk and maturity of each service.
6. Backups and Resilience
Alert21 maintains backup, recovery and service-continuity practices appropriate to the systems in production. Recovery design may differ by component, and no backup mechanism can eliminate every possible interruption or loss scenario.
7. Customer Responsibilities
Customers are responsible for protecting their Alert21 login credentials, API keys and webhook secrets; limiting staff access; securing their own applications and endpoints; validating recipient and template data; and rotating exposed credentials without delay. Customers should notify Alert21 promptly if they suspect unauthorized access or compromise.
8. Security Incidents
We maintain incident-response procedures for investigating suspected security events, containing impact, restoring service and notifying affected customers or authorities when required by applicable law or contract.
9. Report a Security Concern
Security vulnerabilities or suspected platform security issues should be reported to info@scriza.in. Please do not publicly disclose a vulnerability before giving Alert21 reasonable time to investigate and remediate it.
Turn your next business event into a traceable alert.
Start with DLT-ready SMS today on Alert21’s developer-first communication platform.
