Last reviewed August 2026
Magdox maintains reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the CERT-In Directions on information security practices, prevention, response, and reporting of cyber incidents, issued under Section 70B of the IT Act.
All connections to the Magdox platform are encrypted via TLS (1.2+). Database connections between the application and our managed database also require TLS. Account data and configured watch lists are encrypted at rest using AES-256 or equivalent, on our infrastructure provider's managed storage and database services.
Magdox supports multi-factor authentication and passwordless sign-in via a time-limited, single-use email code. Permissions within an organization are governed by role-based access control, not left to ad hoc access. Every watch list, signal, and report is scoped to the owning organization at the database layer - one organization's data is never visible to another. Access to production systems is restricted on a role-based, least-privilege basis and logged for audit purposes.
Magdox only collects data that is publicly accessible without authentication. We do not bypass login walls, paywalls, CAPTCHAs, or other technical access-control measures, and we do not collect data in a manner that breaches a source platform's published terms of service. This approach is designed to avoid liability under Sections 43 and 66 of the Information Technology Act, 2000 and analogous unauthorised-access provisions.
State-changing requests are protected using CSRF tokens. Sensitive actions (exports, user and role changes, authentication events) are recorded in an audit log available to organization administrators.
Magdox is hosted on Oracle Cloud Infrastructure (OCI) in the India West (Mumbai) (ap-mumbai-1) region, keeping Customer data within Indian jurisdiction in line with the Digital Personal Data Protection Act, 2023. Our self-managed PostgreSQL database is backed up nightly to object storage with a 14-day retention window, with continuous write-ahead log archiving for point-in-time recovery and daily block volume snapshots. Backups replicate to India South (Hyderabad) so they survive the loss of the primary region. We do not operate standby compute in that region, so recovery is by rebuild-and-restore rather than failover; the full detail, including recovery objectives, is in our Information Security Addendum.
Magdox does not currently hold formal security certifications such as ISO 27001 or SOC 2. We will not claim a certification we have not earned. The controls described on this page (encryption, access control, audit logging, and multi-tenant isolation) are operational today; formal certification is independent verification of those controls, not a prerequisite for them.
In line with applicable CERT-In directions, Magdox enables logging of relevant ICT systems and maintains such logs securely, within Indian jurisdiction, for the rolling period prescribed by CERT-In. Cyber security incidents falling within the categories mandatorily reportable under the CERT-In Directions are reported to CERT-In within six hours of Magdox becoming aware of the incident, with additional details furnished as they become available. Customers are notified of any personal data breach affecting their data as described in our DPA.
Access to customer data is limited to authorised personnel on a need-to-know basis, bound by confidentiality obligations. We conduct periodic access reviews and maintain a documented information security policy covering encryption, access control, vulnerability management, and incident response.
If you believe you have found a security vulnerability or issue, contact us at [email protected], and we will acknowledge your report within one business day and keep you informed of remediation progress.