Security at AgatePro

Your leads and buyers are your business. Here's how we keep them that way.

Tenant isolation at the database layer

Every table is protected by PostgreSQL Row-Level Security. Your rows are scoped to your account by the database itself — not just by application code — so one seller can never read another seller's leads, buyers, orders or messages.

Encryption

All traffic is TLS-encrypted in transit. Data is encrypted at rest by our infrastructure providers. Your third-party API keys (e.g. marketplace integrations) are additionally encrypted with AES-256-GCM before storage, and inbound routing tokens are stored only as SHA-256 hashes.

Payments

Payments are processed by Razorpay (PCI DSS Level 1). Card and UPI details never touch our servers. Webhook events are signature-verified and idempotent.

Access & auditing

Passwordless sign-in (phone OTP, Google, email link) — no password database to breach. Admin actions on seller accounts are logged with before/after state. Sessions are invalidated server-side on logout.

Your data, portable

Export your leads, contacts, orders and products any time from Dashboard → Settings → Data export. Disconnecting a channel stops all processing of new data from it; deletion requests are honoured per our Privacy Policy and Data Deletion page.

Responsible disclosure

Found a vulnerability? Email support@mbglobalagate.com (see /.well-known/security.txt). We acknowledge within 2 business days and won't take legal action against good-faith research.

More detail: Privacy Policy · Data Processing Agreement · Data Deletion

Security · AgatePro