Security

How JottoSop protects your data and transactions.

Your trust is our foundation.

JottoSop is built with security-first architecture. Every layer — from login to payout — is designed to protect both customers and sellers.

Customer Security

How we protect every shopper on JottoSop

Secure Payments via Razorpay

PCI DSS

All payments are processed by Razorpay — a PCI DSS Level 1 certified gateway. We never store your card details on our servers.

End-to-End HTTPS Encryption

TLS 1.2+

Every request between your browser and our servers is encrypted using TLS 1.2+. Your personal and payment data is always in transit securely.

We Never Sell Your Data

Your name, address, phone number, and order history are used solely to process your orders. We do not sell or share your data with third-party advertisers.

Password Protection

bcrypt

Passwords are hashed using bcrypt with salt rounds before storage. Even our team cannot see your password in plain text.

Order & Account Alerts

You receive real-time notifications for every order placed, shipped, or cancelled. If you notice unexpected activity, contact us immediately.

COD & Refund Protection

Cash-on-Delivery orders are protected with order verification. Refund requests are reviewed within 48 hours and processed within 5–7 business days.

Seller Security

How we keep your business and earnings safe

KYC Verification

Mandatory

Every seller undergoes a mandatory KYC process before listing products. We verify PAN, GST, and business address to ensure platform authenticity.

GST-Compliant Invoicing

All transactions generate GST-compliant invoices automatically. Sellers' financial data is isolated per business account and never shared across sellers.

Role-Based Access Control

RBAC

Seller dashboards support staff accounts with granular permissions. You control who on your team can view orders, manage inventory, or access financials.

Secure Payouts

Seller settlements are processed only to verified bank accounts linked during KYC. Payout requests require authentication before processing.

Fraud Detection

Suspicious order patterns, unusually high COD rates, and fake review activity are flagged automatically and reviewed by our trust & safety team.

API Key Isolation

API-level

Each seller's data is scoped strictly to their business ID. Cross-seller data access is blocked at the API level — not just the UI level.

Platform Infrastructure

What runs under the hood

Hosting

Cloud-hosted with 99.9% uptime SLA

Database

Encrypted PostgreSQL with daily backups

File Storage

S3-compatible object storage with signed URLs

API Security

JWT auth + rate limiting on all endpoints

Images

User uploads scanned before storage

Monitoring

24/7 error tracking and alerting

Security FAQs

Common questions about your safety

Found a security issue?

We take vulnerability reports seriously. If you discover a security concern, please report it directly to [email protected] and we will investigate within 24 hours.

Report Issue

JottoSop — Digitalizing Small Businesses with ❤️ in Bengal

Last updated: March 2026 · For privacy concerns see our Privacy Policy