Security & compliance

Trust, engineered as infrastructure

From bank-held funds to signed APIs and immutable audits, security isn't a feature at TitanTrustee — it's the foundation everything else is built on.

Defence in depth

Six pillars of platform security

Funds in regulated banks

Money is held only in RBI-regulated bank escrow accounts — never a TitanTrustee wallet.

Encryption everywhere

TLS in transit and encryption at rest, with strict key management practices.

Signed APIs & webhooks

HMAC-SHA256 signing, timestamp tolerance, nonce replay protection, constant-time checks.

Immutable audit trail

Tamper-evident logging of every action for regulators, partners, and your auditors.

KYB, AML & risk

PMLA-grade onboarding, sanctions screening, and continuous risk scoring.

Least-privilege access

Role-based access, MFA for privileged consoles, and scoped API keys.

Compliance posture

Built for audits, not against them

Controls that satisfy regulators and partners — verifiable through our public security metadata endpoint.

  • Non-custodial architecture — platform never holds funds
  • OWASP API Top 10 controls mitigated
  • Strict CORS allowlist and security headers (CSP, HSTS)
  • Authentication rate limiting and brute-force protection
  • Sanitised error responses — no stack traces in production
  • Versioned APIs with a clear deprecation policy
  • Responsible disclosure

    Found a vulnerability? Report it to security@titantrustee.com. We acknowledge within 2 business days.

    Uptime & reliability

    Health checks, watchdogs, and automated failover keep the platform online with a 99.9% target.

    Trustee partners

    SEBI-trustee integration enables independent adjudication where regulation requires it.

    Want our full security brief?

    Spin up a sandbox in minutes. Move real money when you're ready — funds always stay in RBI-regulated bank escrow.