Policy
Security
What ASTRA does to keep accounts and data safe — honestly described.
Last updated: January 2026
1. Transport and storage
All traffic is served over HTTPS in transit. Workspace data is encrypted at rest on our infrastructure. Both are industry-standard protections applied by default.
2. Passwords and login
Passwords are hashed using a strong, one-way algorithm — they are never stored in plain text and are never readable by us. Login sessions use secure, httpOnly cookies with CSRF protection on every state-changing request. Login attempts from new devices are watched, and suspicious activity can trigger email notification.
3. Payments
Payments are processed by Razorpay. Card details are entered on Razorpay\'s hosted checkout and never touch our servers, so ASTRA never stores or processes your card number. We verify payment callbacks through signed responses rather than trusting client data.
4. Access controls
Workspace data is scoped to your account: you see your own records, and only you. Administrative access to production systems is limited, logged and restricted to the team members who need it.
5. What this means
No system is unhackable, and we do not claim to be. What we do claim is that security is treated as a default part of the product — encrypted, hashed, scoped and audited — not an afterthought.
6. Reporting a vulnerability
If you find a security issue in ASTRA, please report it through the contact page rather than in public. We will respond, fix it promptly and credit you if you wish.
Questions about this page?
Write to us and a human will answer. We keep policies in plain language on purpose.