01Our approach
Nidavellir Software Private Limited ("Nidavellir") builds every product — Shrno, Commenda, Attune and Calibrate — on shared, security-first foundations. Because all products authenticate through one Nidavellir account and share common infrastructure, the protections described here apply consistently across everything we operate.
We take a defence-in-depth approach: no single control is relied on alone. We combine encryption, strict access management, network isolation, monitoring and regular review so that a weakness in one layer does not expose your data.
02Infrastructure & hosting
Our services run on reputable cloud infrastructure providers that maintain industry-recognised certifications (such as ISO 27001 and SOC 2) for their physical and environmental security. We do not operate our own data centres.
- Production systems are isolated from development and staging environments.
- Services communicate over private networks wherever possible, with public exposure limited to what is strictly required.
- Infrastructure is provisioned as code so changes are reviewable and repeatable.
03Encryption
- In transit: all traffic to and between our services is encrypted using TLS 1.2 or higher.
- At rest: databases and object storage holding customer data are encrypted at rest using industry-standard algorithms (AES-256 or equivalent).
- Secrets: credentials, API keys and tokens are stored in managed secret stores, never in source code.
04Access control
Access to production systems and customer data is restricted to the minimum number of personnel required to operate the service, and is granted on a least-privilege basis.
- Administrative access requires strong authentication, including multi-factor authentication.
- Access is reviewed periodically and revoked promptly when no longer needed.
- Actions on production systems are logged for accountability.
05Payment security
Payments are processed by our Merchant of Record, Paddle.com Market Limited, over a PCI-DSS compliant checkout. Nidavellir never sees or stores full card numbers. See our Sub-processors list and Privacy Policy for details on how billing data is handled.
06Monitoring, backups & resilience
- Systems and application logs are monitored for anomalous activity.
- Customer data is backed up regularly, and restores are tested so we can recover from failures.
- We maintain an incident response process to detect, contain and communicate about security events.
07Your data & your rights
How we collect, use and share personal data — and the rights you have over it — is described in our Privacy Policy. Where we process personal data on your behalf as a business customer, the terms in our Data Processing Agreement apply.
08Reporting a vulnerability
We welcome reports from security researchers and users. If you believe you have found a security vulnerability, please email us at info@nidavellirs.com with enough detail to reproduce the issue. Please give us a reasonable opportunity to investigate and fix the problem before any public disclosure.
Questions about this policy?
Contact Nidavellir Software Private Limited at info@nidavellirs.com. Registered office: Nidavellir Software Private Limited, Chouksey Niwas, NH 12, Hoshangabad Road, Ward No. 85, Samardha, Bhopal, Madhya Pradesh 462046, India.