crave
Home/Policies/Security & Vulnerabilities

Security & Vulnerabilities

Last updated on February 19, 2026

1. Enterprise Infrastructure Security

At crave., security is built into every layer of our platform. Our cloud infrastructure is hosted in ISO 27001 and SOC 2 Type II certified data centers. All network traffic between your client device and our API servers is protected by TLS 1.3 encryption with strict HTTPS enforcement.

2. Data Protection & Access Controls

AES-256 Encryption at Rest

All customer databases, payment tokens, address records, and order histories are encrypted using strong AES-256 keys.

Phone Number Masking

Calls between delivery partners and customers use encrypted proxy telephony lines to keep personal phone numbers 100% private.

PCI-DSS Payment Compliance

All card transactions are routed directly through PCI-DSS Level 1 compliant gateways (Razorpay/PayTM/UPI hubs).

Role-Based Access Control (RBAC)

Merchant console operators and internal staff have strictly audited, principle-of-least-privilege access permissions.

3. Vulnerability Disclosure & Bug Bounty

We welcome security researchers and ethical hackers to report vulnerabilities under our Responsible Disclosure Program. If you discover a potential security flaw in crave. services:

  • Email details directly to security@crave.app with step-by-step reproduction instructions.
  • Do not access, alter, or breach customer accounts or production data during testing.
  • Give us a reasonable window of 14 calendar days to patch reported vulnerabilities prior to public disclosure.