1. Certifications and Compliance
Verified standards covering digital infrastructure and jewelry authenticity.All card payments and UPI transactions are routed via RBI-licensed, PCI-DSS Level 1 certified payment processors (Razorpay & PhonePe). VFS Jewels never stores raw credit/debit card numbers or CVVs on our servers.
Our cloud infrastructure and internal operations adhere to ISO/IEC 27001 information security management principles for access control, disaster recovery, and network isolation.
Strict compliance with the Digital Personal Data Protection Act of India. We enforce explicit consent, data minimization, and automated user data deletion workflows.
Physical jewelry certification ensuring 100% nickel-free, lead-free surgical stainless steel with vacuum-deposited 18K Real Gold plating certified for dermatological safety.
2. Plain-Language Data Encryption
How your personal identity, addresses, and order records are secured.We believe you shouldn't need a computer science degree to understand how your data is protected. Here is our plain-language guarantee:
| State | Encryption Protocol | Plain-Language Explanation |
|---|---|---|
| Data In Transit | TLS 1.3 / SSL (256-Bit) |
Every click, search, cart update, and payment checkout is wrapped inside an encrypted tunnel so eavesdroppers on public Wi-Fi or networks cannot intercept your information. |
| Data At Rest | AES-256 Bit Encryption |
All customer profiles, order history, GST invoice PDFs, and WhatsApp photo slips are stored in databases encrypted with industry-standard AES-256 keys. |
| Payment Credentials | Tokenized Zero-Storage |
Raw banking passwords, PINs, and card numbers never touch our servers. Transactions are completed via encrypted tokens directly with your bank. |
3. Data Residency & Regional Storage
Where your data lives and processes.In accordance with Reserve Bank of India (RBI) guidelines and the Indian DPDP Act, 100% of customer personal data, wholesale ledger accounts, and transaction records are stored strictly within India.
| Data Category | Primary Location | Redundancy / Backup |
|---|---|---|
| Customer Profiles & Orders | AWS / Google Cloud (Mumbai Region, India - ap-south-1) |
Daily encrypted backup in Hyderabad Data Center |
| Payment Logs & GST Invoices | Razorpay / NPCI India Data Centers | Compliant with 7-year statutory financial retention |
| Media & Photo Slips | Cloudinary Secure CDN Edge (India Pop Points) | Multi-zone geo-redundant storage |
4. Strict Internal Access Controls
Who can see customer data and under what rules.We enforce the principle of Least Privilege (PoLP) across our team:
- Role-Based Access Control (RBAC): Dispatch and warehouse staff only see the customer's shipping address and ordered item SKUs. They have zero access to financial or payment records.
- Multi-Factor Authentication (MFA): All admin portals and wholesale manager consoles require hardware/authenticator-app 2FA before login.
- Immutable Audit Logging: Every administrative data view, invoice export, or account change is logged with timestamp, staff ID, and IP address.
- No Third-Party Data Selling: We never sell, rent, or trade your contact info or purchasing habits to third-party ad networks or brokers.
5. Vulnerability Disclosure & Bug Bounty
How security researchers can report issues responsibly.We welcome responsible security disclosures from white-hat researchers, ethical hackers, and engineers.
โฑ๏ธ Response SLA: We acknowledge reports within 24 to 48 hours.
๐ค Safe Harbor: We commit to not pursuing legal action against researchers acting in good faith under responsible disclosure guidelines.
๐ Recognition: Valid security reports receive a shoutout on our Security Hall of Fame and store credits/swag.
6. Transparent Incident History
Public record of system uptime, security audits, and disclosures.All payment webhooks, database clusters, and cloud storage systems are operating with 100% data integrity and zero reported incidents.
Completed comprehensive static and dynamic application security testing (SAST/DAST). 0 critical or high vulnerabilities identified.
Upgraded edge certificates to TLS 1.3 with Cloudflare automated Layer 7 DDoS mitigation for 99.99% uptime.
7. Penetration Testing & Security Audits
Rigorous independent evaluations of our code and infrastructure.VFS Jewels engages independent third-party cybersecurity auditors to perform semi-annual penetration testing against OWASP Top 10 vulnerabilities (including SQL Injection, Cross-Site Scripting, Broken Access Control, and Insecure Direct Object References).
Request a Security Audit Summary
Are you a B2B wholesale partner, corporate gifting client, or boutique reseller requiring a compliance report?
๐ฉ Request Security & Compliance Report
โ Back to Shop