Security
Security practices
Current safeguards and clear boundaries—without unsupported certification claims.
Effective 28 July 2026
Current safeguards
- HTTPS for production web and API traffic.
- Role and account controls enforced by product backends, not only hidden user-interface controls.
- Adaptive password hashing and restricted handling of deployment secrets.
- Customer or tenant separation where the relevant product is designed as a multi-tenant service.
- Protected operational backups, security logging, and limited infrastructure access appropriate to the deployed service.
- Signed and checksum-verified direct Android releases where the direct-update channel is enabled.
Shared responsibility
Customers must manage authorized users, roles, devices, credentials, recipients, integrations, and lawful data entry. No internet service or software system is completely secure, error-free, or continuously available.
No certification claim
Unless a current written certificate is published for a named scope, Sequoia does not claim ISO 27001, SOC 2, HIPAA, NABL, ABDM, medical-device, or government certification.
Report a vulnerability or incident
Email sequoiatechnologies.in@gmail.com with subject “Security report”. Describe the affected product and reproducible impact without accessing, retaining, or disclosing other people’s data. We do not authorize destructive testing, denial of service, social engineering, or credential attacks.