security - CRED (2024)

Best practices to follow

We have always placed your security first on CRED. To ensure maximum security, we have made a simple list of security to-do's you can follow:


  • never divulge your personal bank details like card number, CVV, PIN, and OTP in any medium, including calls, texts, or emails.
  • we will never, ever ask you for any of the sensitive details mentioned above.
  • we will never call you and ask to do any payment transaction on the app or install any remote access software such as teamviewer, anydesk, etc.
  • never respond to such emails, texts, or phone calls.
  • our customer support can only be reached via the app. please do not engage with phone numbers that claim to be of our support team.

Privacy Practices

We do not sell your personal information to or share it with unaffiliated third parties for their own advertising or marketing purposes without your explicit consent

Check out our Privacy Policy for more information

Cloud Infrastructure

CRED is hosted on a Virtual Private Cloud on Amazon Web Services which provides a secure and scalable technology platform to ensure we can provide you services securely and reliably.

Perimeter Security

We have deployed Defence in Depth Architecture using a network firewall, web application firewall, DDoS protection layer, and a content delivery network.

Our infrastructure is launched in compliance with the AWS Well Architected Framework and from the security perspective incorporating practices from the AWS Cloud Adoption Framework

We have a 3-Tier Architecture which incorporates best practices from various standards and certifications

We have strict network segmentation and isolation of environments and services in place.

Host Security

We use industry leading solutions around anti-virus, anti-malware, intrusion prevention systems, intrusion detection systems, file integrity monitoring, application control, application and audit log aggregation, and automated patching

All our servers are launched using the Center for Internet Security Benchmarks for Amazon Linux.

Data Security

We employ separation of environments and segregation of duties and have strict role-based access control on a documented, authorized, need-to-use basis

We use key management services to limit access to data except the data team

Stored data is protected by encryption at rest and sensitive data by application level encryption

We use data replication for data resiliency, snapshotting for data durability and backup/restore testing for data reliability.

Incident and Change Management

We have deployed mature processes around Change Management which enables us to release thoroughly tested features for you both reliably and securely enabling you to enjoy the CRED experience with maximum assurance

We have a very aggressive stance on Incident Management on both Systems downtime and Security and have a Network Operations Center and an Information Security Management System in place which quickly reacts, remediates or escalates any Incidents arising out of planned or unplanned changes.

Vulnerability Assessment and Penetration Testing

We have an inhouse network security team which uses industry leading products to conduct manual and automated VA/PT activities

We employ both static application security testing and dynamic application security testing which is incorporated into our continuous integration / continuous deployment pipeline

We also leverage CERT-IN certified auditors to do periodic external security testing and audits.

Standards and Certifications

We are a PCI DSS v3.2.1 certified company which means we have implemented applicable industry standard security controls governed by PCI council that helps us protect all our customer’s card data in a highly secure manner.

We have successfully completed UPI compliance per the Circular 15B & 32 by the NPCI.

We are an ISO 27001:2013 certified company and have implemented required Information Systems Management System policies and procedures in order to maintain industry standard best practices and applicable controls.

We have successfully completed “Data Localization” requirements as per Reserve Bank of India(RBI) guidelines. This means all our customer data securely resides inside on cloud based out of India (AWS Mumbai Region).

All compliance/audit statuses will be updated in this section in this policy.

Responsible Disclosure

We at CRED are committed about our customer's data and privacy

We blend security at multiple steps within our products with state of the art technology to ensure our systems maintain strong security measures

The overall data and privacy security design allows us defend our systems ranging from low hanging issue up to sophisticated attacks

If you are a security enthusiast or a researcher and you have found a possible security vulnerability on CRED products, we encourage you to report the issue to us responsibly

You could submit a bug report to us at security@cred.club with detailed steps required to reproduce the vulnerability

We shall put best of our efforts to investigate and fix the legitimate issues in a reasonable time frame, meanwhile, requesting you not to publicly disclose it.

security - CRED (2024)
Top Articles
Bitrue - Company Profile - Tracxn
This Grocery Store Beat Costco & Wegmans for the #1 Spot on the 2019 Best Employer List
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Prof. Nancy Dach

Last Updated:

Views: 5615

Rating: 4.7 / 5 (57 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Prof. Nancy Dach

Birthday: 1993-08-23

Address: 569 Waelchi Ports, South Blainebury, LA 11589

Phone: +9958996486049

Job: Sales Manager

Hobby: Web surfing, Scuba diving, Mountaineering, Writing, Sailing, Dance, Blacksmithing

Introduction: My name is Prof. Nancy Dach, I am a lively, joyous, courageous, lovely, tender, charming, open person who loves writing and wants to share my knowledge and understanding with you.