Free forever for unlimited employees — no card, no per-seat minimum. See pricing New — the AI Payroll Agent runs the month for you. Meet the agent India-built HRMS & compliance — live in minutes, not months. How it works
Sign in
Trust Center · Built for India

Security & trust, built for India.

Your payroll and people data is some of the most sensitive information your business holds. Kredily protects it with encryption, strict access controls and data hosted in India — so you stay compliant and in control.

Encrypted

TLS in transit, AES-256 at rest — across the platform.

Hosted in India

Your data is stored within India — a real differentiator.

DPDP-aligned

Privacy built around India's Digital Personal Data Protection Act.

You're in control

Role-based access, audit logs, and data export on request.

Security

Bank-grade security, by design

We only claim what's substantiated. We don't yet hold formal ISO 27001 or SOC 2 certifications — so instead of badges, here is exactly how your payroll and employee data is protected today.

Bank-grade security

The security discipline banks expect — reinforced by our direct integration with ICICI Bank for salary and vendor payouts.

Encrypted end to end

Data is encrypted in transit with TLS and at rest with 256-bit AES. Access is role-based, with multi-tenant isolation.

Data residency in India

Your payroll and employee data is hosted in India and aligned with the DPDP Act.

Data security

Defence in depth, end to end

From the moment data leaves an employee's device to where it rests in our database, it is encrypted and access-controlled.

Encryption in transit & at rest

All traffic is protected with TLS, and stored data is encrypted at rest using AES-256. Keys are managed separately from the data they protect.

TLS · AES-256

Role-based access control

Granular RBAC means admins, managers and employees see only what their role permits. Permissions are scoped by company, location and department.

RBAC · Least privilege

Multi-tenant isolation

Each customer's data is logically isolated. One organisation can never see, query or access another organisation's records.

Tenant isolation

Secure infrastructure

Hosted on a reputable cloud provider with network segmentation, firewalls and hardened configurations. Verify provider & controls

Secure development

Security is built into how we ship: code review, dependency monitoring and regular vulnerability scanning. Confirm SDLC & pen-test cadence

Continuous monitoring

Systems and access are monitored for anomalies, with logging that supports investigation and incident response. Confirm monitoring & IR process

India data residency

Your data stays in India.

Kredily hosts customer data within India. For Indian businesses, that's not a nice-to-have — it keeps your payroll and employee data close to home and simplifies your own data-governance story.

  • Customer data hosted in India — not relocated overseas.
  • Aligns with India-first data-governance expectations.
  • A clear differentiator vs. platforms that store data abroad.
Hosted in India 🇮🇳
Region & data-centre details available on request
Reliability & availability

Up when payday can't wait

Payroll runs to a deadline. We design for availability and recoverability so your team gets paid on time.

Uptime commitment

We target high availability for the platform. Confirm uptime SLA %

Target uptime: __._% — to confirm

Backups

Customer data is backed up regularly so it can be restored if something goes wrong. Confirm backup frequency & retention

Disaster recovery

A documented recovery plan with defined recovery objectives.
RPO: to confirm   RTO: to confirm

Privacy & compliance

Aligned with India's DPDP Act

The Digital Personal Data Protection (DPDP) Act sets the rules for handling personal data in India. We build privacy around it — and keep ownership of the data firmly with you.

DPDP-aligned by design

Data is collected and processed for clear, lawful purposes, with privacy considered as part of how the product is built. Legal to confirm wording

Your data is yours

You own your company and employee data. We act as a processor on your behalf — we don't sell it or use it for advertising.

You own it · We process it

Export & delete

You can export your data, and request deletion when you leave. We handle data-rights requests in line with applicable law.

Export · Erasure on request

Data Processing Agreement

A Data Processing Agreement (DPA) is available on request — covering how we process personal data on your behalf.

DPA available on request

Employee data rights

Employees can view their own records and correct personal details, with changes flowing through approval where required.

Self-service · Correction

Breach response

We maintain a process to detect, contain and notify in the event of a data incident, in line with regulatory timelines. Confirm notification commitment

Subprocessors

Who we work with, openly

We use a small number of trusted vendors to deliver the service. The list below is illustrative and must be confirmed before publishing.

Illustrative only — full subprocessor list to be confirmed before publishing.
SubprocessorPurposeRegionStatus
Cloud hosting provider Application hosting & data storage India To confirm
Email / notifications Transactional email & alerts To confirm To confirm
SMS / OTP provider One-time passcodes & SMS alerts India To confirm
Payments / banking partner Salary disbursement & payouts India To confirm
Access & governance

Visibility and control for admins

Give the right people the right access — and keep a record of who did what.

Audit logs

Key actions are recorded so admins can review changes to payroll, employee records and configuration.

Activity history

Role-based access

Admins assign roles and permissions, so each user only reaches the data and actions their role allows. The AI Copilot inherits the same role limits — it processes in-region, requires human approval for irreversible actions, and every action lands in the audit trail.

RBAC · AI governance

Admin controls

Manage users, approvals and access from one place — onboard and offboard people as your team changes.

User management

Employee data rights

Employees can see and update their own profile data, with sensitive changes routed for approval.

Self-service

Authentication

Secure sign-in protects every account. Confirm MFA / SSO availability

Internal access governance

Kredily staff access to customer data is limited and controlled on a need-to-know basis. Confirm internal access policy

Trust FAQ

Your security questions, answered

The questions buyers, IT and HR teams ask us most.

Your data is hosted in India. Keeping payroll and employee data within India supports your own data-governance requirements and keeps it close to home. Specific region and data-centre details can be provided on request as part of a security review. Request details
Yes. Data is encrypted in transit using TLS and encrypted at rest using AES-256. Access to that data is further restricted by role-based access controls and multi-tenant isolation, so only authorised users in your organisation can reach it.
Yes. You own your company and employee data. You can export your data, and you can request deletion when you stop using Kredily. We handle data-rights and erasure requests in line with applicable law, including India's DPDP Act. Talk to us about a request
Yes — a Data Processing Agreement is available on request. It sets out how Kredily processes personal data on your behalf as a processor. Reach out and our team will share the current DPA along with our security pack. Request the DPA

Run a security review with us

Get the answers your IT, finance and HR teams need — request our DPA and security pack, or book a walkthrough with our team.

Request the DPA & security documentation as part of your evaluation.