Sanothimi
Trust & Safety

Security Policy.

April 21, 2026Continuously ReviewedNepal Jurisdiction

1. Security Commitment

Security is a fundamental part of how Sanothimi — the software and technology services operated by Chandan Sharma — designs, operates, and maintains its products and services. This Security Policy describes the practices we apply to protect the systems, applications, and customer information entrusted to us. It is intended to build customer trust and is not itself a contractual SLA unless referenced as such in an applicable Order Form.

2. Infrastructure Security

Our Services run on reputable third-party cloud infrastructure. We apply network segmentation, firewalls, and separation between environments (such as development, staging, and production) to reduce risk.

3. Encryption

We use TLS/HTTPS to encrypt data in transit between your browser or client and our Services. Data at rest is encrypted where supported by the underlying infrastructure provider. We only state encryption practices we actually implement, and update this section as our infrastructure evolves.

4. Identity and Access Management

Internal access to production systems and Customer Data is limited on a least-privilege, role-based basis, with periodic review of access grants.

5. Authentication

We apply password controls and secure session management for Account access, and support multi-factor authentication where available for a given Service. Credential protection guidance is available in our Documentation.

6. Tenant Isolation

For our multi-tenant SaaS Products, Customer environments are logically separated to help prevent unauthorized access to another Customer's information.

7. Logging and Monitoring

We maintain security and operational logging designed to help detect and investigate unusual or unauthorized activity affecting our Services.

8. Backup and Recovery

We perform periodic backups of Customer Data for Services where applicable, with retention periods described in each Service's Documentation, and maintain recovery procedures intended to restore service in the event of an incident.

9. Vulnerability Management

We monitor for known vulnerabilities in our dependencies, apply security patches on a risk-based schedule, and periodically review our systems for security issues.

10. Secure Development

Our development practices include code review, dependency and secret management, and separation between development, staging, and production environments.

11. Employee Security

Personnel with access to Customer Data are bound by confidentiality obligations, granted access on a need-to-know basis, and have access revoked promptly when no longer required, including upon offboarding.

12. Third-Party Security

We rely on established third-party providers for hosting, payment processing, email delivery, and related infrastructure, and select providers with appropriate security practices for the sensitivity of the data they handle.

13. Security Incidents

We maintain a process to detect, contain, investigate, and remediate security incidents, and to notify affected Customers in accordance with our Data Processing Agreement and applicable law.

14. Business Continuity

We maintain reasonable operational practices intended to support continuity of the Services in the event of a disruption, appropriate to the scale of our current operations.

15. Data Deletion

When Customer Data is deleted from production systems (whether by Customer action or upon termination as described in our Terms and DPA), corresponding backups are removed on a rolling schedule thereafter.

16. Customer Responsibilities

Security is a shared responsibility. Customers should: use strong, unique credentials; enable multi-factor authentication where available; control which Users have access to their Account and at what permission level; avoid sharing credentials; and report suspected security incidents to us promptly.

17. Compliance and Certifications

Certifications: none currently held. We will update this section if and when we obtain formal third-party security certifications, and we do not make certification claims we cannot substantiate.

18. Security Contact

To report a suspected security vulnerability or incident, contact: security@sanothimi.com

Need Our Security Docs?

Enterprise customers can request additional security documentation for procurement review.

Request Documentation