Skip to content
Scrapwhiz
CapabilitiesOne partner for strategy and execution.

Connect growth, revenue, security and technology around a shared outcome.

View all services
Digital marketingDemand, brand and performance
Sales & GTMPipeline, RevOps and customer success
CybersecurityApplication, cloud, data and identity
Web & applicationFast, secure product systems
Manpower Jobs Partnerships Shop
Contact us
All services Digital marketing Sales & GTM Cybersecurity Web & application Manpower consulting Jobs Partnerships Shop Contact

Trust Centre

Compliance and Security

Control status as of 2 August 2026.

This page states what Scrapwhiz has implemented, what remains a business or assessor responsibility and what does not apply to the current production service. It does not claim a certification, attestation or legal opinion.

Framework status

FrameworkCurrent position
Digital Personal Data Protection Act, 2023 and Rules, 2025Privacy controls are designed for notice, purpose limitation, consent records, rights handling, grievance response, safeguards, processor oversight and breach response as the provisions commence.
GDPRController disclosures, lawful-basis records, data-subject rights, retention, processor controls and international-transfer safeguards are applied where GDPR is in scope.
PCI DSS v4.0.1Payment-account-data scope is reduced through Razorpay-hosted checkout. Scrapwhiz does not store card numbers, CVV, UPI PINs or bank passwords. Merchant eligibility, SAQ selection and attestation remain formal PCI activities.
ISO/IEC 27001:2022Controls are mapped to an ISMS-style risk, access, supplier, incident, continuity and improvement model. Scrapwhiz is not represented as ISO-certified unless a valid certificate is published.
SOC 2 Trust Services CriteriaSecurity, availability, confidentiality, processing-integrity and privacy controls inform the control model. Scrapwhiz does not claim a SOC 2 report.
OWASP Top 10:2025The website and shop are reviewed against access control, configuration, supply chain, cryptography, injection, design, authentication, integrity, logging and exception-handling risks.
OWASP Top 10 for Agentic Applications 2026Not applicable to the current website and shop runtime because it does not deploy an autonomous AI agent, agent memory or tool-execution plane. A new agent feature requires a separate threat model before release.

Technical controls

  • HTTPS enforcement, HSTS, restrictive browser policies and framing protection.
  • Server-side product, price, stock, payment-signature and captured-amount checks.
  • Razorpay signed webhooks for independent payment confirmation.
  • Supabase row-level security, restricted admin allowlist and server-only secret keys.
  • Input validation, output encoding, request-size limits, same-origin checks and rate limits.
  • Private admin data separated from public catalogue data.
  • Order-event history, notification queue, security logging and controlled error messages.
  • Dependency pinning, secret scanning, documented deployment checks and restore procedures.

Payment responsibility boundary

Razorpay renders the payment-entry interface and processes payment credentials. Scrapwhiz creates the payable order, supplies the verified amount, receives gateway identifiers, validates the returned signature, checks the captured payment through Razorpay and records the result. A move from test to live requires live keys, an enabled live-payment flag, a separate webhook secret and a successful low-value live transaction.

Fulfilment and tracking boundary

Scrapwhiz records the supplier, fulfilment route, courier, AWB and official tracking URL. The customer can retrieve the timeline with the order ID and checkout email. Courier scan events remain controlled by the courier unless a courier API is connected.

Operational evidence

Evidence can include access lists, change history, dependency results, payment and webhook tests, order-event records, supplier records, incident logs, restore tests and policy approvals. Evidence containing personal data, secrets or infrastructure details is shared only with a legitimate assessor, customer or regulator under appropriate confidentiality terms.

Incident and vulnerability reporting

Report a suspected security issue to hello@scrapwhiz.com. Include the affected URL, impact and reproduction steps without accessing another person’s data or disrupting service. See security.txt.

Shared responsibility

No website change alone creates ISO certification, a SOC 2 attestation, PCI compliance or complete legal compliance. Hosting configuration, access reviews, vendor contracts, backups, incident exercises, employee controls, evidence retention and independent assessment must operate with the code.

Scrapwhiz

Service-led growth, technology, cybersecurity and talent delivery from India to the world.

hello@scrapwhiz.com

Services

Digital marketingSales & GTMCybersecurityWeb & applicationManpower consulting

Explore

ShopDirect employer jobsPartnershipsContactCompliancePrivacyTerms

Follow and read

Updates, practical guides and new opportunities.

Read on Substack
© 2026 Scrapwhiz. All rights reserved.India · Global delivery