Trust Centre
Compliance and Security
Control status as of 2 August 2026.
This page states what Scrapwhiz has implemented, what remains a business or assessor responsibility and what does not apply to the current production service. It does not claim a certification, attestation or legal opinion.
Framework status
| Framework | Current position |
|---|---|
| Digital Personal Data Protection Act, 2023 and Rules, 2025 | Privacy controls are designed for notice, purpose limitation, consent records, rights handling, grievance response, safeguards, processor oversight and breach response as the provisions commence. |
| GDPR | Controller disclosures, lawful-basis records, data-subject rights, retention, processor controls and international-transfer safeguards are applied where GDPR is in scope. |
| PCI DSS v4.0.1 | Payment-account-data scope is reduced through Razorpay-hosted checkout. Scrapwhiz does not store card numbers, CVV, UPI PINs or bank passwords. Merchant eligibility, SAQ selection and attestation remain formal PCI activities. |
| ISO/IEC 27001:2022 | Controls are mapped to an ISMS-style risk, access, supplier, incident, continuity and improvement model. Scrapwhiz is not represented as ISO-certified unless a valid certificate is published. |
| SOC 2 Trust Services Criteria | Security, availability, confidentiality, processing-integrity and privacy controls inform the control model. Scrapwhiz does not claim a SOC 2 report. |
| OWASP Top 10:2025 | The website and shop are reviewed against access control, configuration, supply chain, cryptography, injection, design, authentication, integrity, logging and exception-handling risks. |
| OWASP Top 10 for Agentic Applications 2026 | Not applicable to the current website and shop runtime because it does not deploy an autonomous AI agent, agent memory or tool-execution plane. A new agent feature requires a separate threat model before release. |
Technical controls
- HTTPS enforcement, HSTS, restrictive browser policies and framing protection.
- Server-side product, price, stock, payment-signature and captured-amount checks.
- Razorpay signed webhooks for independent payment confirmation.
- Supabase row-level security, restricted admin allowlist and server-only secret keys.
- Input validation, output encoding, request-size limits, same-origin checks and rate limits.
- Private admin data separated from public catalogue data.
- Order-event history, notification queue, security logging and controlled error messages.
- Dependency pinning, secret scanning, documented deployment checks and restore procedures.
Payment responsibility boundary
Razorpay renders the payment-entry interface and processes payment credentials. Scrapwhiz creates the payable order, supplies the verified amount, receives gateway identifiers, validates the returned signature, checks the captured payment through Razorpay and records the result. A move from test to live requires live keys, an enabled live-payment flag, a separate webhook secret and a successful low-value live transaction.
Fulfilment and tracking boundary
Scrapwhiz records the supplier, fulfilment route, courier, AWB and official tracking URL. The customer can retrieve the timeline with the order ID and checkout email. Courier scan events remain controlled by the courier unless a courier API is connected.
Operational evidence
Evidence can include access lists, change history, dependency results, payment and webhook tests, order-event records, supplier records, incident logs, restore tests and policy approvals. Evidence containing personal data, secrets or infrastructure details is shared only with a legitimate assessor, customer or regulator under appropriate confidentiality terms.
Incident and vulnerability reporting
Report a suspected security issue to hello@scrapwhiz.com. Include the affected URL, impact and reproduction steps without accessing another person’s data or disrupting service. See security.txt.
Shared responsibility
No website change alone creates ISO certification, a SOC 2 attestation, PCI compliance or complete legal compliance. Hosting configuration, access reviews, vendor contracts, backups, incident exercises, employee controls, evidence retention and independent assessment must operate with the code.
