Legal
Security Overview
Security Overview
Effective Date: 24 July 2026 Last Updated: 24 July 2026
GrowthMate is committed to protecting the confidentiality, integrity, and availability of the information processed through its services.
This Security Overview explains the general technical and organizational safeguards used by GrowthMate, including services provided through growthmate.net and app.growthmate.net.
GrowthMate is owned and operated by:
QOPTERVZN INFOCOM PRIVATE LIMITED Plot No. 19, At Khokarla, Balaji Nagar, Behind Bhaiyaji Nagar, Bhupali Duplex, Bhandara, Maharashtra, India – 441904
For security-related questions or reports, contact [[email protected]](mailto:[email protected]).
1. Our Security Approach
GrowthMate maintains a risk-based security program designed to follow generally accepted industry best practices.
Our security measures are intended to:
- Protect customer and business information from unauthorized access;
- Reduce the risk of accidental loss, alteration, disclosure, or destruction;
- Limit access to information according to legitimate business needs;
- Detect and respond to security events;
- Maintain service availability and recoverability; and
- Continuously improve our security practices as the service evolves.
No online system can be guaranteed to be completely secure. GrowthMate therefore applies multiple layers of safeguards and regularly reviews security risks relevant to its systems, users, and operations.
2. Encryption and Secure Communications
GrowthMate uses encrypted connections, including HTTPS and Transport Layer Security, to protect information transmitted between supported browsers, applications, and GrowthMate systems.
Encryption helps reduce the risk of information being intercepted or altered while being transmitted over public networks.
Where supported and appropriate, GrowthMate and its service providers also use encryption, access restrictions, or equivalent safeguards to protect stored information.
Users should access GrowthMate only through official GrowthMate domains and should avoid submitting sensitive information through unencrypted or unofficial communication channels.
3. Access Controls
Access to GrowthMate systems and information is restricted according to job responsibilities, technical requirements, and legitimate business needs.
GrowthMate applies role-based or permission-based access controls to help ensure that authorized personnel and systems can access only the information necessary for their assigned functions.
Access-management practices may include:
- Unique user or administrator accounts;
- Authentication requirements;
- Permission restrictions;
- Administrative access controls;
- Periodic access reviews;
- Removal or modification of access when responsibilities change; and
- Logging of relevant administrative or system activity.
Privileged access is limited to personnel or service providers who require it to operate, maintain, secure, or support the service.
4. Authentication and Account Security
GrowthMate uses authentication controls to help prevent unauthorized account access.
Users are responsible for:
- Providing accurate account information;
- Maintaining the confidentiality of their login credentials;
- Using a strong and unique password;
- Protecting access to their registered email account;
- Avoiding the sharing of accounts or authentication credentials;
- Signing out of devices they do not control; and
- Promptly reporting suspected unauthorized access.
GrowthMate may introduce or require additional authentication measures where appropriate, including verification codes, session controls, or multi-factor authentication.
5. Infrastructure and Hosting Security
GrowthMate may use established cloud infrastructure, hosting providers, database providers, content-delivery services, and other technology vendors to operate its services.
These providers may maintain their own physical, environmental, network, and platform security measures.
GrowthMate selects service providers based on factors such as operational capability, reliability, security practices, privacy commitments, and suitability for the relevant service.
Access to production infrastructure is restricted and managed according to operational and security requirements.
6. Network and Application Security
GrowthMate uses technical safeguards intended to reduce common network and application-security risks.
Depending on the relevant system, these safeguards may include:
- Secure communication protocols;
- Network-access restrictions;
- Firewalls or cloud-security controls;
- Application input validation;
- Authentication and authorization checks;
- Secure session handling;
- Protection against common web-based attacks;
- Rate limiting or abuse-prevention controls;
- Dependency and software-update management; and
- Logging and monitoring of relevant system activity.
Security controls may vary depending on the sensitivity, purpose, architecture, and operational requirements of each GrowthMate component.
7. Secure Development Practices
GrowthMate considers security during the design, development, testing, deployment, and maintenance of its software.
Our development practices may include:
- Code review;
- Separation of development and production environments;
- Testing before production deployment;
- Source-code access restrictions;
- Dependency review;
- Configuration management;
- Secure handling of credentials and secrets;
- Validation of user-controlled input;
- Error handling that avoids unnecessary information exposure; and
- Review of security-sensitive changes.
GrowthMate works to remediate identified security issues according to their severity, exploitability, potential impact, and available mitigations.
8. Vulnerability Management
GrowthMate reviews its systems for known or reasonably foreseeable security weaknesses.
Vulnerability-management activities may include:
- Monitoring relevant security advisories;
- Reviewing software dependencies;
- Applying security patches and updates;
- Testing important application functions;
- Investigating reported vulnerabilities;
- Prioritizing remediation based on risk; and
- Implementing temporary mitigations where an immediate permanent fix is unavailable.
The timing of remediation may depend on the severity of the issue, affected systems, technical complexity, operational risk, and availability of a safe resolution.
9. Monitoring and Security Logging
GrowthMate uses monitoring and logging mechanisms to help maintain service reliability, investigate errors, detect suspicious activity, and respond to security events.
Depending on the system, monitored information may include:
- Authentication activity;
- Administrative actions;
- Application errors;
- System performance;
- API activity;
- Unusual usage patterns;
- Failed access attempts; and
- Infrastructure or service availability.
Access to security logs is restricted, and logs are retained only for as long as reasonably necessary for security, operational, legal, and compliance purposes.
10. Incident Detection and Response
GrowthMate maintains procedures designed to identify, investigate, contain, and respond to suspected security incidents.
Our incident-response process may include:
1. Detecting or receiving notice of a suspected incident; 2. Assessing the nature and potential impact of the event; 3. Containing affected systems or accounts; 4. Investigating the cause and scope; 5. Removing or mitigating the threat; 6. Restoring affected systems or services; 7. Preserving relevant evidence and records; 8. Evaluating whether notification is legally required; and 9. Implementing corrective or preventive improvements.
Where required by applicable law, GrowthMate will notify affected users, regulators, service providers, or other relevant parties within the legally applicable period.
The timing and content of any notification will depend on the available information, the nature of the incident, applicable legal requirements, and law-enforcement or security considerations.
11. Backups and Recovery
GrowthMate maintains backup and recovery measures intended to support service continuity and reduce the risk of permanent data loss.
Depending on the relevant system, these measures may include:
- Scheduled or automated backups;
- Redundant infrastructure or service-provider features;
- Restricted access to backup data;
- Retention of multiple backup versions;
- Recovery procedures; and
- Periodic review or testing of recovery processes.
Backups are not intended to serve as permanent archives for individual users.
GrowthMate cannot guarantee that every item of customer data can be recovered in every circumstance, particularly where information has been intentionally deleted, corrupted before backup, excluded from backup, or affected by an event outside GrowthMate’s reasonable control.
Users should retain independent copies of information that is critical to their business or legal obligations.
12. Business Continuity and Service Availability
GrowthMate maintains operational measures intended to support the continued availability and recovery of its services.
These measures may include:
- Infrastructure monitoring;
- Backup and restoration procedures;
- Redundant or managed cloud services;
- Incident-escalation procedures;
- Capacity and performance monitoring;
- Dependency monitoring; and
- Recovery planning for material service interruptions.
GrowthMate does not guarantee uninterrupted or error-free availability. Maintenance, security events, internet failures, third-party outages, force majeure events, or technical problems may temporarily affect the service.
13. Data Minimization and Retention
GrowthMate seeks to collect and retain only the information reasonably required to:
- Provide and improve the service;
- Authenticate users;
- Process payments;
- Maintain security;
- Provide customer support;
- Comply with legal obligations;
- Resolve disputes; and
- Enforce applicable agreements.
Information is retained in accordance with GrowthMate’s Privacy Policy, legal obligations, contractual requirements, security needs, and legitimate business purposes.
When information is no longer reasonably required, GrowthMate may delete, anonymize, aggregate, or securely dispose of it, subject to applicable law and technical limitations.
14. Personnel and Confidentiality
Personnel and contractors who may access GrowthMate systems or confidential information are expected to follow applicable security and confidentiality requirements.
Access is limited according to assigned responsibilities and may be subject to:
- Confidentiality obligations;
- Internal security procedures;
- Access-control requirements;
- Acceptable-use restrictions;
- Security awareness guidance; and
- Disciplinary or contractual consequences for unauthorized activity.
GrowthMate removes or modifies access when it is no longer required.
15. Service Providers and Subprocessors
GrowthMate may engage third-party service providers to support functions such as:
- Cloud hosting;
- Databases;
- Authentication;
- Email delivery;
- Analytics;
- Customer support;
- Error monitoring;
- Payment processing;
- Communications; and
- Infrastructure management.
GrowthMate seeks to use providers that maintain safeguards appropriate to the nature of the services they perform.
Third-party providers are responsible for the security of their own systems and operate according to their respective agreements, privacy policies, and security practices.
GrowthMate does not claim ownership or direct control over the independent infrastructure and internal operations of third-party providers.
16. Payment Security
Payments may be processed through third-party payment providers, including Razorpay.
GrowthMate generally does not directly store complete payment-card details when payments are handled through an external payment processor.
Payment information may be collected, transmitted, stored, and processed by the payment provider according to its own security standards, contractual terms, and legal obligations.
Users should report suspected unauthorized payment activity to both GrowthMate and their bank or payment provider.
17. Privacy and Security
GrowthMate’s security practices are designed to support its privacy obligations.
Personal information is processed according to GrowthMate’s Privacy Policy, applicable contractual terms, and applicable law.
Security measures are intended to reduce risk but do not replace the user’s responsibility to use the service lawfully, configure integrations carefully, and avoid uploading information that is unnecessary or prohibited.
18. Customer Responsibilities
Security is a shared responsibility.
Users and organizations using GrowthMate should:
- Use strong, unique passwords;
- Protect login credentials and recovery methods;
- Restrict account access to authorized persons;
- Remove access when a team member no longer requires it;
- Review account and integration permissions;
- Protect connected third-party accounts;
- Keep browsers, operating systems, and devices updated;
- Use trusted devices and networks;
- Avoid uploading unnecessary sensitive information;
- Maintain independent backups where appropriate; and
- Promptly report suspicious activity or security concerns.
GrowthMate is not responsible for security incidents caused by a user’s disclosure of credentials, insecure devices, misconfigured third-party services, or actions taken outside GrowthMate’s reasonable control.
19. Prohibited Security Activities
Users must not attempt to:
- Access accounts, systems, or information without authorization;
- Bypass authentication, access controls, usage limits, or security measures;
- Scan, probe, or test GrowthMate systems without written authorization;
- Introduce malware, harmful code, automated attacks, or disruptive traffic;
- Exploit or publicly disclose a vulnerability before GrowthMate has had a reasonable opportunity to investigate and remediate it;
- Obtain another user’s credentials or confidential information;
- Interfere with service availability or integrity; or
- Use GrowthMate for phishing, fraud, credential theft, or other unlawful conduct.
Such activity may result in account suspension, termination, investigation, preservation of relevant records, and reporting to appropriate authorities.
20. Reporting Security Vulnerabilities
Security researchers and users who discover a suspected vulnerability should report it privately to:
Email: [email protected] Subject: Security Vulnerability Report
A useful report should include:
- A description of the suspected issue;
- The affected page, feature, endpoint, or system;
- Steps required to reproduce the issue;
- The potential impact;
- Relevant screenshots, logs, or technical details; and
- Contact information for follow-up.
Do not include unnecessary personal information, exploit the issue beyond what is reasonably required to demonstrate it, access another user’s data, disrupt the service, or publicly disclose the vulnerability before it has been reviewed.
GrowthMate does not currently promise a financial bug bounty or other compensation unless expressly agreed in writing.
21. Security Standards and Certifications
GrowthMate’s security program is designed around generally accepted industry best practices appropriate to its size, services, technical architecture, and risk profile.
Unless expressly stated in a separate written notice, GrowthMate does not claim to be certified under any particular security framework, including ISO 27001, SOC 2, PCI DSS, or another formal certification standard.
The use of third-party providers that hold security certifications does not necessarily mean that GrowthMate itself holds the same certifications.
22. No Absolute Security Guarantee
Although GrowthMate takes reasonable measures to protect its systems and information, no method of electronic transmission, storage, or processing is completely secure.
GrowthMate cannot guarantee that:
- Unauthorized access will never occur;
- Every attempted attack will be detected;
- The service will always be available;
- Every item of data can be recovered; or
- Third-party systems will remain free from vulnerabilities or interruptions.
This Security Overview describes GrowthMate’s general security approach and does not create a warranty, service-level guarantee, or contractual commitment beyond those expressly stated in an applicable written agreement.
23. Updates to This Security Overview
GrowthMate may update this Security Overview as its technology, service providers, risk profile, security controls, or legal obligations change.
The updated version will be published with a revised “Last Updated” date.
Material changes may also be communicated through the GrowthMate service, website, or another appropriate channel.
24. Contact Information
Questions or concerns about GrowthMate’s security practices may be submitted to:
Grievance Officer: Alok Diwate, Director Email: [email protected] Company: QOPTERVZN INFOCOM PRIVATE LIMITED Address: Plot No. 19, At Khokarla, Balaji Nagar, Behind Bhaiyaji Nagar, Bhupali Duplex, Bhandara, Maharashtra, India – 441904
For account-specific issues, contact us from the email address associated with your GrowthMate account and include only the information necessary for us to investigate the matter.