Skip to content
Security & compliance

Security at Artfolio

Your gallery data is sensitive and valuable — artwork records, collector details, financial transactions and provenance histories. Artfolio keeps it in India and protects it with several layers of security.

Mumbai

Data hosted in India

AES-256

Encryption at rest

Row-level

Gallery isolation

Daily

Automated backups

Defense in depth

Every layer matters

Infrastructure

Hosted on managed cloud infrastructure in Mumbai, India, with encrypted connections and daily backups.

Application

Server-side permission checks, input validation with Zod schemas, parameterized queries and rate limiting.

Data

Row-level security that keeps each gallery's data separate, encrypted storage, daily backups and audit trails for key actions.

Security features

How we protect your data

The controls that protect gallery data from the moment it enters Artfolio.

Hosted in India

Your database, sign-in, uploaded files and backups are hosted in Mumbai, India (AWS ap-south-1), and the Artfolio app runs on servers in Mumbai. A few supporting services, such as email delivery and some AI features, may process limited data outside India; each is listed on our sub-processors page.

Data encryption

Data is encrypted at rest with AES-256 and in transit with TLS, so your inventory, collector details and financial records are protected on disk and on the network.

Row-level security

Row-level security policies in the PostgreSQL database decide which rows every query can see, so each gallery's data is kept separate at the database level, not just in the app.

Access controls

Roles (Owner, Admin, Staff, Viewer and Artist) and granular permission templates control who can view, create, edit or delete each kind of record. Permissions are checked on the server, not just hidden in the interface.

Two-factor authentication

TOTP-based two-factor authentication adds a second layer of protection to every account. Team members set up 2FA via QR code with any authenticator app. MFA challenges are enforced at login for enrolled users.

Audit logging

Key actions, such as artwork and invoice changes, payments and permission changes, are recorded in an audit trail, so you can see who did what and when.

Privacy rights (DPDP & GDPR)

Export your gallery's data as CSV or JSON at any time, edit or remove contact records, and let people unsubscribe from campaign emails in one click. Our policies set out the rights people have under India's DPDP Act and the GDPR.

Backup & recovery

The database is backed up automatically every day, and the last seven days of backups are kept, also in Mumbai.

Incident response

Errors are reported to our team automatically through error monitoring. If a personal data breach affects your gallery, we tell you without undue delay so you can inform the people affected and the Data Protection Board of India.

Our commitment

Security is not an afterthought

At Artfolio, security is part of how every feature is built. Each gallery's data is kept separate by row-level security policies in the database itself, not just in the application layer.

API routes check permissions on the server before they act, and input is validated with strict schemas. SQL injection is prevented through parameterized queries. CSV exports are sanitized to prevent formula injection. UUID parameters are validated before they reach the database.

If anything does go wrong, we work to detect it quickly, fix it, and tell affected customers clearly. Found a vulnerability? Email privacy@artfolio.ai.

Your trust is the foundation of our business. We earn it every day by treating your data with the care it deserves.

Ready to secure your gallery data?

Start your free trial today — 30 days, no credit card. Cancel anytime.

Start free trial