Security at Artfolio
Your gallery data is sensitive and valuable — artwork records, collector details, financial transactions and provenance histories. Artfolio keeps it in India and protects it with several layers of security.
Mumbai
Data hosted in India
AES-256
Encryption at rest
Row-level
Gallery isolation
Daily
Automated backups
Every layer matters
Infrastructure
Hosted on managed cloud infrastructure in Mumbai, India, with encrypted connections and daily backups.
Application
Server-side permission checks, input validation with Zod schemas, parameterized queries and rate limiting.
Data
Row-level security that keeps each gallery's data separate, encrypted storage, daily backups and audit trails for key actions.
How we protect your data
The controls that protect gallery data from the moment it enters Artfolio.
Hosted in India
Your database, sign-in, uploaded files and backups are hosted in Mumbai, India (AWS ap-south-1), and the Artfolio app runs on servers in Mumbai. A few supporting services, such as email delivery and some AI features, may process limited data outside India; each is listed on our sub-processors page.
Data encryption
Data is encrypted at rest with AES-256 and in transit with TLS, so your inventory, collector details and financial records are protected on disk and on the network.
Row-level security
Row-level security policies in the PostgreSQL database decide which rows every query can see, so each gallery's data is kept separate at the database level, not just in the app.
Access controls
Roles (Owner, Admin, Staff, Viewer and Artist) and granular permission templates control who can view, create, edit or delete each kind of record. Permissions are checked on the server, not just hidden in the interface.
Two-factor authentication
TOTP-based two-factor authentication adds a second layer of protection to every account. Team members set up 2FA via QR code with any authenticator app. MFA challenges are enforced at login for enrolled users.
Audit logging
Key actions, such as artwork and invoice changes, payments and permission changes, are recorded in an audit trail, so you can see who did what and when.
Privacy rights (DPDP & GDPR)
Export your gallery's data as CSV or JSON at any time, edit or remove contact records, and let people unsubscribe from campaign emails in one click. Our policies set out the rights people have under India's DPDP Act and the GDPR.
Backup & recovery
The database is backed up automatically every day, and the last seven days of backups are kept, also in Mumbai.
Incident response
Errors are reported to our team automatically through error monitoring. If a personal data breach affects your gallery, we tell you without undue delay so you can inform the people affected and the Data Protection Board of India.
Security is not an afterthought
At Artfolio, security is part of how every feature is built. Each gallery's data is kept separate by row-level security policies in the database itself, not just in the application layer.
API routes check permissions on the server before they act, and input is validated with strict schemas. SQL injection is prevented through parameterized queries. CSV exports are sanitized to prevent formula injection. UUID parameters are validated before they reach the database.
If anything does go wrong, we work to detect it quickly, fix it, and tell affected customers clearly. Found a vulnerability? Email privacy@artfolio.ai.
Your trust is the foundation of our business. We earn it every day by treating your data with the care it deserves.
Ready to secure your gallery data?
Start your free trial today — 30 days, no credit card. Cancel anytime.