Security is
built in.
Countr handles shop, transaction and customer information. Our security approach is designed around protecting accounts, controlling access, securing data in transit and reducing unnecessary exposure.
Last reviewed: 27 September 2026 · Security overview version 1.1
Countr
Security by design
Focus
Protect access
Approach
Least exposure
Our principles
Security is a
product responsibility.
Countr combines technical controls, access controls and operational practices. The exact controls may evolve as the service changes.
Secure access
Authentication and authorization are enforced at the application/backend layer rather than relying only on the client.
Protected data
Production traffic is intended to use HTTPS/TLS, while sensitive information stored on supported mobile devices is protected using encrypted storage mechanisms.
Abuse resistance
Countr uses server-side validation and access controls, with rate limiting and security monitoring applied where supported by the service.
Continuous improvement
Security controls, dependencies, configurations and incident-response practices are reviewed and improved as the product grows.
Technical controls
How Countr protects
the application.
The following describes the security architecture and controls relevant to the current Countr product. It is not a claim of certification or a guarantee that every control prevents every attack.
Authentication
Short-lived sessions
Countr's API authentication is designed around short-lived access tokens and refresh tokens, reducing the useful lifetime of a stolen access token.
Authorization
Server-side checks
Permissions should be checked on the server for protected resources and actions. Client-side controls are not treated as the security boundary.
Transport
Encrypted connections
Production API communication is designed to use HTTPS/TLS. Cleartext HTTP should not be used for authenticated production traffic.
Mobile security
Protected local secrets
Sensitive mobile credentials are intended to be stored using encrypted device-backed storage rather than plain application storage.
API security
Validate every request
API endpoints should validate authentication, authorization, input and object ownership before allowing protected operations.
Monitoring
Security visibility
Relevant authentication, application and security events may be logged for troubleshooting, abuse detection, audit and incident response, subject to applicable retention practices.
Your shop data
Access should follow ownership.
Countr is designed as a multi-user service where authenticated users can access the shop information they are authorized to use. Your account credentials should never be shared with other people.
01
Account protection
Use a unique password, protect OTPs and session credentials, and report suspected unauthorized access promptly.
02
Tenant separation
Protected shop resources are intended to be scoped to the authenticated account and its authorized business context.
03
Data deletion
Countr provides account/data deletion mechanisms subject to the Privacy Policy, legal obligations, fraud prevention and necessary records.
Voice & device features
Convenience should not remove control.
Voice features can involve speech processing and third-party technology depending on the implementation. Device security features can also depend on the operating system and device configuration.
Voice processing
Voice input may be processed to convert speech into commands or text. The Privacy Policy explains the categories of information involved and how third-party processing may apply. Countr does not promise that voice recognition will always be accurate.
Device integrity
Where supported and enabled, Countr may use platform security signals to help identify risky or compromised environments. These signals are one part of a broader security model and are not a guarantee against abuse.
If something goes wrong
Security incidents need a process.
Countr maintains an incident-response approach intended to identify, contain, investigate and remediate security events. Where notification is required by applicable law or regulation, Countr will follow the applicable requirements.
01
Detect
Identify suspicious activity through available security signals and reports.
02
Contain
Limit unauthorized access or affected components where reasonably possible.
03
Investigate
Review relevant evidence, logs and system activity to understand the event.
04
Recover
Restore services, remediate the cause and improve controls where appropriate.
Report a security issue
If you discover a suspected vulnerability, unauthorized access or other security issue affecting Countr, please contact the official security/legal contact below. Do not include passwords, OTPs or unnecessary personal data in a report.
support@countr.in
Clear over complicated
No unsupported security promises.
This page is a security overview, not a certification, penetration-test report or guarantee that Countr is immune to every attack.
We do not claim
- • ISO 27001, SOC 2 or other certification unless separately stated and evidenced.
- • Perfect security or zero-risk operation.
- • That every third-party provider uses the same security controls as Countr.
- • That device-level security can be guaranteed by an application.
We do commit to
- • Keeping security and privacy documentation aligned with the service.
- • Applying reasonable technical and organizational safeguards appropriate to the service.
- • Investigating credible security reports and improving controls when issues are identified.
- • Handling personal data according to the Privacy Policy and applicable requirements.
Privacy Policy
The Privacy Policy is the source of truth for personal-data collection, use, sharing, retention, rights and deletion.
Read Privacy Policy →Terms of Service
The Terms explain the rules, responsibilities, limitations and conditions governing use of Countr.
Read Terms →Compliance context
Security practices operate alongside applicable Indian requirements.
Countr considers applicable requirements relating to digital personal data protection and cybersecurity, including the Digital Personal Data Protection Act, 2023 and the notified Digital Personal Data Protection Rules, 2025, as applicable to the service and its processing activities. Countr also considers applicable CERT-In cybersecurity directions and incident-reporting requirements. This page does not by itself constitute a certification or a legal-compliance guarantee.
For the current legal position and applicability to Countr's specific processing activities, obtain professional legal advice and keep the product implementation, contracts and policies aligned.
Countr Technologies Pvt. Ltd.
Build your shop
with confidence.
Simple shop management should also mean clear, responsible security and data practices.
Get Countr →