Your data stays in India
PGManage runs in Amazon Web Services’ Mumbai region (ap-south-1). Resident records, KYC and payment data are stored and processed in India — they do not leave the country in normal operation.
Security
A PG keeps Aadhaar-linked KYC, photographs of ID documents, and the phone number of everyone in the building. That is sensitive, and treating it carelessly would be the fastest way to lose your trust. This page is what we actually do — and where something is not done yet, it says so.
PGManage runs in Amazon Web Services’ Mumbai region (ap-south-1). Resident records, KYC and payment data are stored and processed in India — they do not leave the country in normal operation.
Every connection is HTTPS with HSTS enforced — there is no unencrypted way in. The database volume is encrypted at rest, and application secrets (payment keys, the WhatsApp token) live in AWS Secrets Manager, write-only over the API, never shown back after they are set.
Each organisation’s data lives in its own isolated database schema. A request is pinned to one organisation for its entire life, so there is no query path from your account into anyone else’s — the separation is structural, not a filter someone could forget to apply.
Owners, managers and collection staff each see only what their role allows. A staff member is limited to the properties you assign them; financial screens are gated to the roles that should see money. Access is a login per person, not a shared password.
The audit log records who did what, with the value before and after, and flags sensitive actions. A recorded payment cannot be silently edited, and a deleted record can be restored. If something looks wrong, there is a trail to check it against.
You can export residents, ledgers, payments and expenses as spreadsheets at any time — including the day you decide to leave. After cancellation we retain your data for a short grace period in case you return, then delete it.
We are an operator who built a tool, not a security vendor with a wall of badges. We do not claim certifications we do not hold. If you need something specific — a signed data processing agreement, a penetration-test summary, a defined backup schedule in writing — ask us directly and we will tell you plainly where we are, including where we are not there yet.
Security questions go to pgmanage36@gmail.com.