Security & Compliance

How MorphCharge protects drivers' money, operators' revenue and everyone's data โ€” by architecture, not by promise.

Platform security

๐Ÿ”’ Encryption everywhere

TLS 1.2+ on every driver, console and charger connection (wss:// for OCPP). HSTS enforced. Data encrypted at rest on Microsoft Azure (India region today; EU/UK/GCC regions per deployment).

โšก Charger authentication

OCPP 1.6 Security Profile 1:every charger authenticates with its own Basic-auth credential; keys are rotatable per unit from the console and every rotation is audit-logged.

๐Ÿ”‘ Credential hygiene

OTPs are stored only as salted hashes with constant-time comparison, strict attempt limits and short expiry. Admin logins carry brute-force lockouts; passwords are bcrypt-hashed; role-based access is enforced server-side on every request.

๐Ÿงพ Payment isolation (PCI scope-free)

Card and UPI data never touch our servers โ€” payments run on the gateway's PCI-DSS Level 1 infrastructure (hosted checkout). Webhooks are HMAC-signature verified per merchant account. Refunds are automatic and idempotent.

๐Ÿ›ก Hardened web surface

Content-Security-Policy, X-Frame-Options DENY, nosniff, strict referrer policy and no-store API caching. Signed, expiring QR tokens with per-gun revocation defeat sticker tampering.

๐Ÿ“œ Auditability

Every administrative change โ€” tariffs, splits, tenants, keys โ€” is recorded with actor, before/after and timestamp. Read-only MIS logins give clients verification without write risk.

Data protection by region

IndiaDPDP Act 2023

Data minimisation by design: driver phone numbers are stored as salted hashes; no accounts, no profiles, no marketing reuse. Explicit consent at OTP; GST e-receipts; grievance & erasure requests honoured via privacy@datamorphosis.in.

EUGDPR & AFIR

Ad-hoc charging without registration is our native model (AFIR Art. 5). Lawful basis: contract performance; minimal personal data; EU-region hosting and DPA available for EU deployments; sub-processor list on request; 72-hour breach notification commitment.

UKUK GDPR & Public Charge Point Regulations

Pence-per-kWh price transparency before every session, continuous per-charger reliability measurement for uptime reporting, and contactless-terminal integration for rapid chargers via certified payment partners.

GCCUAE PDPL / KSA PDPL

Regional hosting available (Azure UAE), data-residency on request, Arabic-ready driver flow on the roadmap, and merchant-of-record always the local operator โ€” funds never pool with the platform.

Operational security

Independent testing: CERT-In-empanelled VAPT scheduled ahead of government deployments; findings remediated before go-live. Backups: automated daily with point-in-time recovery. Monitoring: live charger heartbeats, fault auto-ticketing and billing-anomaly detection. Access: least-privilege, per-tenant scoping enforced in every query.

Responsible disclosure

Found a vulnerability? We want to hear from you first. Email security@datamorphosis.in โ€” we acknowledge within 48 hours, don't pursue good-faith researchers, and credit fixes on request.