Security
Security at Winsen Rho.
and it is enterprise-grade from day one.
Security and compliance
Designed in compliance with the rules you answer to.
01
Data stays where your regulator expects
Rho runs in the region you choose and sends nothing anywhere else, built for data localisation and cross-border rules such as the RBI's, India's DPDP Act and the GDPR.
02
Ready for your outsourcing review
Everything your outsourcing and third-party rules ask of a provider: a register entry, audit and inspection rights, a sub-processor list and an exit plan.
03
Evidence a supervisor can rely on
Signed, object-locked records that reproduce exactly, kept for as long as your retention rules require.
Rho supports your obligations; your institution remains accountable for meeting them. See how Rho maps to each rule on the regulations page.
01 · Data residency
Your data stays in your region.
- Rho runs in the cloud region you choose at onboarding, such as Mumbai for India.
- Egress is allowlisted to three Rho endpoints in that region. No other region is reachable.
- Anything else is dropped at your boundary, logged, and raised to your SIEM.
- You can see every byte that leaves, by destination, in the egress inspector.

02 · PII handling
Customer identity never leaves your bank.
- The Rho Bridge runs inside your network and redacts every payload before it leaves.
- Direct identifiers such as PAN, Aadhaar and account numbers are never forwarded.
- Anything that still looks like one is quarantined locally, encrypted and access-logged, then deleted within 72 hours.
- Rho Cloud sees tokens, not people. The console shows counts, never the quarantined data.

03 · Keys, access and encryption
The keys stay with you.
- Customer tokens are keyed by a key held in your HSM. It never leaves the bank, so Rho Cloud cannot turn a token back into a person.
- The Bridge authenticates to Rho with mutual TLS, and data is encrypted in transit and at rest.
- The key is created in a ceremony with your named custodians, with a verified backup.
- If the key doesn't match, the Bridge refuses to start rather than mix tenants.

04 · Evidence integrity
Nobody can quietly edit the record.
- Every evidence pack is signed and object-locked for its retention period.
- Any pack reproduces exactly, and restatements sit beside the original, never over it.
- Every read of a pack is logged: who, when and which version.
- Supervisors and auditors get the same record your teams use.

For your third-party review
Everything your review asks for.
We share these with institutions evaluating Rho, under a non-disclosure agreement.
Request documentation
Request security documentation.
Tell us about your review. We reply within two working days, usually with an NDA to sign first.
Report a security issue
Found something? Tell us first.
Reports go straight to
security@winsenrho.comUse the form below, or write to us directly. Also in security.txt.
- We acknowledge every report and keep you updated until it's resolved.
- Give us reasonable time to fix an issue before disclosing it.
- Don't access, change or keep data that isn't yours, or degrade the service.
This website
How winsenrho.com protects what you send.
- Encrypted everywhere
- Every page and form is served over TLS, with HSTS. What you submit is encrypted in transit and at rest by each provider that stores it.
- No cookies
- The site sets no cookies. Analytics load only if you allow them, and never capture what you type.
- Least access
- Form submissions are visible only to the team members who handle them.
- Hardened headers
- No framing by other sites, and no access to camera, microphone or location.
More in our privacy policy, or write to hello@winsenrho.com.



