Security

How FlatPe keeps your data secure

FlatPe protects members' details with layers: optional authenticator-app sign-in (MFA) and an app-lock PIN, separate data for every society, payment records that cannot be edited, and an owner-visible security log.

  • Optional MFA and app-lock PIN
  • Separate data per society
  • Payments never edited

Last reviewed

Sign-in

Your sign-in, step by step

The steps below match the defaults for a new society.

  1. 1. Your passwordStored only as a one-way scrambled hash, so not even we can read it.
  2. 2. Optional: an authenticator codeA six-digit code that changes every 30 seconds, from an app on your phone.
  3. 3. Your app-lock PINLocks the app whenever it is opened or left for a minute. The server checks it, not the phone.

Layers

9 layers between your records and everyone else

Authenticator-app sign-in

Standard time-based six-digit codes (RFC 6238) that work with common authenticator apps. Each code works once, ten one-time recovery codes are kept hashed, and the authenticator secret is encrypted before it is stored. It is optional, and the owner can require it.

App-lock PIN

A four-digit PIN that locks the app each time it opens and after a minute away. Obvious PINs such as 1111 or 1234 are refused, the PIN is checked on our server rather than on the phone, and five wrong tries end the session.

Lockout and rate limits

Ten wrong passwords or codes lock that one account for fifteen minutes, whichever device they came from. Sign-in, password-reset, one-time-code, MFA and PIN requests are also rate-limited.

Separate data per society

Every client, fee and payment query is scoped to the signed-in society on the server, and we test that another society cannot reach your records. A number or id sent from the browser is never trusted.

Payments you can trust

Payment records are never edited. A wrong one is cancelled and entered again, so the history stays intact, and each entry records who made it.

Passwords and sessions

Passwords are kept only as a salted one-way hash. The session cookie is HttpOnly and Secure, and changing your authenticator or PIN signs you out everywhere else.

Encrypted in transit, not cached

Everything between your phone and FlatPe travels over HTTPS. Responses carry no-cache headers so an intermediary cannot show yesterday's balance.

Enforced on the server

Hiding a screen is never the only control. One security gate in front of every request refuses access until the required sign-in steps are done, so a half-finished sign-in cannot reach members' data.

You can see what happened

The owner can read a log of sign-ins, authenticator and PIN set-ups, failed attempts, lockouts, resets and policy changes, and can reset a colleague's authenticator or PIN.

Defaults

Settings a new society starts with

Authenticator-app sign-in (MFA)Optional: each person can turn on it, and the owner can make it required
App-lock PINOptional: each person can turn on it, and the owner can make it required
App locks again after60 seconds away from the app, and every time it is opened fresh
Account lockout10 wrong passwords or codes lock that account for 15 minutes, from any device
Who can change theseThe society owner, from the Sign-in security screen

Societies can change every setting above from the Sign-in security screen.

Your part

  • Use a password you do not use anywhere else.
  • Keep your recovery codes somewhere safe, and not in the same phone as the authenticator app.
  • Give each colleague their own login instead of sharing yours, and ask the society owner to remove people who leave.
  • Keep your phone screen lock on as well as the app PIN.

What this page does and does not say

Report a security problem

If you think you have found a weakness, email support@classpe.in with what you found and how to reproduce it. Please give us time to fix it before you share it. Our contact details are also published in security.txt.

Frequently asked questions

Does FlatPe support two-factor authentication?

Yes. Sign-in can require a six-digit code from an authenticator app after the password, with one-time recovery codes in case a phone is lost. For a new society it is optional, and the owner can make it required.

What is the app-lock PIN?

A four-digit PIN that locks the app each time it is opened and after a minute away. It stops a lost or borrowed phone from opening members' details. The PIN is checked on the server, and five wrong tries end the session so the person must sign in again with their password.

What if I lose my phone?

Sign in on another device with your password and one of your recovery codes, then set up the authenticator again. If you have no recovery code, the owner can reset a colleague, and the platform team can reset an owner.

Can one society see another society's data?

No. Every record belongs to one society, every request is checked against the signed-in society on the server, and we test that access across societies is refused.

Can a payment record be edited or deleted?

No. Payment records are never changed. A mistake is cancelled and entered again, so there is always a trail of what happened and who did it.

Can FlatPe staff read my password?

No. Your password is stored only as a salted one-way hash, so it cannot be turned back into the password.

How do I report a security problem?

Email the address on this page or see our security.txt file. Please include what you found and how to reproduce it, and give us time to fix it before you share it publicly.

See who has paid this month, at a glance.

Create your society's account, add your units and members and record your first payment. Free to try for 2 weeks, no card needed.

Start free trial

Or call sales: +91 94946 44848

Call sales Start free trial