Security & privacy

Your society’s money, protected.

Committees handle real money on behalf of hundreds of residents. Omkosh is built so that trust is never misplaced.

Per-society isolation
Every society’s data is scoped to its own tenant. Your records are never visible to another society — enforced at a single choke-point on every request.
Encrypted & authenticated
Passwords are hashed with bcrypt, sessions run on signed, httpOnly cookies, and all traffic is served over HTTPS.
Role-based access
Fine-grained roles — Admin, Treasurer, Collector, Viewer and your own — control exactly who can view, edit or manage money.
Hardened by default
Rate-limited auth, validated and sanitised inputs, security headers and a locked-down CORS allow-list — safe from day one.
Audit-ready trail
Every collection, expense and receipt is logged with who, what and when — so your books stand up to any AGM.
PCI-safe payments
Card and UPI payments run through Razorpay — a PCI-DSS compliant gateway. We never store card details.
Security questions

What committees ask us most.

Can another society see our data?
No. Every record is tagged to your society and every query is scoped to it. There is no route through which one society can read another’s data.
Who in our committee can see the money?
Exactly who you decide. You assign each member a role, and roles control view / edit / manage access per module — from full admin down to read-only transparency for auditors.
Is our data backed up?
Yes — your data lives on managed MongoDB with automated backups and point-in-time recovery, so a mistake or outage never loses your festival records.
What happens if we leave?
You own your data. Export your members, collections, expenses and reports at any time, and request full deletion when you close your account.
Have a specific security question? Talk to our team.

Run your festival on a platform you can trust.

Transparent books, encrypted data and full control over who sees what — on every plan, including Free.

Get startedSchedule a demo