Security

How we protect your gym's data

We know biometric attendance and door-access data are sensitive — here's exactly what we do to protect it, in plain language.

Encrypted in transit

Every connection to 92 GYMS — the dashboard, your gym's member app, and every API call — runs over HTTPS.

Encrypted credentials at rest

Payment gateway keys and WhatsApp access tokens are stored encrypted in our database, not in plain text. Passwords are hashed (bcrypt) and never stored or visible to anyone, including our own team.

Your gym's data stays yours

Every gym on 92 GYMS is isolated at the database level — members, payments, staff and attendance records for one gym are never visible to another, even though we all share one platform.

Role-based access control

Owner, manager, staff and trainer accounts each see and can do only what their role allows — front-desk staff can't touch financial settings, for example.

Payments via certified processors

Card and bank payments are handled directly by Razorpay and Paytm, both PCI-DSS certified payment processors. 92 GYMS never sees or stores your members' card numbers or bank details.

Backups & account protection

Automated backups keep your gym's data recoverable, and login attempts are rate-limited to slow down brute-force attacks on your account.

We're a growing platform and keep investing in security as we scale. We don't hold formal certifications like ISO 27001 or SOC 2 today — if your gym or franchise has specific compliance requirements or a security questionnaire to complete, get in touch and we'll work through it with you directly.