Security
Is it safe to save your MeroShare password in SajiloShare?
It is the right question to ask before giving any app your MeroShare login, CRN and PIN. Here is exactly where SajiloShare keeps them, what leaves your phone and what never does.
- Stored only on your phone
- Password and PIN encrypted with AES-256-GCM
- Encryption key kept in Android Keystore or iOS Keychain
- Sent only to CDSC's MeroShare, never to a SajiloShare server
- PIN and fingerprint or Face ID app lock
Where your MeroShare details live
- Password and PIN
- Encrypted, on your phone
- DP, username, CRN, BOID
- On your phone
- Encryption key
- Keystore / Keychain
- Sent to
- CDSC MeroShare only
- On SajiloShare servers
- Nothing
Why the app asks for each detail
| Detail | Why SajiloShare needs it | Where it is kept |
|---|---|---|
| DP and username | To log in to MeroShare for that account | On your phone, in the app's private storage |
| Password | To log in to MeroShare | On your phone, encrypted with AES-256-GCM |
| CRN | MeroShare asks for it so the bank can block funds when you apply | On your phone, in the app's private storage |
| Transaction PIN | MeroShare requires it to confirm every application | On your phone, encrypted with AES-256-GCM |
| BOID | To check IPO results; filled in from MeroShare | On your phone, in the app's private storage |
The encryption key is a random 256-bit key created on your phone the first time the app runs. It is held by the Android Keystore or the iOS Keychain and never leaves the device.
What leaves your phone, and where it goes
- Your login details go directly to CDSC's MeroShare servers over HTTPS, only when you apply, refresh the portfolio or check an account.
- When checking results, the captcha image is sent to our server so it can be read automatically. For some older issues, the BOIDs being checked are passed through our server to CDSC's result site. Neither is stored.
- If notifications are on, a push notification token is registered with our server.
- Share prices come from public market data, without any personal information.
Your password, CRN, PIN and portfolio are never sent to a SajiloShare server.
Protecting the app on your phone
- Lock the app with a 4-digit PIN, and fingerprint or Face ID.
- Revealing a saved password asks for that lock again.
- Moving to a new phone uses an encrypted file protected by a password you set, or a nearby Wi-Fi transfer confirmed with a matching verification number.
- Deleting an account in the app removes its details from your phone immediately.
What we cannot do
Because we never receive your credentials, we cannot recover them, see your portfolio or apply on your behalf. If your phone is lost or stolen, change your MeroShare password on meroshare.cdsc.com.np.
Questions to ask any IPO app
- Does it say, specifically, where your MeroShare password, CRN and PIN are stored: on your phone or on its servers?
- Are the password and PIN encrypted, and where is the key?
- Can the app be locked, and does revealing a password need that lock?
- Is it installed from Google Play or the App Store, not an APK from a website?
- Does every application need your tap, or can it act on its own?
Frequently asked
Can SajiloShare see my MeroShare password?
Why does the app need my transaction PIN?
Does SajiloShare apply for IPOs without me?
What should I do if I lose my phone?
Read next
Stop logging in to MeroShare once per account
Add the family's MeroShare accounts once. Apply to every open issue for all of them in one run, then check every result together. Free on Android and iPhone.