Security & Access

Is a Smart Home Safe in India?

Yes, if you buy for it. The real risks are ordinary: a default password, a device nobody updates, and a cloud account with a reused password. India's own code of practice for consumer devices names those first. Insist on local control, unique passwords and updates, and the rest is detail.

Keenan Pereira Security & Access 23 September 2026 10 min read Skip to the Indian code of practice
Two questions, not one

Security is about who can get in. Privacy is about who can see in. They get discussed together and they have different answers. Security is mostly settled by the hardware you choose and the passwords you set. Privacy is settled by which devices capture real content, cameras and microphones, and by what a company does with what it collects. Keeping them apart makes both easier to judge.

It is the question every family asks in the first meeting, usually phrased as can it be hacked. It deserves a straight answer rather than reassurance, because the honest answer tells you what to buy.

What can actually go wrong in a smart home?

Four things, in rough order of how often they matter:

A password that was never changed. A device that ships with the same admin login as every other unit of its kind is the oldest problem in connected hardware, and it is the first item in India's code of practice.

A device that never gets updated. Firmware written three years ago and never touched since carries every flaw it was born with. What matters is not whether a product is perfect on the day it ships, but whether anyone is still fixing it.

An account, not a device. The email address and app password that control a home are a softer target than the lock on the door. A password reused from a shopping site is the realistic way a stranger gets in.

People you gave access to and forgot. The PIN given to a contractor in March, still working in September, is a more common failure than anything technical.

AHA smart lock fitted to a front door, operated by fingerprint, face, PIN or card
The lock is rarely the weak point. The account that can open it from a phone usually is.

What does India's own code of practice ask of a smart device?

India has published exactly what a consumer connected device should do. The Telecommunication Engineering Centre, under the Department of Telecommunications, issued the Code of Practice for Securing Consumer Internet of Things (IoT), TEC 31318:2021, in August 2021. It is a baseline for manufacturers rather than a law you can wave at a salesman, but it is a free, public checklist, and you can hold a quotation against it.

Its thirteen guidelines, in its own words, with what each one means when you are the one buying:

TEC 31318:2021, section 3 guidelines, and what to ask.
The guideline What it means for your home
No universal default passwordsEvery unit has its own credentials, and you can change them.
Implement a means to manage reports of vulnerabilitiesSomeone at the company receives security reports and acts on them.
Keep software updatedUpdates arrive after you have paid, for years, not months.
Securely store sensitive security parametersKeys and passwords are not sitting in plain text inside the device.
Communicate securelyTraffic between device, hub and app is encrypted.
Minimize exposed attack surfacesPorts and services you do not use are switched off.
Ensure software integrityThe device refuses software that is not genuine.
Ensure that personal data is secureWhat the system learns about your routine is protected.
Make systems resilient to outagesThe house still works when the internet or power does not.
Examine system telemetry dataUnusual behaviour can be spotted rather than guessed at.
Make it easy for users to delete user dataYou can have your data removed, and hand a device on cleanly.
Make installation and maintenance of devices easySecurity that is hard to use gets switched off by the household.
Validate input dataThe device does not fall over when it is sent nonsense.

The international reference behind most of this is the same one AHA designs against in spirit: NIST's Profile of the IoT Core Baseline for Consumer IoT Products (NIST IR 8425, September 2022) asks for the same capabilities in different words, including Data Protection, Interface Access Control, Software Update and Cybersecurity State Awareness, plus something people forget to ask for: Documentation, so that a buyer can actually find out how a product behaves.

Does the house still work when the internet goes down?

This is the practical half of make systems resilient to outages, and it is the single question that separates a system from a pile of gadgets. In an AHA home the scenes run on a hub inside the flat, so lighting, curtains, locks and schedules keep working with the router unplugged. A keypad on the wall is not asking the internet for permission.

Internet is needed for three things only: reaching the home from outside, viewing cameras, and voice assistants, which are cloud services by design. If the connection drops mid-evening, the wall keypads carry on as usual. We wrote the longer version of this in does a smart home work without internet, including what to test at a demo.

There is a second kind of outage worth being honest about. In a power cut the hub stops with everything else, and automations resume when power returns. The lock is the exception people care about most: its manual key override still works during a power loss or a short circuit, and two mechanical keys come with it.

An AHA smart hub, the device that runs a home's scenes locally
Scenes are programmed on the hub, so the decisions are made inside the house rather than in a data centre.

Who can see what happens inside your home?

Start by separating the devices that capture content from the devices that only sense state. A light driver knows a light is on. A curtain motor knows a curtain is open. A presence sensor senses a body with mmWave radar, and a motion sensor reacts to movement: neither makes a picture or a recording. Cameras and microphones are the only parts of a smart home that capture something a person could watch or listen to later, which is why they deserve separate thought, and why some households keep them to entrances only.

Then ask about the company, because Indian law now gives you standing to. The Digital Personal Data Protection Act, 2023 requires that consent be free, specific, informed, unconditional and unambiguous, and it requires any company holding your personal data to take reasonable security safeguards to prevent a personal data breach. Both phrases are quoted from the Act. In plain terms: a supplier should be able to tell you what it collects, why, and how you get it deleted, and vague answers are themselves an answer.

AHA's own position, for the record: remote access to a home is used only for support and diagnostics with the household's permission, data is encrypted, and customer data is not shared with third parties. There are no SIM cards, subscriptions or monthly fees in the system either, which removes a whole category of reasons a device would phone home.

Is a smart lock safer than a key?

It fails differently, which is the more useful way to think about it. A mechanical key can be copied at any market stall, lent, lost or left with a neighbour, and you will never know it happened. A smart lock's risks are an account password, a PIN you gave out and forgot, and a battery you ignored for months.

What changes in daily life is control rather than strength. A one-time or scheduled password lets house help in at the hours you choose, without a spare key existing anywhere. A break-in attempt triggers a 30-second alarm and an app alert, so you know at the time rather than at 9pm. The trade is that you now have a list of who can open your door, and it is your job to keep that list short. Our guide to coordinating house help covers how households actually set this up.

If you are weighing the hardware itself, smart locks against traditional locks compares the failure modes, and the buyer's guide to smart door locks in India covers access methods. The full specification of the lock family sits on the AHA smart locks page.

What should you check before you buy?

Six questions, none of which need a technical background. Ask them in the showroom, and notice whether the answers are specific.

  • Show me the house working with the internet off. Not a description of it. Ask at the demo and watch a scene run.
  • Who updates this, and for how long? A product with no update story is a product with an expiry date.
  • What happens to my access list? How a PIN is added, how it is removed, and who can see the list.
  • What is collected about my home, and how do I get it deleted? The DPDP Act gives you the right to ask; a good supplier answers in a sentence.
  • Which devices have a camera or a microphone? Get the list, then decide room by room.
  • If your company disappeared, what happens to my house? AHA runs on Zigbee, an open global standard, so another Zigbee-capable company could service the system. Proprietary systems that only their maker can touch are a different bet.

Those are the technical tests. The commercial ones, who employs the technicians and who answers in year three, are in our guide to choosing a home automation company in India.

What will none of this fix?

Four honest limits, so nothing here reads as a sales pitch.

A phone that anyone can pick up and use. If the phone is unlocked, the home is unlocked. Everything else is secondary to that.

A shared Wi-Fi password. Handing the network password to every visitor for years is a habit no product can undo. AHA devices run on their own Zigbee network rather than your Wi-Fi, which helps, but the phone and the router are still yours to look after.

Voice assistants. They are cloud services. If that bothers you, you can run the home on keypads, schedules and the app, and leave voice out entirely. The keypads keep working either way.

A power cut. The hub stops when the power does. Scenes resume when it returns, and the lock still opens with its key.

What do people ask us next?

Is a smart home safe from hacking?

In practice, yes, and most of it is a buying decision. The devices that get attacked are the ones shipped with a default password, never updated, and reachable from the internet. India's TEC code of practice for consumer IoT puts no universal default passwords and keep software updated at the top of its list for that reason.

Does a smart home work if the internet goes down?

Yes, for the things you touch. Lighting, curtains, locks and scenes run on a hub inside the house, so a keypad and a schedule keep working. Internet is needed only for remote access from outside, camera viewing and voice assistants.

Can someone unlock a smart lock from outside the house?

Not by attacking the lock at the door. Remote unlock happens through the app account, so that account is what needs protecting. Give house help a one-time or scheduled PIN rather than sharing yours, delete codes when someone stops coming, and keep the two mechanical keys somewhere safe.

Do smart sensors record video or audio?

AHA's presence sensor senses people with mmWave radar and its motion sensor reacts to movement, so neither produces a picture or a recording. Cameras and voice assistants are the parts of a smart home that capture real content, and they are the parts worth asking hard questions about.

What does Indian law say about my smart home data?

The Digital Personal Data Protection Act 2023 requires your consent to be free, specific, informed, unconditional and unambiguous, and it requires any company holding your personal data to take reasonable security safeguards to prevent a personal data breach. You are entitled to ask a supplier what is collected, why, and how it gets deleted.

What is the biggest security risk in a smart home?

The account, not the device. An email or app password reused from somewhere else undoes every lock on the door. Give the home app and the email behind it a password you use nowhere else, and keep the phone itself locked.

The short version: judge a smart home on three things, whether it works with the internet off, whether anyone is still updating it, and whether the company can tell you plainly what it collects. Everything else is a preference.

If you want to test the first one yourself, both our experience centres, in Santacruz West and Lower Parel, are open 11am to 7pm (Santacruz West is closed on Tuesdays). Ask us to pull the internet out while you are standing there.

Book a free consultation →

Takes under a minute

Book your free demo

Interact with lighting, security, climate and many more experiences at our centres. You'll leave knowing exactly what a smart home costs and what your home would feel like.

Expert Consultants

Who have designed 1200+ smart homes

Personalised Pricing

Carry your electrical plan, it helps us design your home accurately

60 Minutes

Avg time to experience the demo

Free 60-minute demo

We’d love to have you over

Tell us a little about your home, and we’ll set up a demo that feels like yours, one quick call, and your visit is booked.

Takes under a minute, we’ll call just once to find a time that suits you