The same principles your DPDP programme demands of you, applied to us. Data in India, encryption everywhere, immutable audit logs, and a published breach-response SLA.
All tenant data is hosted in India, in Azure Central India. Backups stay within India. No US or EU replication of customer data without explicit contract.
TLS 1.2+ in transit on every endpoint, including the embeddable widget. AES-256 at rest for database, object store, and backups.
Granular permissions across modules, with multi-tenant isolation enforced at the data layer. Least-privilege by default; admins escalate explicitly.
Every state-changing action is recorded with user, timestamp, IP, user-agent, and the before / after diff. Logs are append-only at the application layer.
If a breach affects customer data, we notify the affected tenant within 24 hours of confirmation, alongside containment status and a preliminary RCA.
Every tenant can export consent records, DSR history, grievance log, RoPA, and breach register at any time as CSV / JSON / PDF. Exit means data, not lock-in.
If the Board notifies your organisation as a Significant Data Fiduciary under §10, you owe four additional duties. The platform has them mapped.
Where we are honestly. We don't claim certifications until the audit closes.
What procurement and CISOs ask before they buy.
We have a pre-filled vendor security pack ready for procurement. Email us and we'll send it over.
Open vendor questionnaire →