Security & Trust

Built for India. Hardened for the Board.

The same principles your DPDP programme demands of you, applied to us. Data in India, encryption everywhere, immutable audit logs, and a published breach-response SLA.

India data residency

All tenant data is hosted in India, in Azure Central India. Backups stay within India. No US or EU replication of customer data without explicit contract.

  • Azure Central India primary
  • Backups in-region
  • No cross-border replication by default
  • App and database on the same private network

Encryption everywhere

TLS 1.2+ in transit on every endpoint, including the embeddable widget. AES-256 at rest for database, object store, and backups.

  • TLS 1.2+ enforced
  • AES-256 at rest
  • Encrypted database fields for sensitive PII
  • Secrets in AWS Secrets Manager

Role-based access control

Granular permissions across modules, with multi-tenant isolation enforced at the data layer. Least-privilege by default; admins escalate explicitly.

  • Per-module roles
  • Multi-tenant row-level isolation
  • Per-tenant API keys
  • Topbar tenant switcher with audit

Immutable audit log

Every state-changing action is recorded with user, timestamp, IP, user-agent, and the before / after diff. Logs are append-only at the application layer.

  • User · timestamp · IP · UA
  • Before/after diff per action
  • Append-only at app layer
  • Exportable as signed PDF

Breach response SLA

If a breach affects customer data, we notify the affected tenant within 24 hours of confirmation, alongside containment status and a preliminary RCA.

  • 24h tenant notification on confirmed breach
  • Containment status + preliminary RCA
  • Aligns with §8(6) Board-notification flow
  • Post-incident review shared with tenant

Data export & portability

Every tenant can export consent records, DSR history, grievance log, RoPA, and breach register at any time as CSV / JSON / PDF. Exit means data, not lock-in.

  • CSV + JSON + PDF exports
  • Signed consent-record receipts
  • RoPA + grievance + breach registers
  • 30-day grace export window on cancellation

Significant Data Fiduciary readiness

If the Board notifies your organisation as a Significant Data Fiduciary under §10, you owe four additional duties. The platform has them mapped.

  1. Appointed Data Protection Officer (DPO) — wired into the platform's grievance officer module
  2. Periodic Data Protection Impact Assessment (DPIA) — supported by the L3 DeepDive assessment
  3. Periodic compliance audit — exportable from the assessment + RoPA + grievance modules
  4. Other measures as the Board may prescribe — tracked as they're notified, surfaced inline

On the roadmap

Where we are honestly. We don't claim certifications until the audit closes.

SOC 2 Type IIPre-audit
ISO 27001On roadmap
BYO-SSO (SAML / OIDC)Enterprise
On-prem deploymentEnterprise

Security FAQ

What procurement and CISOs ask before they buy.

Need a security questionnaire filled?

We have a pre-filled vendor security pack ready for procurement. Email us and we'll send it over.

Open vendor questionnaire →