Trust & Security

Compliance &
Security Posture

Enterprise clients trust us with their most sensitive systems. Our compliance program ensures we earn and maintain that trust through continuous security, auditability, and regulatory adherence.

SOC 2
Type II Compliant
ISO
27001 Aligned
Zero
Data Breaches to Date
99.95%
Infrastructure Uptime

Our Compliance Certifications

Independently verified security and privacy certifications that enterprise clients require.

๐Ÿ›ก๏ธ

SOC 2 Type II

Active

Annual SOC 2 Type II audit covering Security, Availability, and Confidentiality Trust Service Criteria. Report available to enterprise clients under NDA.

๐Ÿ”

ISO 27001

Aligned

Our information security management system (ISMS) is aligned to ISO 27001:2022 controls covering risk assessment, access management, and incident response.

๐Ÿ‡ช๐Ÿ‡บ

GDPR Compliant

Active

Data processing agreements (DPAs), lawful basis documentation, DPIA processes, and data subject rights management fully implemented per GDPR requirements.

๐Ÿฅ

HIPAA Ready

Active

Business Associate Agreements (BAAs) available. PHI handling controls, audit logging, access restrictions, and breach notification procedures in place for healthcare projects.

๐Ÿ’ณ

PCI DSS Level 2

Active

PCI DSS Level 2 merchant and service provider requirements followed for projects handling cardholder data. Annual SAQ with quarterly ASV scans.

๐Ÿ‡ฎ๐Ÿ‡ณ

India DPDPA

Active

Full compliance with India's Digital Personal Data Protection Act 2023 โ€” consent management, data fiduciary obligations, and data localisation where required.

How We Protect Your Data

Layered technical and organisational controls across every dimension of our operations.

๐Ÿ”‘

Identity & Access Management

SSO + MFA enforced for all team members. Zero-trust network access. Privileged access management (PAM) with session recording.

Okta SSOMFA RequiredRBAC
๐Ÿ”’

Encryption

AES-256 encryption at rest. TLS 1.3 in transit. KMS-managed encryption keys with rotation. No plaintext secrets stored.

AES-256TLS 1.3AWS KMS
๐ŸŒ

Network Security

VPC isolation, security groups, WAF, DDoS protection. All traffic flows through inspection. No public SSH/RDP access.

VPCWAFCloudFront
๐Ÿ”Ž

Security Monitoring

24/7 SIEM-based threat detection. Anomaly detection alerts. Security incident response team with <1 hour response SLA.

SplunkAWS GuardDutyPagerDuty
๐Ÿงช

Vulnerability Management

Annual penetration testing by third-party security firms. Continuous dependency scanning. CVE patching SLA: Critical <48h.

SnykTrivyOWASP ZAP
๐Ÿ“‹

Audit Logging

Immutable audit logs for all data access and system changes. CloudTrail enabled. Log retention 12 months minimum. Tamper-proof storage.

CloudTrailS3 Object LockDatadog

Industry-Specific Compliance

We understand the regulatory requirements of the industries we serve.

๐Ÿฆ

Financial Services

We build for banks, NBFCs, and fintech platforms. Our financial services compliance covers data localisation, customer data protection, and transaction security requirements.

RBI GuidelinesPCI DSSSEBISOC 2
๐Ÿฅ

Healthcare

PHI data is handled with HIPAA-grade controls. We sign Business Associate Agreements and implement the technical and administrative safeguards required for healthcare IT.

HIPAAHL7 FHIRDISHAISO 27799
๐Ÿ›’

E-commerce & Retail

Consumer data protection, payment security, and fraud prevention controls aligned to e-commerce regulatory requirements across India and international markets.

PCI DSSDPDPAConsumer Protection Act
๐ŸŽ“

EdTech

Student data protection with special handling for minors, FERPA guidance for US-facing platforms, and age-appropriate data collection controls.

FERPACOPPADPDPAGDPR

Our Security Track Record

0
Data Breaches in Company History
100%
Annual Pen Tests Passed
72h
Max Breach Notification SLA
<48h
Critical CVE Patch SLA
100%
Team Security Training Completion
99.95%
Infrastructure Uptime SLA

Need a Compliance Package?

We provide SOC 2 reports, DPA agreements, security questionnaire responses, and compliance documentation upon request for enterprise procurement teams.