Security & compliance

Built like the bank vault. Runs like a teammate.

ISO 27001 + SOC 2 + CERT-In + DPDP. Hash-chained audit trail on every action. Sovereign deployment in 13 regions including air-gapped on-prem.

Trust pillars

Built-in. Audited. Enforced on every action.

Each pillar is independently audited and enforced live in production. Reports and certificates available under NDA.

Encryption & keys

AES-256, TLS 1.3, HSM-backed KMS.

FIPS 140-2 L3
  • AES-256 at rest sealed
  • TLS 1.3 in transit verified
  • HSM-backed keys rotated

Hash-chained audit trail

Signed, sealed, replayable on every action.

TAMPER-EVIDENT
a3f8b7c2 9d4e1f08 7b2c6a91
Signed · CARO + Companies Act ready

PII redaction

PAN, Aadhaar, GSTIN masked before inference.

3 DETECTORS
PAN ABCDE1234F raw
PAN █████████ masked

Sovereign residency

13 regions, sovereign India, on-prem, air-gap.

MUMBAI · LIVE
India · Mumbai ap-south-1 sovereign
Yotta CtrlS AWS Azure
+ 12 more regions · on-prem · air-gap
  • ISO 27001 ISMS

    Independent annual audit. Surveillance every 12 months.

  • Your data, your training

    We never train on customer data. Contractually committed.

  • Responsible AI

    Bias monitoring, content safety, fairness. All toggleable per agent.

  • Hallucination guardrails

    Citation enforcement, confidence scoring, low-conf block policy.

Compliance

Certifications and frameworks we operate under.

Independent audits, regulator-grade artefacts, and a public stance we keep current. Reports and DPAs available under NDA.

  • SOC 2 Type II

    Active

    Security, availability, confidentiality trust services.

    Body
    AICPA
    Coverage
    12 months
  • CERT-In empanelled

    Compliant

    India's national cyber incident response empanelment.

    Body
    MeitY · CERT-In
    Status
    Active panel
  • DPDP Act 2023

    Compliant

    India's Digital Personal Data Protection Act compliance.

    Coverage
    Data fiduciary obligations
    Audit
    Quarterly
  • HIPAA

    In progress

    Healthcare data privacy and security (US).

    Stage
    Final assessment
    Target
    Q3 2026
  • GDPR

    Compliant

    EU data protection regulation compliance.

    Region
    EU/EEA
    DPA
    Available on request
SLA

Service-level commitments by tier.

Written into every contract. Service credits paid out automatically on breach. No claim form required.

  • Pilot

    First-agent pilots and proofs of concept.

    Uptime
    99.5%
    Response
    8 business hours
    Recovery
    RPO 24h · RTO 8h
    Credits
    Automated credit on breach
  • Business

    Production agents across multiple functions.

    Uptime
    99.9%
    Response
    4 business hours
    Recovery
    RPO 4h · RTO 2h
    Credits
    10% MRR / breach
    Automated credit on breach
  • Enterprise

    Recommended

    Mission-critical agents under regulator oversight.

    Uptime
    99.99%
    Response
    1h · 24/7
    Recovery
    RPO 15min · RTO 30min
    Credits
    25% MRR / breach
    Automated credit on breach
Deployment

13 regions. Plus on-prem and air-gap.

Deploy where your regulators say so. VPC on the major hyperscalers, sovereign options for India, or fully on-prem.

  • Mumbai
    India
    ap-south-1
    • Sovereign
    • AWS
    • Azure
    • Yotta
    • CtrlS
  • Bengaluru
    India
    in-south
    • GCP
    • OCI
  • Singapore
    Singapore
    ap-southeast-1
    • AWS
    • Azure
    • GCP
  • Frankfurt
    Germany
    eu-central-1
    • AWS
    • Azure
    • GCP
  • London
    UK
    eu-west-2
    • AWS
    • Azure
  • Dublin
    Ireland
    eu-west-1
    • AWS
  • Virginia
    USA
    us-east-1
    • AWS
    • Azure
    • GCP
  • Oregon
    USA
    us-west-2
    • AWS
    • GCP
  • Dubai
    UAE
    me-central-1
    • AWS
    • Azure
  • Bahrain
    Bahrain
    me-south-1
    • AWS
  • Sydney
    Australia
    ap-southeast-2
    • AWS
    • Azure
  • Tokyo
    Japan
    ap-northeast-1
    • AWS
    • GCP
On-prem & air-gap · Fully isolated deployment for the strictest regulators.
India + global · talk to security team

Got a security questionnaire? We'll send it back signed today.

DPA, SOC 2 Type II, ISO 27001, sub-processor list, pen-test summary. Every artefact your procurement team will ask for. All under NDA.

Talk to security team