Fristine Infotech
Book a session
Home/Trust & Compliance

Built for auditors, not just users

Our security, privacy and compliance posture, stated plainly. Anything we’re working towards is described as in progress rather than held.

ISO 27001DPDP Act 2023AI GovernanceIndia Data ResidencyCERT-In

Our security, privacy and compliance posture for enterprise AI and operational systems, stated plainly with certifications, controls and audit provisions.

Trust and compliance framework

Data residency

We deploy in Indian regions by default for Indian clients, and inside your own cloud tenant where that’s your requirement.

Available regions: AWS Mumbai (ap-south-1) and Hyderabad (ap-south-2) · Azure Central India (Pune), South India (Chennai), West India (Mumbai) · Google Cloud Mumbai (asia-south1) and Delhi NCR (asia-south2) · Zoho India data centres (Mumbai and Chennai).

Model inference: Regional endpoints where the provider offers them, documented per deployment before build. Where a model provider has no Indian endpoint, we tell you before you commit.

Access control and data handling

Least privilege. Engineer access is granted per engagement, time-bound, and reviewed regularly.
No production data in test environments. Without your written approval and equivalent controls. Masked or synthetic data by default.
Encryption. In transit and at rest as standard.
Logging. Access to client environments logged, retained per your policy, minimum 180 days in India under CERT-In.
Offboarding. Access revoked on the day a person leaves an engagement, verified by checklist.

Our AI governance

The controls we apply to every agent we build, unless you explicitly ask for something different in writing:

Human in the loop. On decisions with financial or customer consequence, at a confidence threshold you set and own.
Immutable decision logs. Timestamped and append-only, recording input records, source document, extracted values, confidence score, model and prompt version, and the human who approved.
Permission inheritance. An agent operates with the entitlements of the user who invoked it and cannot retrieve what that user couldn't open.
Evaluation suites. A labelled set of your real cases, re run on schedule and on every model or prompt change, retained as evidence.
Change control. No prompt or model change reaches production without a diff and a test result.
No training on your data. Your data is used for retrieval and inference at query time only.
Disclosure. Voice agents identify themselves as automated by default.

Working with your auditors

Right to audit

Included in our contracts for you and, where applicable, your regulator, including on site.

Subcontractors

Disclosed in a register, with prior consent required for any change affecting your data. Cloud and model providers named explicitly.

Incident response

We notify you without undue delay, support your investigation with logs and forensics, and equip you to report to your regulator, CERT-In or the Data Protection Board.

Exit

Documented exit and data-portability plan from the start of the engagement, not negotiated at the end. You get your data, your configuration, your code and your documentation.

Privacy

We operate as a Data Processor under India’s DPDP Act 2023 and DPDP Rules 2025, bound by a processing agreement covering security safeguards, breach notification support, retention, deletion and consent-artefact handling. Fiduciary obligations remain yours; the discipline that lets you meet them has to be ours.

BFSI compliance detail

Questions about our security posture?

Book a working session