Our security, privacy and compliance posture for enterprise AI and operational systems, stated plainly with certifications, controls and audit provisions.
Data residency
We deploy in Indian regions by default for Indian clients, and inside your own cloud tenant where that’s your requirement.
Available regions: AWS Mumbai (ap-south-1) and Hyderabad (ap-south-2) · Azure Central India (Pune), South India (Chennai), West India (Mumbai) · Google Cloud Mumbai (asia-south1) and Delhi NCR (asia-south2) · Zoho India data centres (Mumbai and Chennai).
Model inference: Regional endpoints where the provider offers them, documented per deployment before build. Where a model provider has no Indian endpoint, we tell you before you commit.
Access control and data handling
Our AI governance
The controls we apply to every agent we build, unless you explicitly ask for something different in writing:
Working with your auditors
Right to audit
Included in our contracts for you and, where applicable, your regulator, including on site.
Subcontractors
Disclosed in a register, with prior consent required for any change affecting your data. Cloud and model providers named explicitly.
Incident response
We notify you without undue delay, support your investigation with logs and forensics, and equip you to report to your regulator, CERT-In or the Data Protection Board.
Exit
Documented exit and data-portability plan from the start of the engagement, not negotiated at the end. You get your data, your configuration, your code and your documentation.
Privacy
We operate as a Data Processor under India’s DPDP Act 2023 and DPDP Rules 2025, bound by a processing agreement covering security safeguards, breach notification support, retention, deletion and consent-artefact handling. Fiduciary obligations remain yours; the discipline that lets you meet them has to be ours.
BFSI compliance detail