DPDP-ready by design. Runs in your cloud, in your tenancy. India data residency by default. The executive summary is below — the full reference for security reviewers lives in our posture post.
The headline commitments every CXO and procurement team asks for. The full reference — regulatory tables, sub-processors, retention by class — lives in our posture post.
Consent capture, retention by class, and withdrawal are built into every deployment — not bolted on. PII is redacted before any model call.
Every system runs in your tenancy on AWS, Azure, or GCP — your identity, your keys, your audit boundary. An on-prem option is available.
All deployments run in ap-south-1 (Mumbai) by default. No cross-border transfer without explicit consent and a documented purpose.
Every external call, model invocation, and human decision is written to a tamper-evident WORM store, with retention enforced at bucket policy.
ISMS being built against the standard, target Q4 2026. SOC 2 and GDPR programmes follow our enterprise expansion in 2027.
For the most sensitive environments, the full Blueprint can be deployed on-premise — no public egress, nothing leaving the boundary you control.
Regulatory alignment, technical controls, the sub-processor list, data residency, retention by class, and DPDP specifics — in full.
Architecture diagrams. Sub-processor DPAs. Pentest summary. ISMS scope statement. DPDP compliance questionnaire. Available under NDA for enterprise prospects.