Trust & Security
Your data stays yours.
Security isn't a feature we added later. It's how Vaanika was built from day one - so your security, procurement and legal teams can say yes faster.
All systems operational
Built for complex,
regulated industries.
Encryption, audit trails and certifications that pass security, procurement and legal review on day one. Your data stays yours.
Audited
SOC 2
Type II
Certified
ISO
27001
Ready
DPDP
Act 2023
Compliant
GDPR
EU
Encryption
AES-256 at rest. TLS 1.3 in transit. HSM-backed keys.
Data residency
Deploy in India, the EU or the US.
Access controls
Role-based access with least privilege. MFA on every system.
Incident response
24/7 on-call engineers. Documented runbooks. SLA-backed alerts.
Security practices
Infrastructure
- Hosted in ISO 27001 certified data centres in India
- Isolated customer environments
- Daily encrypted backups
Application
- Secure code reviews on every change
- Annual third-party penetration tests
- Dependency and vulnerability scanning
People
- Background checks for all employees
- Security training every quarter
- Least-privilege access, reviewed monthly
Sub-processors
Third parties that help us deliver the Services and may process customer data.
| Name | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting | India (Mumbai) |
| Exotel | Telephony | India |
| Meta (WhatsApp Business) | Messaging | Global |
| Razorpay | Payments | India |
| Google Workspace | Email and collaboration | Global |
Report a vulnerability
Found a security issue? Email us and we'll respond within 48 hours. We appreciate responsible disclosure.
security@vaanika.ai