🛡 Trust & Security

SOC 2 Type 2 in-progress · ISO 27001 planned · RBI · DPDP · CERT-In · PMLA compliant by design · Vendor security assessment pack auto-emailed.

📥 Download security pack (PDF) Email security team
Compliance & Certifications
🏛

SOC 2 Type 2

12-month observation
In progress · audit firm Drata · ETA Q3
🔒

ISO 27001

ISMS certification
Planned · Q4 kickoff
💳

PCI DSS

Level 4 SAQ-A
Live · annual SAQ filed
🇮🇳

DPDP Act 2023

Data Fiduciary registration
In progress · DPB submission
⚖️

RBI Master Direction KYC

2024 amendment
Compliant · 43 endpoints
🚨

CERT-In 20(3)/2022

6-hour breach SLA
Automated incident XML
💰

PMLA + FATF

STR + sanctions + UBO
Compliant · 6 lists
🌏

India Data Residency

RBI Storage 2018
Enforced · ap-south-1 only
Security controls

Encryption · Identity · Network

ControlImplementationStatus
At-rest encryptionAWS KMS · envelope encryption · per-tenant CMK · automatic rotationlive
In-transit encryptionTLS 1.3 only · HSTS · perfect forward secrecy · OWASP Score A+live
Multi-tenant isolationPostgres RLS (row-level security) · tenant_id enforced at DB-level · not just applive
AuthenticationSAML 2.0 · OIDC · Magic-link · WebAuthn passkey · API keys w/ scoped JWTlive
AuthorizationRBAC w/ scopes · per-endpoint · per-action · audit log captures all RBAC denialslive
MFA · admin accountsMandatory · TOTP + WebAuthn · 24h session timeout for adminlive
WAF + DDoSAWS WAF · OWASP Top 10 · rate limiting · Shield Standard · Cloudflare optionallive
Secrets managementAWS Secrets Manager · HashiCorp Vault optional · zero secrets in code/gitlive
Network segmentationVPC peering · private subnets only for data · public for ALB onlylive
Audit logSHA256 hash-chained · Merkle-anchored · monthly external timestamp · 10-yr retentionlive

Vulnerability management

ActivityFrequencyLast performed
External penetration test (CERT-In empanelled vendor)Annual + on-major-releaseFeb 2026 · clean · 1 low
Internal red-team exerciseQuarterlyMay 2026 · clean
SAST scan (Semgrep + CodeQL)On every PRContinuous
DAST scan (OWASP ZAP)NightlyLast night · 0 critical
Dependency scan (Snyk + Dependabot)DailyToday · 2 medium auto-fixed
Container image scan (Trivy + Grype)On every build + nightlyContinuous
Cloud config audit (Prowler · Steampipe)DailyToday · 0 high
SBOM publication (CycloneDX)Per releaseLast release v1.0.0-oss

Privacy & Data protection

Incident response

Downloads · Security pack for procurement

Most enterprise customers complete vendor security review in 2-3 days using this pack. Need a custom answer? Email security@zyroai.com · response < 1 business day.