Security & Trust

You're evaluating the company as much as the product. Good.

An identity platform holds the keys to everything else. Here is how we secure ours — the certification, the architecture choices and the practices behind both products.

ISO/IEC 27001:2022 certified

Our information security management system is certified to ISO/IEC 27001:2022, with a scope covering the complete product lifecycle — design, development, delivery and support.

Deployment & data residency

On-premises, private cloud, public cloud or hybrid. In on-premises deployments, identity data, credentials and logs never leave your infrastructure. Cloud deployments keep data in India.

Credential protection

Credentials for legacy application SSO are stored encrypted, injected without user visibility and rotated automatically. Administrative access to the platform itself is MFA-protected and audited.

Availability & resilience

High-availability topologies and disaster-recovery deployments are supported for both products — including primary + DR site architectures standard in Indian BFSI.

Auditability

Every authentication decision, provisioning action, review sign-off and administrative change is logged for traceability. Log retention aligns with CERT-In and DPDP expectations.

Responsible disclosure

Found a vulnerability? Report it to [email protected] with 'SECURITY' in the subject. We acknowledge within 48 hours, keep you informed through remediation, and credit researchers who report responsibly.

Evaluating us formally? We support security questionnaires, architecture reviews and audit meetings as part of every enterprise engagement — request our security documentation.

Put our architecture in front of your security team

We'll walk your architects through deployment topologies, encryption, credential handling and audit design — engineer to engineer.