Trust center
We hold ourselves to the standard we sell.
Certifications
- SOC 2 Type IIIn progress · target 12 months
- CERT-In empanelmentIn progress · target 18 months
- ISO 27001In progress · target 24 months
We do not claim certifications we don't hold. Targets are shown as in-progress with a timeline.
Data residency
Primary region Mumbai (ap-south-1); Singapore and Frankfurt available. Keys never leave the HSM. Audit logs are append-only and object-locked.
Responsible disclosure & security.txt →Compliance frameworks
What each framework requires, and how we map to it.
PCI DSS 4.0
Global · payments
§12.3.3, the mandatory cryptographic inventory, already in force.
NIST IR 8547
US · post-quantum
The whole document is the crypto clause.
CNSA 2.0
US · national security
Signing must be PQ-ready by 2027.
RBI Master Directions
India · BFSI
Key-management and data-protection controls now read onto PQC.
CERT-In directions
India
DPDP Act 2023
India · privacy
Your key material's location becomes a legal question.
ISO 27001:2022
Global
A.8.24, use of cryptography.
ISO 42001:2023 (AI)
Global · AI
SOC 2
Global
GDPR
EU · privacy
EU NIS2 · DORA
EU
SEBI CSCRF
India · markets
CEA · AERB · NERC CIP
India/US · energy & nuclear
FIPS 203 / 204 / 205
US · algorithms
The algorithms themselves.
CycloneDX 1.6 CBOM
Global · standard
