all_inclusive
AUDEXFLOW
Legal

Technical Architecture & Vendor Security Pack

Everything your internal IT team, managing partner committee, or enterprise corporate clients require for vendor evaluation and compliance audits.

View Vendor Questionnaire fact_check
IT Architecture

5 Implementation Standards

Detailed technical responses to standard enterprise cybersecurity and vendor risk assessments.

enhanced_encryption

1. Data Encryption

At Rest: AES-256 with key management stored in FIPS 140-2 Level 3 Hardware Security Modules (HSMs).
In Transit: TLS 1.3 enforced across all web, API, and mobile connections with Perfect Forward Secrecy.

layers

2. Logical Tenant Isolation

Multi-tenant architecture enforces strict logical database isolation via parameterized row-level security (RLS) and schema scoping, ensuring zero possibility of cross-tenant data leakage.

backup

3. Backup & Disaster Recovery

Automated daily encrypted snapshots replicated across dual geographic regions in India. Continuous point-in-time recovery (PITR) with RPO < 15 minutes and RTO < 2 hours.

bug_report

4. CI/CD Scanning & VAPT

Automated static application security testing (SAST) in CI/CD pipelines. Annual third-party penetration testing (VAPT) performed by certified CREST/CERT-In auditing firms.

domain

5. Cloud Infrastructure & Administrative Governance

Hosted exclusively on Tier-4 ISO 27001 / SOC 2 Type II certified cloud facilities in Mumbai & Hyderabad. Internal staff access requires Zero-Trust hardware tokens, ephemeral credentials, and continuous activity monitoring.

Pre-Filled Document

Pre-Filled IT Security Assessment

Q: Where is customer and client financial data stored?
A: All primary database clusters and object vaults are located in AWS/GCP regions in Mumbai and Hyderabad, India. Zero data is routed or stored internationally.
Q: Does Audexflow staff have access to view client confidential audit files?
A: No. Client files are encrypted at rest with tenant-scoped cryptographic keys. Audexflow support personnel cannot access document content without explicit, time-bounded admin consent.
Q: Is data encrypted during transit and at rest?
A: Yes. All data at rest is encrypted with AES-256. All data in transit uses TLS 1.3 with modern cipher suites and HSTS enabled.
FOURTEEN DAYS, EVERYTHING UNLOCKED

Stop scattering compliance files you were trying to keep organized.

apps Features account_tree Workflow calendar_month Calendar