Technical Architecture & Vendor Security Pack
Everything your internal IT team, managing partner committee, or enterprise corporate clients require for vendor evaluation and compliance audits.
5 Implementation Standards
Detailed technical responses to standard enterprise cybersecurity and vendor risk assessments.
1. Data Encryption
At Rest: AES-256 with key management stored in FIPS 140-2 Level 3 Hardware Security Modules (HSMs).
In Transit: TLS 1.3 enforced across all web, API, and mobile connections with Perfect Forward Secrecy.
2. Logical Tenant Isolation
Multi-tenant architecture enforces strict logical database isolation via parameterized row-level security (RLS) and schema scoping, ensuring zero possibility of cross-tenant data leakage.
3. Backup & Disaster Recovery
Automated daily encrypted snapshots replicated across dual geographic regions in India. Continuous point-in-time recovery (PITR) with RPO < 15 minutes and RTO < 2 hours.
4. CI/CD Scanning & VAPT
Automated static application security testing (SAST) in CI/CD pipelines. Annual third-party penetration testing (VAPT) performed by certified CREST/CERT-In auditing firms.
5. Cloud Infrastructure & Administrative Governance
Hosted exclusively on Tier-4 ISO 27001 / SOC 2 Type II certified cloud facilities in Mumbai & Hyderabad. Internal staff access requires Zero-Trust hardware tokens, ephemeral credentials, and continuous activity monitoring.