Security & Trust
The first question in every sales call
Procurement data reveals your margins, your vendor relationships, and occasionally things the owner would rather not have in a system. Here's how we handle that.
Infrastructure
India-Region Hosting
Your data stays in India. Full stop.
- All data hosted in India (Mumbai region)
- No data leaves India unless you explicitly configure an export
- Cloud infrastructure on AWS ap-south-1
- Encrypted at rest (AES-256) and in transit (TLS 1.3)
Data Isolation
Tenant Isolation
Your data is yours. Not a training set, not a benchmark, not shared.
- Each customer's data in a separate logical tenant
- No cross-tenant data access, even for benchmarking
- API keys scoped to individual tenants
- Database-level row isolation, not just application-level
Access Control
Roles, Permissions & Audit
Know who did what, when, and why — including the agent.
- Role-based access: admin, purchase manager, approver, viewer
- Every agent action logged with timestamp, user, and outcome
- Audit log exportable as CSV
- You can see exactly what the agent did, when, and why
Agent Guardrails
Agent Hard Limits
The agent can never do these things without explicit human approval. No exceptions, no overrides.
- Commit to any spend or issue a PO
- Share your data with another customer
- Contact a vendor outside your approved list
- Change approval thresholds or workflows
- Delete any record (audit trail is append-only)
Compliance
DPDP Posture
Aligned with India's data protection framework from day one.
- Aligned with India's Digital Personal Data Protection Act, 2023
- Data Processing Agreement (DPA) available on request
- Data export available in standard formats on request
- Data deletion on contract termination, with certificate
- Sub-processors listed and updated
Still have questions?
We're happy to walk through our security posture on a call, share our detailed security overview, or answer specific questions from your IT team.