Trust & Security

Trust, built into every byte.

Vishwaas AI is owned by DrishVera Private Limited and sold through Tata Tele Business Services (TTBS). India-resident, cryptographically verifiable, and architected to be the regulator's primary source of evidence — because a privacy platform must itself be a model of security.

TLS 1.3
in transit — modern ciphers only
AES-256-GCM
field-level encryption for personal data at rest
RFC 3161
trusted timestamping, on by default for new tenants
72 h / 6 h
DPBI breach clock / CERT-In first notification
7 years
consent and audit evidence retention
Trust principles

Five principles, engineered in.

Non-repudiation

Every consent record is SHA-256 hash-chained to the one before it, RSA-signed, and trusted-timestamped — no party can quietly deny that a consent was given, withdrawn, or modified.

Data minimisation

We collect and process only what is necessary. No passwords, no tracking pixels, no behavioural profiling — anywhere in the platform.

Least privilege

Every system component, database user, and human operator holds the minimum permissions their function needs — enforced in code and at the database grant level.

Defence in depth

Independent controls at the network, application, data, and operational layers — so no single failure exposes personal data.

Transparency

Security architecture and sub-processors documented openly; the detailed review pack — threat model, penetration-test summaries, certification roadmap — available under NDA.
Consent evidence

Proof you can verify, not just trust.

Consent records are append-only, SHA-256 hash-chained, RSA-signed and bound to the exact notice version and language the person saw, with RFC 3161 trusted timestamping on by default — tamper-evident, independently verifiable records.

Append-only by grant

UPDATE and DELETE are revoked on the consent ledger and audit tables at the PostgreSQL role level — no application code, administrator, or attacker can rewrite history.

Chained, signed, timestamped

Each record's hash folds into the next (any edit breaks every subsequent link), is RSA-signed per tenant, and carries an RFC 3161 timestamp token binding it to a moment in time.

Verify it yourself

Chain integrity is checkable via the consent verify-integrity API, and JWT signing keys are published at a standard JWKS endpoint for external verification.
Security posture

How the platform protects data.

India data residency

Primary deployment in ap-south-1 (Mumbai). Optional read-replicas in ap-south-2 (Hyderabad) for §16 residency-sensitive tenants. No personal data leaves India without an explicit legal mechanism under §16.

Encrypted at rest

AES-256-GCM field-level encryption for personal data, with per-tenant keys in a dedicated key-management layer — compromising one tenant's keys never affects another. PII columns hold ciphertext plus a search hash, not plaintext.

Encrypted in transit

TLS 1.3 across client, service-to-service, database, cache and event-stream connections; webhook delivery to your systems requires TLS 1.2 or better.

No passwords, anywhere

OTP-only authentication: CSPRNG-generated codes, stored only as bcrypt hashes with a 10-minute TTL and 5-attempt lockout. Short-lived (15-minute) access tokens in HttpOnly, Secure cookies.

Fine-grained access control

11 customer roles under CASL attribute-based access control — DPO, privacy manager, legal officer, grievance officer, auditor and more — with conditions scoped by tenant, department, and data principal.

Tenant isolation, tested

Defence-in-depth isolation including database-level Row-Level Security on the most sensitive data, exercised in independent penetration testing for cross-tenant leakage.

Append-only audit trail

Every privileged action lands in a SHA-256 hash-chained, append-only audit ledger — enforced at the database grant level — with tamper-evident PDF export for regulators.

Read-only discovery

Data Discovery is read-only in your systems, always — it never deletes, masks, or modifies. Raw samples are discarded immediately after in-memory detection; only classifications and hashes are stored, never the values. Findings are gated behind DPO approval.

Independent VAPT

Annual penetration testing by an independent CERT-In empanelled firm — web, API, cloud configuration, multi-tenant isolation, and cryptographic implementation. Executive summaries available under NDA.
Incident readiness

When something goes wrong, the clock is engineered in.

A documented incident-response plan pairs with the product's own breach module: containment within hours, assessment within a day, and notification tooling built for the 72-hour DPBI clock and the 6-hour CERT-In first notification.

Detect & contain

On-call paging within the first hour; affected systems isolated and evidence preserved within four.

Notify on regulatory clocks

Customer notification within 72 hours, with the platform's 8-milestone breach workflow computing the DPBI and CERT-In deadlines from containment.

Learn & harden

Root-cause analysis and control updates within seven days — and every production change ships through two-engineer review, security scanning, and versioned GitOps deployment with 5-minute rollback.
Data lifecycle

Guarded from creation to erasure.

Exports, controlled

Data exports are encrypted, RBAC-gated, and logged as audit events — every export is on the record, independent of the download link's expiry.

Erasure with evidence

Erasure jobs overwrite ciphertext and write an immutable audit record confirming deletion; key destruction provides cryptographic shredding as a final guarantee.

Retention, locked

Consent records, audit events, rights requests and breach records are retained for 7 years — extendable, never reducible below the regulatory floor.
Compliance posture

DPDP-first, standards-aware.

Security is positioned on verifiable architecture and controls, mapped directly to the DPDP Act: §8(4) safeguards through encryption and access control, §8(6) breach notification through the 72-hour workflow, Rule 7 security safeguards across the stack, and 7-year evidence retention. The platform also helps customers demonstrate alignment with sector expectations — SEBI and IRDAI cybersecurity guidance for BFSI and insurance, ABDM privacy guidelines for healthcare.

Responsible disclosure

Found something? Tell us.

Report a vulnerability

Write to support@vishwaas.ai. Acknowledgement within 24 hours; assessment within 72.

Good faith, protected

We follow coordinated disclosure principles and will not pursue good-faith security researchers.

Stay informed

Security advisories and the sub-processor list are available on request while the public advisory feed is being stood up.

Security review pack available on request.

Threat model, penetration test summaries, architecture diagrams, certification roadmap — all under NDA. Reach out for the full pack.