TRUST CENTER

A security product has to survive its own scrutiny.

Everything a security or procurement team needs to evaluate us, in one place. We'd rather hand you the evidence than ask you to trust the claim.

02 · THE EVIDENCE
DATA RESIDENCY
Your tenant's region, stated in writing.

India is live today. The country your data is stored in is set per customer and written into your contract — not buried in a FAQ.

ARCHITECTURE & ENCRYPTION
Isolated, encrypted, role-bound.

Your data sits in its own walled-off space, is scrambled both while moving and while stored, is protected against tampering, and is locked down so each staffer sees only what their role needs (role-based access).

COMPLIANCE MAPPING
Mapped to the frameworks you answer to.

ISO 27001 · SOC 2 · GDPR · HIPAA · PCI DSS · DPDP · RBI/SEBI/CERT-In. Cyfriq helps you demonstrate controls — the programme stays yours.

SUB-PROCESSORS
List public. DPA on request.

A current sub-processor list, and a signed Data Processing Agreement for your procurement file.

REPORT A VULNERABILITY
security@cyfriq.com

Responsible disclosure policy, plus a live /.well-known/security.txt — for a security vendor, itself a trust signal.

DOCUMENT REQUESTS
The security pack.

Certificates, an independent penetration-test summary (VAPT), a data-processing agreement (DPA), and our security & architecture whitepaper — shared under NDA.

Need our security pack?

Certificates, VAPT summary, DPA and whitepaper — assembled for your vendor-risk review.

Request the pack Book a demo