Trust Center

Every artefact, on request.

Most security reviews ask the same 200 questions. We've published the answers. Request an NDA, and you'll receive the full pack — audit reports, control mappings, sub-processor list, pen-test summary, and a pre-completed CAIQ — within one business day.

Available artefacts

Self-service security review.

Click any artefact to request it. NDA gets returned signed within 4 business hours; document pack follows within 24 hours.

AUDIT REPORT

SOC 2 Type II

Independent attestation of our security, availability, processing integrity, confidentiality and privacy controls over a 12-month observation window.

Latest report: current · Renews annually
CERTIFICATION

ISO/IEC 27001:2022

Information security management system. Issued by an accredited certification body covering all production Cyfriq services.

Status: current
CERTIFICATION

ISO/IEC 27701:2019

Privacy information management system extension to ISO 27001. Covers data-principal rights, breach handling, and DPO controls.

Status: current
QUESTIONNAIRE

CAIQ v4 (CSA STAR)

Cloud Security Alliance Consensus Assessments Initiative Questionnaire — 261 pre-answered control questions covering our entire cloud-native stack.

Last updated: April 2026
QUESTIONNAIRE

SIG / SIG Lite

Standardized Information Gathering questionnaire — pre-completed full and lite versions. We respond to vendor-specific questionnaires within 5 business days.

Updated quarterly
PEN TEST

Penetration test summary

Executive summary of the most recent third-party penetration test against the Cyfriq production environment. Findings, severity, remediation status.

Last test: 2026 Q1 · Annual cadence
DPDP

DPDP Act 2023 readiness letter

Third-party readiness assessment mapping Cyfriq controls to the Data Protection Board's expected obligations for Data Fiduciaries and Processors.

Status: current
SUB-PROCESSORS

Sub-processor list

Complete list of third parties processing customer data on behalf of Cyfriq. Includes purpose, location, and security attestations of each.

30-day change notification SLA
LEGAL

Data Processing Agreement

DPDP- and GDPR-aligned DPA covering all processing activities, sub-processor disclosure, breach notification SLAs and data residency.

No NDA required
ARCHITECTURE

Architecture diagram

Logical data-flow diagram showing customer endpoints → Cyfriq edge → policy engine → KMS-wrapped storage → WORM audit. Buyer-level detail.

No NDA required
VULN DISCLOSURE

Security.txt + disclosure policy

Coordinated vulnerability disclosure. Researchers can submit findings to security@cyfriq.com. We acknowledge within 1 business day.

Public credit on request
STATUS

System status & uptime

Live production status, current incidents (if any), and historical uptime by component. Subscribe for incident notifications.

Updated in real time
For your security questionnaire

Send us your specific questionnaire. We respond within 5 business days.

Different procurement teams use different questionnaire formats. Send yours — Excel, Word, PDF, vendor portal link — to security@cyfriq.com. We'll return it pre-completed with evidence attachments.

Built on · Sovereign data foundation

The sovereign foundation beneath your data

Cyfriq is built on ShaktiDB — India's indigenous, open-source, PostgreSQL-forked database, incubated at and backed by IIT Madras Pravartak. Engineered for sovereignty, ACID-compliant, and designed to align with RBI regulations and CERT-In's SBOM directive. The trust we ask you to place in Cyfriq rests on a foundation built for it.