Security & Trust

The first question in every sales call

Procurement data reveals your margins, your vendor relationships, and occasionally things the owner would rather not have in a system. Here's how we handle that.

India-Region Hosting

Your data stays in India. Full stop.

  • All data hosted in India (Mumbai region)
  • No data leaves India unless you explicitly configure an export
  • Cloud infrastructure on AWS ap-south-1
  • Encrypted at rest (AES-256) and in transit (TLS 1.3)

Tenant Isolation

Your data is yours. Not a training set, not a benchmark, not shared.

  • Each customer's data in a separate logical tenant
  • No cross-tenant data access, even for benchmarking
  • API keys scoped to individual tenants
  • Database-level row isolation, not just application-level

Roles, Permissions & Audit

Know who did what, when, and why — including the agent.

  • Role-based access: admin, purchase manager, approver, viewer
  • Every agent action logged with timestamp, user, and outcome
  • Audit log exportable as CSV
  • You can see exactly what the agent did, when, and why

Agent Hard Limits

The agent can never do these things without explicit human approval. No exceptions, no overrides.

  • Commit to any spend or issue a PO
  • Share your data with another customer
  • Contact a vendor outside your approved list
  • Change approval thresholds or workflows
  • Delete any record (audit trail is append-only)

DPDP Posture

Aligned with India's data protection framework from day one.

  • Aligned with India's Digital Personal Data Protection Act, 2023
  • Data Processing Agreement (DPA) available on request
  • Data export available in standard formats on request
  • Data deletion on contract termination, with certificate
  • Sub-processors listed and updated

Still have questions?

We're happy to walk through our security posture on a call, share our detailed security overview, or answer specific questions from your IT team.

Book a Demo Download Security Overview