Compliance · documented & transparent

Compliance &
security, on the record.

The standards we're building toward, the sub-processors we plan to use, the data centres we operate in, and how to contact the people responsible. Everything procurement teams need, on one page.

Standards & posture.

The security and compliance standards we're building toward as we prepare for launch.

SOC 2 · Type II

Security & availability

Independent audit of our controls over security, availability, and confidentiality — planned ahead of public launch.

Planned
ISO 27001:2022

Information security

A formal ISMS covering risk management, access control, cryptography, and supplier security.

Planned
DPDP · India

Indian data protection

Building toward Data Fiduciary obligations under the DPDP Act 2023, with a notified DPO and grievance officer.

In progress
GDPR · EU

European data protection

Standard Contractual Clauses for EU transfers, applied as we expand to EU users.

Planned
PCI-DSS

Card-data security

We never store card data directly — card handling stays within our PCI-compliant payment partner's scope.

Via payment partner
RBI · PA-PG

Payment aggregator

Escrow and payouts are operated through an RBI-authorised Payment Aggregator partner.

Via partner
ASCI

Advertising standards

Campaigns are designed to follow Advertising Standards Council of India influencer-disclosure norms.

Committed
CSA · STAR

Cloud security

Cloud Security Alliance STAR self-assessment, with higher-level attestation on our roadmap.

In progress
Last updated 2026 · MAY · 24Page is refreshed within 7 days of any material change

01Sub-processors

We use the following sub-processors to operate the Service. Customers are notified by email at least 30 days before any addition.

VendorPurposeLocation
Amazon Web ServicesPrimary cloud · compute, storage, networkingIN (ap-south-1) · EU (eu-central-1)
CloudflareCDN, DDoS protection, edge securityGlobal
RazorpayXIndia payments, escrow, payouts (UPI/NEFT/IMPS)IN
Wise (TransferWise)International payouts & multi-currencyUK / Global
Twilio · SendGridTransactional email & SMS OTPUS / EU
Hugging Face InferenceMatchmaking model serving (anonymised inputs)EU (eu-central-1)
LinearInternal issue tracking — no customer dataUS
Plausible AnalyticsPrivacy-friendly site analytics (no PII)EU (Frankfurt)

02Data residency

Indian users' data is primary-stored in Mumbai (AWS ap-south-1). EU users' data is primary-stored in Frankfurt (AWS eu-central-1). Cross-border replication is limited to encrypted backups, governed by SCCs (GDPR) and equivalent safeguards under the DPDP Act.

03Encryption

  • In transit — TLS 1.3 for all customer-facing endpoints; mutual TLS for internal service-to-service.
  • At rest — AES-256 across all primary databases and object storage. Keys managed via AWS KMS with per-tenant data keys.
  • Backups — encrypted, cross-region, retained 30 days; point-in-time recovery enabled.
  • Passwords — Argon2id with per-user salt; never stored in plaintext.

04Incident response

We maintain a documented Incident Response Plan reviewed quarterly. Customer-impacting incidents trigger notification to affected users within 72 hours (DPDP / GDPR limit) with a published post-mortem within 14 days. Our security status is publicly available at status.altibix.com.

05Vulnerability disclosure

We run a coordinated disclosure programme. Report security issues to info@altibix.com (PGP key on request). We acknowledge within 24 hours, triage within 72, and credit researchers in our hall of fame. Critical findings are eligible for a bounty under our published rules.

06Officers & contacts