The standards we're building toward, the sub-processors we plan to use, the data centres we operate in, and how to contact the people responsible. Everything procurement teams need, on one page.
The security and compliance standards we're building toward as we prepare for launch.
Independent audit of our controls over security, availability, and confidentiality — planned ahead of public launch.
PlannedA formal ISMS covering risk management, access control, cryptography, and supplier security.
PlannedBuilding toward Data Fiduciary obligations under the DPDP Act 2023, with a notified DPO and grievance officer.
In progressStandard Contractual Clauses for EU transfers, applied as we expand to EU users.
PlannedWe never store card data directly — card handling stays within our PCI-compliant payment partner's scope.
Via payment partnerEscrow and payouts are operated through an RBI-authorised Payment Aggregator partner.
Via partnerCampaigns are designed to follow Advertising Standards Council of India influencer-disclosure norms.
CommittedCloud Security Alliance STAR self-assessment, with higher-level attestation on our roadmap.
In progressWe use the following sub-processors to operate the Service. Customers are notified by email at least 30 days before any addition.
| Vendor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Primary cloud · compute, storage, networking | IN (ap-south-1) · EU (eu-central-1) |
| Cloudflare | CDN, DDoS protection, edge security | Global |
| RazorpayX | India payments, escrow, payouts (UPI/NEFT/IMPS) | IN |
| Wise (TransferWise) | International payouts & multi-currency | UK / Global |
| Twilio · SendGrid | Transactional email & SMS OTP | US / EU |
| Hugging Face Inference | Matchmaking model serving (anonymised inputs) | EU (eu-central-1) |
| Linear | Internal issue tracking — no customer data | US |
| Plausible Analytics | Privacy-friendly site analytics (no PII) | EU (Frankfurt) |
Indian users' data is primary-stored in Mumbai (AWS ap-south-1). EU users' data is primary-stored in Frankfurt (AWS eu-central-1). Cross-border replication is limited to encrypted backups, governed by SCCs (GDPR) and equivalent safeguards under the DPDP Act.
We maintain a documented Incident Response Plan reviewed quarterly. Customer-impacting incidents trigger notification to affected users within 72 hours (DPDP / GDPR limit) with a published post-mortem within 14 days. Our security status is publicly available at status.altibix.com.
We run a coordinated disclosure programme. Report security issues to info@altibix.com (PGP key on request). We acknowledge within 24 hours, triage within 72, and credit researchers in our hall of fame. Critical findings are eligible for a bounty under our published rules.