Enterprise Security

Security is our foundation,
not an afterthought

We hold ourselves to the same standards we help our customers achieve. Anverith AI is built on enterprise-grade security infrastructure with India-native data residency and continuous compliance monitoring.

AES-256 + TLS 1.3
India Data Residency
Annual VAPT
SOC 2 Planned
Zero Data Training
Security Posture

Six pillars of enterprise security

Every layer of Anverith AI is designed to meet the requirements of the most security-conscious enterprise teams.

Enforced

AES-256 Encryption

All data encrypted at rest using AES-256 and in transit using TLS 1.3. Encryption keys are rotated quarterly and stored in AWS KMS.

Planned

SOC 2 Type 2

SOC 2 Type 2 certification is planned as we scale. We help our customers achieve SOC 2 — and hold ourselves to the same standards we set for them.

Available

India Data Residency

Indian customer data stays in the Mumbai region (AWS ap-south-1). Data never leaves the selected region. DPDP-compliant by design.

Certified

VAPT Tested

Annual penetration testing conducted by a CREST-accredited security firm. Last test: Q1 2026. Reports available to enterprise customers under NDA.

Guaranteed

99.9% Uptime SLA

Guaranteed 99.9% uptime for Scale and Enterprise plans with <15 minute RTO. Real-time status at anverith.com/status.

Enforced

Zero Training on Your Data

Your compliance data, evidence, and AI system information are never used to train models. Strict data isolation between tenants.

Data Residency

Your data stays where you choose

Select your region at onboarding. Data never crosses regional boundaries. Fully compliant with DPDP, GDPR, and local data protection laws.

RegionData CentreComplianceStatus
IndiaMumbai (AWS ap-south-1)DPDP 2023 compliant
Available
European UnionFrankfurt (AWS eu-central-1)GDPR compliant
Available
United StatesVirginia (AWS us-east-1)SOC 2 compliant
Available

Need a specific region not listed above? Contact our enterprise team

Access & Identity

Enterprise-grade access controls

Every access point is locked down with multi-layer controls designed for regulated industries.

  • Role-Based Access Control (RBAC) with least-privilege principle
  • MFA enforcement for all user accounts — TOTP and backup codes
  • Immutable audit log for every user action and data access event
  • API keys scoped per integration with granular permissions
  • Session timeout with configurable idle period (default 30 min)
  • SSO / SAML 2.0 support for Enterprise plans
  • IP allowlisting available on Scale and Enterprise plans
  • Single-tenant deployment option for regulated industries

Audit Log — Live Preview

10:42:01Evidence uploaded[email protected]
10:41:33Compliance scan triggered[email protected]
10:38:17AI system registered[email protected]
10:35:52Trust Passport published[email protected]
10:30:04Login attempt blocked (MFA)unknown
10:28:41Report downloaded[email protected]

Every action logged · Tamper-proof · Exportable

We Eat Our Own Cooking

Anverith's own compliance status

We use Anverith AI to manage our own compliance. Here's exactly where we stand — no spin.

ISO 27001

Planned

Information Security Management System

Target: 2027

SOC 2 Type 2

Planned

Trust Service Criteria — Security & Availability

Target: 2027

DPDP 2023

Compliant

India Digital Personal Data Protection Act

Currently compliant

ISO 42001:2023

Planned

AI Management System Standard

Target: 2027

Enterprise customers can request our latest compliance reports and VAPT summaries under NDA. [email protected]

Transparency

Sub-processors & third-party services

We maintain a complete list of all sub-processors with access to customer data.

Amazon Web Services (AWS)Cloud infrastructure, storage, computeIndia / EU / US
Anthropic (Claude)AI model for document analysis and model card generation (no data retention)US
PostmarkTransactional email (notifications, reports)US
RazorpayINR payment processing (Indian customers)India
StripeUSD payment processing (international)US

Last updated: June 2026 · Changes notified 30 days in advance

Responsible Disclosure

Found a security vulnerability in Anverith AI? We take every report seriously. Please disclose responsibly and we commit to a response within 24 hours.

[email protected]

PGP key available on request · We do not pursue legal action for responsible disclosure

Need full security documentation?

Enterprise customers can request our security questionnaire responses, VAPT summary, SOC 2 bridge letter, and sub-processor list under NDA.

Response within 24 hours NDA available CISO-to-CISO calls available