You are giving us an agent on production servers. Here is exactly what it does — and what it does not do.
Data residency in India
All customer data is stored and processed in AWS Asia Pacific (Mumbai), ap-south-1. Nothing is replicated outside the region. Zurlux Technologies will not change this default without written notice to affected customers.
Agent behaviour
The PatchMortem agent is a code-signed binary deployed on managed endpoints. It collects patch state and servicing logs. Remediation capability is off by default and must be enabled explicitly, per policy, per host group. The agent initiates outbound TLS only — there is no inbound listener and no open port on your estate.
Encryption
All data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. Per-tenant key isolation is enforced — no shared credentials between customer environments. Encryption keys are managed via AWS KMS with automatic rotation.
Access control
PatchMortem supports SAML and OIDC single sign-on. Role-based access control (RBAC) is enforced at the API level. An approval gate is required for any action that changes the state of a host. All access is logged to the audit chain.
Audit trail integrity
Every detection, decision, approval, and rollback is written to an append-only, HMAC-SHA256 chained audit log. Records cannot be edited or deleted by any user, including Zurlux staff. Retention is configured by the customer and the chain is exportable on demand in formats accepted by RBI, PCI-DSS, SEBI, and IRDAI auditors.
Vulnerability management
All container images are scanned on push via AWS Inspector. Dependencies are monitored via GitHub Dependabot with automated pull requests for security updates. An independent penetration test (VAPT) is scheduled prior to general availability and the report will be shared with customers on request under NDA.
Incident response
Security incidents are acknowledged within 72 hours of report. Critical vulnerabilities affecting customer data are disclosed to affected customers within 48 hours of confirmation. Our responsible disclosure process is documented at disclosure policy.
What we do not do
- We do not patch anything on our own initiative. PatchMortem reacts to your schedule; it does not set one.
- We do not claim agentless coverage. Real root cause needs the servicing logs, and those live on the host.
- We do not roll back where the rollback is unsafe — a driver, firmware flash, or schema change gets flagged for a human.
- We do not hold SOC 2 or ISO 27001 today. The controls above are built and running; the audits are on the roadmap and we will not imply otherwise.
- We do not access customer systems without explicit authorisation documented in a signed Data Processing Addendum.
Certifications and compliance
| SOC 2 Type I | In progress — target Q4 2026 |
| ISO 27001 | Roadmap — 2027 |
| RBI IT Framework 2023 | Aligned — audit trail designed for Section 4.2 |
| AWS BAA | Signed — July 2026 |
| VAPT | Scheduled — pre-GA |
| Data residency | AWS ap-south-1 (Mumbai) — all data |