Built to be let near production.
You are being asked to put software near servers that run a bank. This is what that software does, where your data lives, and what we can and cannot yet claim.
Least privilege by default.
Code-signed, outbound-only
The agent is code-signed and opens no inbound connections to your endpoints. It sends signal out; nothing dials in. Agentless webhook integration is available where you'd rather deploy nothing at all.
SSO, RBAC, approval gates
Single sign-on and role-based access control throughout. Anything that changes a host passes an approval gate — high-risk actions require change-board sign-off before execution.
Stays in India
All data is stored and processed in AWS ap-south-1 (Mumbai). Per-tenant isolation. Retention is configured per customer and deleted within 90 days of account termination.
An audit trail that survives review.
Every detection, classification, approval and rollback is written to an append-only, HMAC-SHA256 cryptographically chained log. Tamper with one record and the chain breaks — the failure is visible to you and to an auditor. It is built specifically for RBI IT Framework Section 4.2 evidence requirements, and exports are available for RBI, PCI-DSS, SEBI and IRDAI.
What procurement will ask for.
Found something?
We run a responsible-disclosure process. If you've found a vulnerability, tell us before you tell anyone else and we'll work it with you.