Security

Built to be let near production.

You are being asked to put software near servers that run a bank. This is what that software does, where your data lives, and what we can and cannot yet claim.

Data residency · AWS Mumbai (ap-south-1) HMAC-SHA256 audit chain SOC 2 Type I · in progress ISO 27001 · not yet
Architecture

Least privilege by default.

Agent

Code-signed, outbound-only

The agent is code-signed and opens no inbound connections to your endpoints. It sends signal out; nothing dials in. Agentless webhook integration is available where you'd rather deploy nothing at all.

Access

SSO, RBAC, approval gates

Single sign-on and role-based access control throughout. Anything that changes a host passes an approval gate — high-risk actions require change-board sign-off before execution.

Data

Stays in India

All data is stored and processed in AWS ap-south-1 (Mumbai). Per-tenant isolation. Retention is configured per customer and deleted within 90 days of account termination.

Audit & evidence

An audit trail that survives review.

Every detection, classification, approval and rollback is written to an append-only, HMAC-SHA256 cryptographically chained log. Tamper with one record and the chain breaks — the failure is visible to you and to an auditor. It is built specifically for RBI IT Framework Section 4.2 evidence requirements, and exports are available for RBI, PCI-DSS, SEBI and IRDAI.

Compliance & data processing

What procurement will ask for.

Regulatory alignment
RBI IT Framework 2023 · PCI-DSS · SEBI · IRDAI
Data protection
Data Processing Addendum under the DPDP Act 2023; Zurlux acts as Data Processor
Sub-processors
AWS (ap-south-1), Pinecone, Anthropic — anonymised signals only
Breach notification
Within 72 hours of a confirmed breach
Retention
Configured per customer; deleted within 90 days of termination
Audit rights
Customer may audit once per calendar year, 30 days notice
SOC 2
Type I — in progress. Controls are running today; the report follows when the audit completes
ISO 27001
Not yet held — we won't imply a certification we don't have

Found something?

We run a responsible-disclosure process. If you've found a vulnerability, tell us before you tell anyone else and we'll work it with you.

Responsible disclosure →