Security & data handling

What runs on your servers. What leaves your network. What we cannot do.

Trust in this category is not a badge on a page.

You are giving us an agent on production servers. Here is exactly what it does — and what it does not do.

Data residency in India

All customer data is stored and processed in AWS Asia Pacific (Mumbai), ap-south-1. Nothing is replicated outside the region. Zurlux Technologies will not change this default without written notice to affected customers.

Agent behaviour

The PatchMortem agent is a code-signed binary deployed on managed endpoints. It collects patch state and servicing logs. Remediation capability is off by default and must be enabled explicitly, per policy, per host group. The agent initiates outbound TLS only — there is no inbound listener and no open port on your estate.

Encryption

All data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. Per-tenant key isolation is enforced — no shared credentials between customer environments. Encryption keys are managed via AWS KMS with automatic rotation.

Access control

PatchMortem supports SAML and OIDC single sign-on. Role-based access control (RBAC) is enforced at the API level. An approval gate is required for any action that changes the state of a host. All access is logged to the audit chain.

Audit trail integrity

Every detection, decision, approval, and rollback is written to an append-only, HMAC-SHA256 chained audit log. Records cannot be edited or deleted by any user, including Zurlux staff. Retention is configured by the customer and the chain is exportable on demand in formats accepted by RBI, PCI-DSS, SEBI, and IRDAI auditors.

Vulnerability management

All container images are scanned on push via AWS Inspector. Dependencies are monitored via GitHub Dependabot with automated pull requests for security updates. An independent penetration test (VAPT) is scheduled prior to general availability and the report will be shared with customers on request under NDA.

Incident response

Security incidents are acknowledged within 72 hours of report. Critical vulnerabilities affecting customer data are disclosed to affected customers within 48 hours of confirmation. Our responsible disclosure process is documented at disclosure policy.

What we do not do

  • We do not patch anything on our own initiative. PatchMortem reacts to your schedule; it does not set one.
  • We do not claim agentless coverage. Real root cause needs the servicing logs, and those live on the host.
  • We do not roll back where the rollback is unsafe — a driver, firmware flash, or schema change gets flagged for a human.
  • We do not hold SOC 2 or ISO 27001 today. The controls above are built and running; the audits are on the roadmap and we will not imply otherwise.
  • We do not access customer systems without explicit authorisation documented in a signed Data Processing Addendum.

Certifications and compliance

SOC 2 Type IIn progress — target Q4 2026
ISO 27001Roadmap — 2027
RBI IT Framework 2023Aligned — audit trail designed for Section 4.2
AWS BAASigned — July 2026
VAPTScheduled — pre-GA
Data residencyAWS ap-south-1 (Mumbai) — all data
Report a security issue →