Security at dcomply

Your Compliance Data, Fortified

dcomply is built on a defence-in-depth philosophy, multiple independent layers of protection so that no single failure can compromise your data. As a product of Decipher Consultancy Services, we hold ourselves to the same compliance standards we help you achieve.

AES-256
Data Encryption
India
Data Residency
TLS 1.3
Transit Security
99.9%
Uptime Target
Our Approach

Five Pillars of dcomply Security

Every layer of our platform is purpose-built to keep your data safe, from the moment it enters our system until the moment you choose to remove it.

1

Encryption Everywhere

Your data is never stored or transmitted in plaintext.

  • AES-256 bit encryption for all data at rest, databases, backups, and file storage
  • TLS 1.3 enforced on every connection. API calls, browser sessions, and webhooks
  • Encryption keys managed through hardware security modules with automatic rotation
2

Identity & Access Governance

The right people see the right data, nothing more.

  • Granular role-based permissions. Admin, Manager, Analyst, and Viewer roles
  • Multi-factor authentication (MFA) available for every account
  • Automatic session expiry, IP anomaly detection, and brute-force lockout
3

Indian Data Residency

Your data stays in India, period.

  • All primary databases and file storage hosted on Indian cloud infrastructure
  • Automated daily backups stored in geographically separate Indian data centres
  • Compliant with DPDP Act data localisation and cross-border transfer provisions
4

Secure Software Delivery

Security is built into every line of code we ship.

  • Peer code reviews, static analysis (SAST), and dependency audits on every pull request
  • OWASP Top 10 protections, parameterised queries, CSP headers, CSRF tokens
  • Third-party penetration tests annually; critical patches deployed within 24 hours
5

Incident Preparedness

We plan for the worst so you don't have to.

  • Documented incident response plan with defined escalation matrix
  • 24/7 infrastructure monitoring with automated anomaly alerts
  • Breach notification per DPDP Act Section 8(6). Board and individuals notified
  • Point-in-time recovery with RPO under 1 hour, RTO under 4 hours
  • Post-incident reviews with root cause analysis published internally
  • Immutable audit logs retained for 3 years for forensic review
Commitments

What We Promise You

We Never Sell Your Data

Your compliance data, documents, and assessments are yours. We do not sell, rent, share, or monetise your data in any way. Period.

No AI Training on Your Content

Documents you upload for analysis are processed solely for compliance assessment. They are never used to train machine learning models or shared with AI providers.

Complete Data Erasure

When you delete your account or request erasure, we permanently remove all your data within 30 days, including backups. No ghost copies, no archives.

Tenant Isolation

Each customer's data is logically isolated at the database level. One customer's data can never be accessed by or leaked to another, even in error.

Full Audit Trail

Every data access, modification, and deletion event is logged with timestamps and user identity. These logs are immutable and exportable for your compliance records.

Minimal Internal Access

Our own team operates on least-privilege access. Customer data access requires multi-party approval, is time-limited, and is fully logged for review.

Standards

Aligned with Leading Frameworks

DPDP Act 2023

Built for India's data protection law from day one

ISO 27001 Aligned

ISMS controls mapped and implemented across operations

OWASP Top 10

Application security covering all critical web vulnerabilities

PCI-DSS via Razorpay

Payments handled by PCI-certified processor, we never see card data

Questions

Common Security Questions

Yes, all customer data resides on Indian cloud infrastructure. Backups are also stored within India in a geographically separate facility. This ensures full compliance with DPDP Act data localisation requirements.

No. Our team operates on a strict least-privilege model. Access to customer data requires documented justification, multi-party approval, and is time-limited. All access events are logged and periodically audited. Routine operations do not require access to your data.

Absolutely not. Documents you upload are processed solely for the compliance analysis you requested. We do not use customer data, in any form, to train, fine-tune, or improve machine learning models. Any external processing involves automatic PII redaction beforehand.

You get a 30-day window to export your data after cancellation. After that, all your data, including documents, assessments, reports, and activity logs, is permanently and irreversibly deleted from our systems, including backups. You can also request immediate erasure by contacting our Grievance Officer Subesh Kumar at [email protected] or +91 9911202099.

We follow a documented incident response plan. Per Section 8(6) of the DPDP Act, we notify the Data Protection Board of India and all affected individuals with breach details, impact assessment, and remediation steps. Post-incident, we conduct a root cause analysis and publish a summary to prevent recurrence.

Yes. Enterprise customers can request our latest penetration test summary, infrastructure audit report, and detailed security documentation under NDA. Reach out to our team at [email protected] or through our contact page.

Have Security Questions?

Our team at Decipher Consultancy Services is happy to walk you through our security practices or arrange a detailed review.