Trust · Security · Privacy
This page is maintained by Aiera to answer common security and data-handling questions. It reflects our current controls — not an independent certification.
India Data Residency
All customer data stored in Mumbai (ap-south-1). No cross-border replication.
Role-Based Access
6 roles · row-level scoping by beat, distributor, region. SSO via Google / Azure AD.
Immutable Audit Log
Every scheme edit, master change, and payout approval is timestamped and signed.
Encryption Everywhere
TLS 1.3 in transit · AES-256 at rest · field-level encryption for PII columns.
Backup & Recovery
Point-in-time restore, 15-min RPO, 4-hr RTO. Quarterly disaster-recovery drill.
DSE Privacy
GPS captured only during shift window · photos hashed, no gallery access · consent logged.
Compliance Posture
SOC 2 Type II
In progress · audit Q4 2026
ISO 27001
Roadmap · 2027
India DPDP Act
Aligned · DPO appointed
VAPT
Quarterly · last Jun 2026
Not a certification
Statuses reflect Aiera's roadmap. Independent audit reports available under NDA on request.
Shared Responsibility
Who owns what
Platform uptime, infra security, encryption, backups, audit logging, patching.
User provisioning, role assignment, master-data accuracy, scheme approvals, DSE consent workflow.
Credential hygiene, device lock, on-shift geolocation, honest visit reporting.
Security contact
security@aiera.example
Privacy / DPO
privacy@aiera.example
Vulnerability disclosure
security.txt · 90-day SLA