Trust · Security · Privacy

Enterprise trust, by design.

This page is maintained by Aiera to answer common security and data-handling questions. It reflects our current controls — not an independent certification.

ap-south-1

India Data Residency

All customer data stored in Mumbai (ap-south-1). No cross-border replication.

6 roles

Role-Based Access

6 roles · row-level scoping by beat, distributor, region. SSO via Google / Azure AD.

7-yr retention

Immutable Audit Log

Every scheme edit, master change, and payout approval is timestamped and signed.

AES-256

Encryption Everywhere

TLS 1.3 in transit · AES-256 at rest · field-level encryption for PII columns.

RPO 15m

Backup & Recovery

Point-in-time restore, 15-min RPO, 4-hr RTO. Quarterly disaster-recovery drill.

DPDP-aligned

DSE Privacy

GPS captured only during shift window · photos hashed, no gallery access · consent logged.

Compliance Posture

SOC 2 Type II

In progress · audit Q4 2026

ISO 27001

Roadmap · 2027

India DPDP Act

Aligned · DPO appointed

VAPT

Quarterly · last Jun 2026

Not a certification

Statuses reflect Aiera's roadmap. Independent audit reports available under NDA on request.

Shared Responsibility

Who owns what

Aiera

Platform uptime, infra security, encryption, backups, audit logging, patching.

You

User provisioning, role assignment, master-data accuracy, scheme approvals, DSE consent workflow.

DSE / Field

Credential hygiene, device lock, on-shift geolocation, honest visit reporting.

Security contact

security@aiera.example

Privacy / DPO

privacy@aiera.example

Vulnerability disclosure

security.txt · 90-day SLA