SECURITY & TRUST
Your whole business, in one place — so it had better be a safe one.
One system holding your customers, ledgers and payroll is only an advantage if it is looked after properly. Here is where your data lives, how it is protected, who can touch it — and, honestly, what is still on the roadmap.
The short answers, first
The six things a security review asks before anything else.
AT A GLANCE
- India is where your data livesAWS Mumbai region. Backups stay in India too.
- TLS 1.2+ on every connectionEncrypted in transit; older protocols refused.
- AES-256 on every diskDatabases, documents and backups, at rest.
- Zero actions taken without approvalThe AI drafts; nothing is sent, paid or changed until the right role says so.
- 6 hrs to report to CERT-InReportable incidents, as its 2022 directions require.
- 35 days of daily backupsAny point in the last week; any day in the last five.
Your records stay in India
Your customers, your ledgers, your payroll — none of it leaves the country to be stored or processed. That is a decision about where the servers are, made once, not a setting you have to find.
LIVE SERVICE
Mumbai
AWS Asia Pacific · ap-south-1
RECOVERY COPY
Hyderabad
AWS Asia Pacific · ap-south-2
- Spread across availability zonesMore than one physically separate data centre in the region, so losing one does not take your business with it.
- A recovery copy, still in IndiaThe Hyderabad copy is for recovery from a region-wide failure. Backups do not leave India.
- AI processing, in the same placeThe models that read and draft for you run against your data inside the same Indian region. Your data is not used to train models for any other business.
Encrypted on the wire and on the disk
Encryption is not a feature you switch on per department. It is on for everything, everywhere, from the first record you bring across.
In transit
Every connection to OneSuite — browser, mobile, integrations. HSTS means browsers never fall back to plain HTTP.
At rest
Databases, uploaded documents, search indexes and backups.
Keys held in a key-management service
Rotated every year, and never stored alongside the data they protect.
Secrets kept out of code
Passwords are stored only as salted, slow hashes. API keys and integration credentials live in a secrets manager, not in source code.
Backed up — and the restore rehearsed
A backup nobody has restored is a hope, not a plan. So we restore ours on a schedule, and write down how long it took.
01 Point-in-time
To within minutes
02 Daily snapshots
Any day, then deleted
03 Hyderabad copy
Second region
Nothing happens without someone’s say-so
The same principle that governs the AI governs people: each person sees the departments their role needs, and anything consequential waits for the person allowed to approve it.
Roles set per department
Who sees, edits and approves in each of the fourteen departments. Your accountant does not need hiring; sales does not need payroll.
Approval before action
The AI drafts the payment, reminder, reorder or filing — and stops until the right role approves it.
Multi-factor sign-in
Any account can require a second factor; administrators can make it mandatory for the whole business.
An audit trail you can read
Who looked at, changed or approved what, when and from where — kept for the life of your account, exportable at any time.
No standing access for our staff
Our engineers do not have standing access to your data. Support access needs your permission, for a limited time and a stated reason.
People who are vetted and bound
Everyone at QUAN with production access signs a confidentiality agreement, passes a background check and is trained in security every year.
Support access request
Request SA-0193 · QUAN support
PREPARED
Let QUAN support read the Accounts department for 4 hours to fix the bank import.
Waiting for the owner
Access ends on its own when the time is up, and every record opened shows in the audit trail.
Your data stays yours
You are paying us — or, for the first year, not paying us — to run your business, not to own a copy of it.
You own it
Everything your business puts into OneSuite belongs to your business. We process it only to run the service for you, as your data processor.
Export it whenever you like
Any department, any record. No fee, no ticket, no notice period.
- Records: CSV, Excel
- Accounting: Tally XML
- Documents: originals, PDF
- Everything: JSON via API
Never sold, never used for advertising
We do not sell your data, share it with advertisers, or use it to train models for other businesses.
When you leave, it goes
01 Export window
90 days
02 Live system
Within 30 days
03 Backups
Within 35 more
If something goes wrong, you hear it from us
No system is immune to incidents. What we can promise is how we behave when one happens: quickly, in writing, and without waiting to be asked.
Detect
Around the clockAutomated alerts on infrastructure, sign-ins and unusual access, with an engineer on call at all times.
Report to CERT-In
Within 6 hoursReportable cyber-security incidents, counted from when we notice them, as its April 2022 directions require.
Tell you, in writing
Within 72 hoursIf your data is affected, you hear as soon as we know; a full written account — what happened, what it touched, what we did — follows within 72 hours. The Data Protection Board of India is notified as the DPDP Act requires.
Review
AfterwardsEvery significant incident ends in a written review of cause and fixes, shared with the customers it affected.
System and security logs are retained within India for 180 days, so an incident can actually be investigated.
Compliance, as it actually stands
We would rather show you a roadmap than a row of badges we have not earned yet. What is in place is in place; what is planned says so.
Today
In placeDPDP Act 2023 alignment
Privacy notice, purpose-bound processing, rights requests, a named grievance officer, and processor terms for the data you put into OneSuite.
In placeCERT-In directions (2022)
Six-hour incident reporting, a designated point of contact, synchronised clocks and 180-day log retention in India.
Q1 2027
PlannedVAPT by a CERT-In empanelled auditor
An independent vulnerability assessment and penetration test of the application and infrastructure, repeated every year. The summary letter will be available on request. Target: Q1 2027.
2027
PlannedISO/IEC 27001:2022
Certification of our information security management system by an accredited body. Target: 2027.
2028
PlannedSOC 2 Type II
An independent report on how our security controls actually operated over a period of months, not on a single day. Target: 2028.
Ask us the hard questions
Send your security questionnaire, ask for our data processing terms, or report a vulnerability to security@quan.co.in. We answer in writing.