SECURITY & TRUST

Your whole business, in one place — so it had better be a safe one.

One system holding your customers, ledgers and payroll is only an advantage if it is looked after properly. Here is where your data lives, how it is protected, who can touch it — and, honestly, what is still on the roadmap.

The short answers, first

The six things a security review asks before anything else.

AT A GLANCE

  • India is where your data livesAWS Mumbai region. Backups stay in India too.
  • TLS 1.2+ on every connectionEncrypted in transit; older protocols refused.
  • AES-256 on every diskDatabases, documents and backups, at rest.
  • Zero actions taken without approvalThe AI drafts; nothing is sent, paid or changed until the right role says so.
  • 6 hrs to report to CERT-InReportable incidents, as its 2022 directions require.
  • 35 days of daily backupsAny point in the last week; any day in the last five.

Your records stay in India

Your customers, your ledgers, your payroll — none of it leaves the country to be stored or processed. That is a decision about where the servers are, made once, not a setting you have to find.

  • Spread across availability zonesMore than one physically separate data centre in the region, so losing one does not take your business with it.
  • A recovery copy, still in IndiaThe Hyderabad copy is for recovery from a region-wide failure. Backups do not leave India.
  • AI processing, in the same placeThe models that read and draft for you run against your data inside the same Indian region. Your data is not used to train models for any other business.

Encrypted on the wire and on the disk

Encryption is not a feature you switch on per department. It is on for everything, everywhere, from the first record you bring across.

In transit

TLS 1.2TLS 1.3HSTS

Every connection to OneSuite — browser, mobile, integrations. HSTS means browsers never fall back to plain HTTP.

At rest

AES-256

Databases, uploaded documents, search indexes and backups.

Keys held in a key-management service

AWS KMSYearly rotation

Rotated every year, and never stored alongside the data they protect.

Secrets kept out of code

Salted hashesSecrets manager

Passwords are stored only as salted, slow hashes. API keys and integration credentials live in a secrets manager, not in source code.

Backed up — and the restore rehearsed

A backup nobody has restored is a hope, not a plan. So we restore ours on a schedule, and write down how long it took.

15 minmost data we could lose (RPO)
4 hrsto be running again (RTO)
7 daysof point-in-time recovery
restore tests a year
A full encrypted snapshot every day, kept for 35 days, held in a different availability zone from the live system with a further copy in the Hyderabad region. Once a quarter we restore one into an isolated environment and check it: lose no more than 15 minutes of data, be running again within 4 hours.

Nothing happens without someone’s say-so

The same principle that governs the AI governs people: each person sees the departments their role needs, and anything consequential waits for the person allowed to approve it.

  • Roles set per department

    Who sees, edits and approves in each of the fourteen departments. Your accountant does not need hiring; sales does not need payroll.

  • Approval before action

    The AI drafts the payment, reminder, reorder or filing — and stops until the right role approves it.

  • Multi-factor sign-in

    Any account can require a second factor; administrators can make it mandatory for the whole business.

  • An audit trail you can read

    Who looked at, changed or approved what, when and from where — kept for the life of your account, exportable at any time.

  • No standing access for our staff

    Our engineers do not have standing access to your data. Support access needs your permission, for a limited time and a stated reason.

  • People who are vetted and bound

    Everyone at QUAN with production access signs a confidentiality agreement, passes a background check and is trained in security every year.

Our engineers see your data only when you let them: for a stated reason, for a limited time, and on the record. Illustrative figures, drawn to show the working; not a customer’s records.

Your data stays yours

You are paying us — or, for the first year, not paying us — to run your business, not to own a copy of it.

  • You own it

    Everything your business puts into OneSuite belongs to your business. We process it only to run the service for you, as your data processor.

  • Export it whenever you like

    Any department, any record. No fee, no ticket, no notice period.

    • Records: CSV, Excel
    • Accounting: Tally XML
    • Documents: originals, PDF
    • Everything: JSON via API
  • Never sold, never used for advertising

    We do not sell your data, share it with advertisers, or use it to train models for other businesses.

When you leave, it goes

If something goes wrong, you hear it from us

No system is immune to incidents. What we can promise is how we behave when one happens: quickly, in writing, and without waiting to be asked.

  1. Detect

    Around the clock

    Automated alerts on infrastructure, sign-ins and unusual access, with an engineer on call at all times.

  2. Report to CERT-In

    Within 6 hours

    Reportable cyber-security incidents, counted from when we notice them, as its April 2022 directions require.

  3. Tell you, in writing

    Within 72 hours

    If your data is affected, you hear as soon as we know; a full written account — what happened, what it touched, what we did — follows within 72 hours. The Data Protection Board of India is notified as the DPDP Act requires.

  4. Review

    Afterwards

    Every significant incident ends in a written review of cause and fixes, shared with the customers it affected.

180 days

System and security logs are retained within India for 180 days, so an incident can actually be investigated.

Compliance, as it actually stands

We would rather show you a roadmap than a row of badges we have not earned yet. What is in place is in place; what is planned says so.

  1. Today

    In place

    DPDP Act 2023 alignment

    Privacy notice, purpose-bound processing, rights requests, a named grievance officer, and processor terms for the data you put into OneSuite.

    In place

    CERT-In directions (2022)

    Six-hour incident reporting, a designated point of contact, synchronised clocks and 180-day log retention in India.

  2. Q1 2027

    Planned

    VAPT by a CERT-In empanelled auditor

    An independent vulnerability assessment and penetration test of the application and infrastructure, repeated every year. The summary letter will be available on request. Target: Q1 2027.

  3. 2027

    Planned

    ISO/IEC 27001:2022

    Certification of our information security management system by an accredited body. Target: 2027.

  4. 2028

    Planned

    SOC 2 Type II

    An independent report on how our security controls actually operated over a period of months, not on a single day. Target: 2028.

Ask us the hard questions

Send your security questionnaire, ask for our data processing terms, or report a vulnerability to security@quan.co.in. We answer in writing.