Trust & Security at AUDT
Governance Built on Proof.
AUDT is an AI-Native Trust, Risk & Compliance Platform designed for regulated industries. This page documents our security architecture, compliance posture, data protection practices, and responsible AI principles.
Security Architecture
Multi-tenant isolation, zero-trust auth, layered defense, and India data residency.
Compliance Frameworks
ISO 27001, SOC 2, DPDP, PCI DSS, HIPAA, GDPR, and EU AI Act support.
Encryption
AES-256-GCM at rest, TLS 1.3 in transit, bcrypt for secrets, HSTS preload.
Data Protection
Row-Level Security on every table, tenant isolation, DPDP readiness, export and deletion.
Privacy
What we collect, what we never do, customer data ownership, and right to erasure.
Responsible AI
Gemini 2.5 Flash, no training on customer data, human-in-the-loop, audit trail.
Support & Operations
Support channels, SLA commitments by plan, severity levels, and incident procedures.
Security Contact
Responsible disclosure policy, PGP key, and 24-hour acknowledgement SLA.
Uptime & Status
Real-time service health, incident history, and SLA commitments.
API Security
Bearer auth, bcrypt API keys, rate limiting, and versioned REST endpoints.
Legal & Commercial
Documentation for enterprise procurement, legal review, and data protection compliance.
Terms of Service
Service terms, acceptable use, liability, and governing law.
Privacy Policy
Data collection, retention, sub-processors, and your rights.
Data Processing Agreement
Processor obligations, sub-processors, data transfers, and DPDP compliance.
Responsible Disclosure
Security vulnerability reporting, scope, and safe harbour commitment.