Get in touch

Trust & security

Security & compliance

How we approach security and compliance across the products and the organisation.

Certifications & attestations

Independently certified

ISO/IEC 27001 certified

ISO/IEC 27001

An established information-security management system covering the products, the platform and the organisation.

SOC 2 attested

SOC 2

Controls attested against security, availability and confidentiality.

Framework coverage

GDPR, DPDP Act, ISO 27701, HIPAA, PCI DSS, NIST CSF and CERT-In — cross-mapped across 20+ frameworks in Probity.

Tenancy & data separation

Separated at the data layer

Each product separates tenants at the infrastructure and data layer, not only in application logic — row-level security, per-tenant search isolation and per-organisation scoping across the portfolio.

Encryption is applied to data in transit and at rest, and credentials are held using industry-standard mechanisms — limiting the blast radius of any single compromise.

Deployment & data residency

Run it where your policy requires

The same products can be deployed to suit your data-handling obligations.

Ramadya-hosted cloud

Hosted by Ramadya in a multi-tenant cloud, kept current and monitored.

Customer cloud

Deployed into your own cloud tenancy, keeping data within your environment and controls.

On-premise

Operated entirely within your infrastructure where regulation or policy requires it.

What data each product processes, and where it is held, is documented per product and available on request.