Skip to main content

Security

ISO 27001:2022 certified, with all production data held in India on AWS Mumbai.

Certification and alignment

What we hold, and the frameworks our controls are aligned to.

ISO 27001:2022

Certified information security management system. Annex A control notes are published on our certifications page.

View details

DPDP Act 2023 aligned

Personal-data processing aligned with the Digital Personal Data Protection Act 2023.

View details

RBI IT governance aligned

Controls aligned with RBI IT governance expectations for regulated-entity customers.

View details

AWS Mumbai

Production runs exclusively in the managed AWS Mumbai data centre. No physical servers at office locations.

View details

Security controls

Drawn from our ISO 27001:2022 Annex A control notes.

Encryption at rest and in transit

AES-256 for data at rest and TLS 1.2 or higher for data in transit, with key management through AWS KMS.

Multi-factor authentication

MFA is mandatory for all privileged accounts and enforced on every external-facing system and cloud management console.

Role-based access control

Access is scoped to role and client, with no cross-tenant data access. Access rights are reviewed quarterly and on every role change.

Audit log retention

Audit logs are retained for seven years in line with the regulatory minimum.

Vulnerability management

Vulnerability scans run fortnightly, with critical findings remediated within 72 hours. DAST and penetration testing run before every major release.

Encrypted daily backups

Daily encrypted backups, with restoration tested quarterly against a defined recovery time objective.

Infrastructure

Production hardware sits exclusively in the managed AWS Mumbai data centre, which is SOC 2 Type II audited and built to Tier III standards for power, cooling and environmental controls. There are no physical servers at our office locations.

Access to production is through a centralised identity provider with mandatory multi-factor authentication, under the principle of least privilege. Removable media is prohibited in production environments.

Backups are taken daily and encrypted, and restoration is tested every quarter against a defined recovery time objective.

Security Contacts

Report a vulnerability

info@terra-insight.com

Security questionnaires

info@terra-insight.com

Security FAQ

Common questions about our security practices.

How do you handle data encryption?
Data at rest is encrypted with AES-256 and data in transit with TLS 1.2 or higher; deprecated protocols are disabled. Encryption keys are managed through AWS KMS.
Where is my data stored?
In India. Production for both TransactIG and TransactIQ runs exclusively in the managed AWS Mumbai data centre, operated by Terra Insight. We do not offer on-premise or customer-hosted deployment.
Which certifications do you hold?
Terra Insight is ISO 27001:2022 certified. Our practices are aligned with the Digital Personal Data Protection Act 2023 and with RBI IT governance expectations. The Annex A control-by-control notes are published on our certifications page.
How do you test your security?
Vulnerability scans run fortnightly and critical findings are remediated within 72 hours. Dynamic application security testing and penetration testing are conducted before every major release.
What happens in case of a security incident?
We maintain an incident response plan, tested through an annual tabletop exercise, with runbooks for common incident types and a defined escalation path to CERT-In. Post-incident reviews are completed within five business days and findings are tracked to closure.
Can I request a security questionnaire or assessment?
Yes. Send your questionnaire or assessment request to info@terra-insight.com and our team will respond.

Need more information?

Talk to us about your security review, questionnaire or documentation requirements.