Skip to content
attpro
Book a demo

Security

Written for your vendor questionnaire, not your comfort

Everything below is a property of the running system. Where a certification is not yet held, this page says so instead of implying otherwise. Sub-processors, documents under NDA and the change log are on the Trust Center.

Posture

Eight properties of the running system

Tenant isolation at the schema level

Each lender's data lives in its own database schema, not in shared tables filtered by an ID. A query cannot wander into another tenant's book, because the other book is not addressable from your session.

Your own provider credentials

Telephony, messaging and AI providers connect with credentials you own. Keys are envelope-encrypted at rest, never logged, never shown back in full, and revocable by you at the provider without asking us.

Encryption in transit and at rest

TLS on every connection. Secrets under envelope encryption. Recordings and exports encrypted at rest in in-country object storage.

Data residency in India

Application, database and storage run in-country. No borrower record leaves India in the normal operation of the platform.

Access that is scoped and recorded

Role-based access with a tenant-editable permission matrix. Support access to your tenant happens through time-boxed, reason-required impersonation that writes to an audit feed you can read.

Evidence you can stand behind

Every contact, disposition and payment writes to a hash-chained audit log with a Merkle anchor. A changed record breaks the chain and shows up. Recording disclosure is enforced on every call, and transcripts carry PII redaction.

Retention, erasure and legal hold

Recordings and records live on schedules you set. DPDP erasure requests are honoured through the same lifecycle machinery, and legal hold overrides are themselves audited.

Backups that restore

Automated backups with periodic restore verification - a backup that has never been restored is a hope, not a control.

People controls

The floor is audited the way the software is

For managed and hybrid engagements the people are part of the control surface. Six conduct controls, audited internally every cycle.

DRA-certified employees

Every caller and field officer holds the IIBF Debt Recovery Agent certification before they work an account.

Police clearance before hiring

Background screening with a mandatory Police Clearance Certificate, for the floor and the field.

Training for the lowest escalation rate

Outbound call training is measured on complaints avoided, not calls made.

Timelines enforced in software

Calling and field-visit windows are gates in the dialer and the FOS app, not lines in a policy document.

Periodic refresher training

Every employee re-trains on RBI conduct expectations on a fixed cycle.

Internal audit controls

Conduct, recordings and dispositions are sampled and audited internally every cycle.

Certifications

Held versus planned, without blur

Overclaiming here fails the first serious review, so we do not.

ISO/IEC 27001

Controls are designed against it; the certification audit is on the roadmap and will be dated here when scheduled.

planned

SOC 2

Undertaken on enterprise demand, funded by the first contract that requires it - stated as exactly that.

on demand

Responsible disclosure

A published process for reporting vulnerabilities, with acknowledgement timelines. See the legal section.

active

Controls

Every control, and where it is enforced

Not a policy list. Each row is a property of the running system, enforced by the platform rather than by an instruction to a person.

Control coverage19 controls · 4 groups
ControlState
Data residency in Indiaactive
Encryption in transit and at restactive
Envelope-encrypted secretsactive
PII redaction on transcriptsactive
Retention, erasure and legal holdactive
Schema-per-tenant isolationactive
Role-based access, tenant-editableactive
Multi-factor authenticationactive
Audited support accessactive
Single sign-on (SAML / OIDC)planned
Hash-chained audit logactive
Calling windows enforced at dispatchactive
Recording disclosure enforcedactive
DLT template bindingactive
DRA-certified, police-verified peopleactive
Backups with restore verificationactive
Health monitoring and alertingactive
Published availability targeton-request
Independent penetration testplanned

Held and planned are stated separately and never blurred. A planned control is not described as if it were running.

Send us the questionnaire.

The fastest way to evaluate a vendor's security posture is to make them fill in yours. We answer in writing, and the answers match this page.