Trust Center
Everything a vendor review will ask, in one place
Security posture, certifications held and planned, where data lives, who processes it, and the documents we can hand over. Every line is a property of the running system or a document you can request; where something is not yet true, it says so.
16 in place · 2 planned · 1 on requestnothing overclaimed
On this page
At a glance
Four properties, stated first
Data in India
Application, database and storage in Indian regions.
Encrypted everywhere
TLS in transit; databases, recordings and backups at rest.
Isolated per tenant
One database schema per lender; nothing shared by row filter.
Evidence you can verify
Hash-chained audit log with a Merkle anchor on every action.
16 controls in place · 2 planned · 1 available on request. Last reviewed .
Controls
What is in place, what is planned
Grouped the way a questionnaire groups them. Planned means designed and scheduled, not aspirational.
Data protection5 of 5 in place
Data residency in India
In placeApplication, database and object storage run in Indian regions. No borrower record leaves India in normal operation.
Encryption in transit and at rest
In placeTLS 1.2+ on every connection; databases, backups, recordings and exports encrypted at rest.
Envelope-encrypted secrets
In placeProvider credentials are encrypted with per-tenant data keys under a master key; never logged, never shown back in full.
PII redaction on transcripts
In placeCall transcripts carry PII redaction before they are stored for QA and analytics.
Retention, erasure and legal hold
In placeRecordings and records live on schedules the lender sets; DPDP erasure and legal hold run through the same audited lifecycle.
Isolation and access4 of 5 in place
Schema-per-tenant isolation
In placeEach lender's data lives in its own database schema. Another tenant's book is not addressable from your session.
Role-based access, tenant-editable
In placeA permission matrix per tenant; admins control which role can see or do what.
Multi-factor authentication
In placeTOTP second factor for platform users; enforced for administrator roles.
Audited support access
In placeSupport enters a tenant only through time-boxed, reason-required impersonation that writes to an audit feed the tenant can read.
Single sign-on (SAML / OIDC)
PlannedEnterprise SSO for platform users.
Evidence and compliance5 of 5 in place
Hash-chained audit log
In placeEvery contact, disposition and payment writes to a Merkle-anchored audit log. A changed record breaks the chain and shows up.
Calling windows enforced at dispatch
In placeRBI Fair Practices, DPDP and TRAI constraints are gates in the dialer, not policy documents. A call outside the window is never placed.
Recording disclosure enforced
In placeThe disclosure is played by the engine on every call, not left to the agent.
DLT template binding
In placeSMS dispatches only on TRAI DLT-registered templates.
DRA-certified, police-verified people
In placeFor managed and hybrid engagements: IIBF DRA certification and a Police Clearance Certificate before anyone works an account.
Resilience2 of 4 in place
Backups with restore verification
In placeAutomated encrypted backups; restores are exercised on a schedule, not assumed.
Health monitoring and alerting
In placeBuilt-in ops console with host, container and job health; alerts to on-call by email and WhatsApp.
Published availability target
On requestA contractual uptime commitment in the master service agreement.
Independent penetration test
PlannedA third-party test of the platform, with a summary letter available under NDA.
Certifications
Held versus planned, without blur
Overclaiming here fails the first serious review, so we do not.
ISO/IEC 27001
PlannedControls are designed against it; the certification audit is on the roadmap and will be dated here when scheduled.
SOC 2 Type II
On requestUndertaken on enterprise demand, funded by the first contract that requires it.
DPDP Act readiness
In placeConsent, retention, erasure, grievance officer and breach-notification procedures in place; a readiness statement is available.
RBI outsourcing and DRA norms
In placeManaged-recovery staff hold IIBF DRA certification; conduct controls are audited internally every cycle.
Responsible disclosure
In placeA published process with acknowledgement and fix timelines and a safe harbour for good-faith research.
Sub-processors
Who touches data on our account
Telephony, messaging, AI and payment providers connect under each lender's own credentials and are the lender's processors. The list below is what runs on attpro's own account.
| Purpose | Provider | Location | Note |
|---|---|---|---|
| Application and database hosting | Indian-region cloud, named in the DPA | India | Compute, Postgres and Redis for the platform |
| Object storage | Wasabi (Mumbai region) | India | Recordings, exports and encrypted backups |
| Transactional email | SendGrid (Twilio) | United States | Platform notifications and website replies; no borrower content |
| Website lead delivery | Configured CRM or messaging webhook | India | Demo and contact form submissions only |
Under your own credentials
- Telephony
- Exotel
- SMS, WhatsApp, RCS
- Helo.ai and DLT-registered routes
- Speech and language models
- Sarvam, Deepgram, Google, Anthropic, OpenAI
- Payments
- Razorpay, Cashfree
- Alternate MetaData
- Contact-enrichment provider on the tenant's own credentials
You pay these vendors their price, revoke keys at the provider without asking us, and their data-processing terms are between you and them.
Documents
What we can hand over
Public documents are linked. Documents marked NDA are shared on request under a mutual non-disclosure agreement, usually within two working days.
- Public
Security and architecture overview
Tenant isolation, credential handling, evidence chain and residency, stated for a vendor questionnaire.
Open - Public
Privacy policy (DPDP)
What this website collects and how the platform processes borrower data on lender instructions.
Open - Under NDA
Data processing agreement
Processor terms for borrower data, sub-processor list and breach-notification timelines.
Request - Under NDA
Completed security questionnaire
Answers to standard BFSI vendor questionnaires (CAIQ-style), matching this page.
Request - Under NDA
Business continuity and backup policy
Backup schedule, restore-test cadence, recovery objectives.
Request - Under NDA
Penetration test summary
Summary letter from the independent test, once completed.
Request - Public
Grievance redressal process
Named officer, timelines and escalation routes for borrowers and lenders.
Open - Public
Responsible disclosure policy
How to report a vulnerability and what we commit to in return.
Open
Policies and changes
Dated, with a change log
Every legal document carries an effective date and a last-updated date. Material changes are recorded here.
Policies
Change log
- Legal documents restructured with numbered sections, effective dates and summaries; Trust Center published.
- Privacy policy, terms of service, grievance redressal and responsible disclosure first published.
Contact
Talk to the people who built it
Security questions and questionnaires
Send the questionnaire; we answer in writing and the answers match this page.
info@attpro.inReport a vulnerability
Acknowledged within 48 hours, safe harbour for good-faith research.
Responsible disclosureSend us the questionnaire.
The fastest way to evaluate a vendor's security posture is to make them fill in yours. We answer in writing, and the answers match this page.