Skip to content
attpro
Book a demo

Trust Center

Everything a vendor review will ask, in one place

Security posture, certifications held and planned, where data lives, who processes it, and the documents we can hand over. Every line is a property of the running system or a document you can request; where something is not yet true, it says so.

Posture · 19 controlsas at 29 Aug 2026

16 in place · 2 planned · 1 on requestnothing overclaimed

Security posture: 16 of 19 controls in place, 2 planned, 1 on request; certifications: ISO/IEC 27001 Planned, SOC 2 Type II On request, DPDP Act readiness In place, RBI outsourcing and DRA norms In place, Responsible disclosure In place.
On this page

At a glance

Four properties, stated first

Data in India

Application, database and storage in Indian regions.

Encrypted everywhere

TLS in transit; databases, recordings and backups at rest.

Isolated per tenant

One database schema per lender; nothing shared by row filter.

Evidence you can verify

Hash-chained audit log with a Merkle anchor on every action.

16 controls in place · 2 planned · 1 available on request. Last reviewed .

Controls

What is in place, what is planned

Grouped the way a questionnaire groups them. Planned means designed and scheduled, not aspirational.

Data protection5 of 5 in place
  • Data residency in India

    In place

    Application, database and object storage run in Indian regions. No borrower record leaves India in normal operation.

  • Encryption in transit and at rest

    In place

    TLS 1.2+ on every connection; databases, backups, recordings and exports encrypted at rest.

  • Envelope-encrypted secrets

    In place

    Provider credentials are encrypted with per-tenant data keys under a master key; never logged, never shown back in full.

  • PII redaction on transcripts

    In place

    Call transcripts carry PII redaction before they are stored for QA and analytics.

  • Retention, erasure and legal hold

    In place

    Recordings and records live on schedules the lender sets; DPDP erasure and legal hold run through the same audited lifecycle.

Isolation and access4 of 5 in place
  • Schema-per-tenant isolation

    In place

    Each lender's data lives in its own database schema. Another tenant's book is not addressable from your session.

  • Role-based access, tenant-editable

    In place

    A permission matrix per tenant; admins control which role can see or do what.

  • Multi-factor authentication

    In place

    TOTP second factor for platform users; enforced for administrator roles.

  • Audited support access

    In place

    Support enters a tenant only through time-boxed, reason-required impersonation that writes to an audit feed the tenant can read.

  • Single sign-on (SAML / OIDC)

    Planned

    Enterprise SSO for platform users.

Evidence and compliance5 of 5 in place
  • Hash-chained audit log

    In place

    Every contact, disposition and payment writes to a Merkle-anchored audit log. A changed record breaks the chain and shows up.

  • Calling windows enforced at dispatch

    In place

    RBI Fair Practices, DPDP and TRAI constraints are gates in the dialer, not policy documents. A call outside the window is never placed.

  • Recording disclosure enforced

    In place

    The disclosure is played by the engine on every call, not left to the agent.

  • DLT template binding

    In place

    SMS dispatches only on TRAI DLT-registered templates.

  • DRA-certified, police-verified people

    In place

    For managed and hybrid engagements: IIBF DRA certification and a Police Clearance Certificate before anyone works an account.

Resilience2 of 4 in place
  • Backups with restore verification

    In place

    Automated encrypted backups; restores are exercised on a schedule, not assumed.

  • Health monitoring and alerting

    In place

    Built-in ops console with host, container and job health; alerts to on-call by email and WhatsApp.

  • Published availability target

    On request

    A contractual uptime commitment in the master service agreement.

  • Independent penetration test

    Planned

    A third-party test of the platform, with a summary letter available under NDA.

Certifications

Held versus planned, without blur

Overclaiming here fails the first serious review, so we do not.

ISO/IEC 27001

Planned

Controls are designed against it; the certification audit is on the roadmap and will be dated here when scheduled.

SOC 2 Type II

On request

Undertaken on enterprise demand, funded by the first contract that requires it.

DPDP Act readiness

In place

Consent, retention, erasure, grievance officer and breach-notification procedures in place; a readiness statement is available.

RBI outsourcing and DRA norms

In place

Managed-recovery staff hold IIBF DRA certification; conduct controls are audited internally every cycle.

Responsible disclosure

In place

A published process with acknowledgement and fix timelines and a safe harbour for good-faith research.

Sub-processors

Who touches data on our account

Telephony, messaging, AI and payment providers connect under each lender's own credentials and are the lender's processors. The list below is what runs on attpro's own account.

PurposeProviderLocationNote
Application and database hostingIndian-region cloud, named in the DPAIndiaCompute, Postgres and Redis for the platform
Object storageWasabi (Mumbai region)IndiaRecordings, exports and encrypted backups
Transactional emailSendGrid (Twilio)United StatesPlatform notifications and website replies; no borrower content
Website lead deliveryConfigured CRM or messaging webhookIndiaDemo and contact form submissions only

Under your own credentials

Telephony
Exotel
SMS, WhatsApp, RCS
Helo.ai and DLT-registered routes
Speech and language models
Sarvam, Deepgram, Google, Anthropic, OpenAI
Payments
Razorpay, Cashfree
Alternate MetaData
Contact-enrichment provider on the tenant's own credentials

You pay these vendors their price, revoke keys at the provider without asking us, and their data-processing terms are between you and them.

Policies and changes

Dated, with a change log

Every legal document carries an effective date and a last-updated date. Material changes are recorded here.

Change log

  1. Legal documents restructured with numbered sections, effective dates and summaries; Trust Center published.
  2. Privacy policy, terms of service, grievance redressal and responsible disclosure first published.

Contact

Talk to the people who built it

Security questions and questionnaires

Send the questionnaire; we answer in writing and the answers match this page.

info@attpro.in

Report a vulnerability

Acknowledged within 48 hours, safe harbour for good-faith research.

Responsible disclosure

Send us the questionnaire.

The fastest way to evaluate a vendor's security posture is to make them fill in yours. We answer in writing, and the answers match this page.