Compliance & security

Compliant. Secure. Sovereign.

Every commitment below is designed to survive audit, RTI and vigilance scrutiny, on infrastructure your department chooses.

Data Privacy
Designed for compliance with the Digital Personal Data Protection (DPDP) Act, 2023: consent capture, purpose limitation, data minimisation, and breach-notification workflows built into the platform.
Deployment Model
On-premise within department/State Data Centre or NIC infrastructure, private/Government Community Cloud, or hybrid, selected by the department, not fixed by the vendor.
Data Sovereignty
All data, backups and processing remain within Indian jurisdiction as required; no mandatory transfer outside government-approved infrastructure.
Information Security
ISO 27001:2013-certified information security management system; role-based access control, encryption in transit and at rest, and detailed activity logging.
Customisation
Workflows, forms, roles, approval hierarchies, reports and language/localisation are configured per department, not a one-size-fits-all product.
Auditability
Every workflow step, document action and bid event is logged for RTI, CAG/departmental audit and vigilance requirements.
Make in India
Product conceived, engineered and supported by an India-based team, aligned with the Government's preference for domestically developed software under public procurement guidelines.

Security by design

Secured at every layer

Role-based access control

File- and folder-level permissions mapped to designation and department hierarchy.

Encryption everywhere

Data encrypted in transit and at rest, with sealed, tamper-proof bid encryption in procurement.

Immutable audit trails

Every action, approval and comment timestamped and immutable for RTI and audit readiness.

ISO 27001:2013 ISMS

A certified information security management system governing how we build, deploy and support.

Deployment

Selected by the department, not fixed by the vendor

Pick the model that matches your policy and empanelment requirements.

01

On-premise

Inside your own data centre, State Data Centre or NIC infrastructure, fully within your perimeter.

02

Government Community Cloud

An empanelled private or Government Community Cloud, under Indian jurisdiction.

03

Hybrid

Sensitive workloads on-premise, the rest on sovereign cloud, per your department policy.

Next step

Ready to see it on your files?

Start with a requirement-mapping workshop and a pilot on a single wing or scheme. No decks, no obligation, no pitch.

  • Make in India
  • DPDP Act 2023
  • ISO 27001
  • On-Prem & Sovereign Cloud