Compliance built in — not bolted on

Security & compliance
from day one.

3 of 7 frameworks done. 14 formal security policies approved. We treat compliance as an engineering discipline, not a checkbox exercise.

Framework coverage

Every framework we track — current posture and what evidence is available.

GDPR

Compliant

EU AI Act Art. 50

Compliant

India DPDP 2023

Compliant

PCI DSS SAQ-A

In progress

SOC 2 Type II

In progress

ISO 27001

In progress

ISO 42001

In progress
GDPRGeneral Data Protection RegulationCompliant

Data minimisation, subject access rights (access, correction, deletion, export), data-processing terms with all sub-processors, 72-hour breach notification, tamper-evident audit logs.

DPA available on request

EU AI Act Art. 50EU AI Act — Transparency ObligationsCompliant

Machine-readable AI-output labeling embedded in all translated files. X-AI-Generated and X-AI-Disclosure HTTP headers on every download. August 2026 deadline met early.

Technical implementation available for review

India DPDP 2023Digital Personal Data Protection ActCompliant

Consent capture, data principal rights, breach notification (72 h), Records of Processing Activities, and data fiduciary designation all implemented. DPDP Consent Manager integration underway (November 2026 deadline).

RoPA available on request

PCI DSS SAQ-APayment Card Industry — Self-Assessment Questionnaire AIn progress

No card data is handled or stored on Vernacia infrastructure. Payments are fully tokenized through Stripe (global) and Razorpay (India), keeping scope within the simplest SAQ-A posture.

Self-assessment in progress

SOC 2 Type IIAICPA System and Organization Controls 2In progress

14 formal security policies approved v1.0. All technical controls implemented and in production. Evidence collection window opens at production launch. Report expected Q1 2027.

SOC 2 report under NDA (post-certification)

ISO 27001Information Security Management SystemIn progress

Statement of Applicability complete. All 93 controls mapped across every Annex A domain. Control catalog cross-referenced to SOC 2 and ISO 42001. Stage 1 audit targeted Q3 2026.

SoA and control documentation available on request

ISO 42001Artificial Intelligence Management SystemIn progress

AI management system controls mapped. AI impact assessment complete. Bias and quality controls documented in the AI Governance Policy. Certification planned post-SOC 2.

AI impact assessment available on request

Formal policy library

14 written, version-controlled, owner-approved policies covering every major compliance domain. Auditors require these alongside technical controls — we have both.

All v1.0 — approved 2026-06-16

Information Security Policy

ISO 27001 · SOC 2

v1.0 — 2026-06-16

Access Control Policy

SOC 2 CC6 · ISO A.5

v1.0 — 2026-06-16

Change Management Policy

SOC 2 CC8 · ISO A.8.32

v1.0 — 2026-06-16

Data Protection & Privacy Policy

GDPR · DPDP

v1.0 — 2026-06-16

Data Retention & Deletion Policy

GDPR · DPDP · SOC 2

v1.0 — 2026-06-16

Incident Response Plan

SOC 2 CC7 · ISO A.5.24–28 · GDPR/DPDP

v1.0 — 2026-06-16

Business Continuity & DR Plan

SOC 2 A1 · ISO A.5.29

v1.0 — 2026-06-16

Vendor & Sub-processor Management Policy

SOC 2 CC9 · ISO A.5.19 · GDPR Art.28

v1.0 — 2026-06-16

Risk Assessment & Treatment Policy

ISO 27001 Clause 6 · SOC 2 CC3

v1.0 — 2026-06-16

Acceptable Use Policy

SOC 2 · ISO A.5.10

v1.0 — 2026-06-16

AI Governance Policy

ISO 42001 · EU AI Act · NIST AI RMF

v1.0 — 2026-06-16

AI Acceptable Use & Transparency Policy

EU AI Act Art.50

v1.0 — 2026-06-16

Secure Development Policy

SOC 2 · ISO A.8.25–28

v1.0 — 2026-06-16

Cryptography Policy

SOC 2 · ISO A.8.24 · PCI DSS

v1.0 — 2026-06-16
Requesting policies: The full text of any policy is available to Enterprise customers and qualified auditors on request. Email [email protected] with your company name and which document you need.

Trust documents

Public documents your legal and procurement teams need.

Compliance confirmed? Start your first translation.

No procurement cycle required to try it — 7-day free trial, 25 page credits, no credit card.

Compliance team inquiry

Need to complete a vendor security questionnaire, request evidence for an audit, arrange a security review call, or execute a DPA? Email us — we respond within one business day.

Vernacia is a product of CloudServe Digital, a division of CloudServe Infotech (RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED).
CIN: U62091KA2025PTC210162 · GST: 29AAPCR1639E1Z3
#36, WeWork Prestige Central, Infantry Road,
Mahatma Gandhi Road, Bengaluru – 560001, Karnataka, India
Tel: +91-9110618988