Where your document goes
Upload
TLS 1.3 in transit
Encrypted storage
AES-256 at rest
AI translation
OpenAI DPA, no training
Encrypted output
AES-256 at rest
Auto-deleted
30 days after job
Data in transit
All connections to Vernacia use TLS 1.3. Older TLS versions and plaintext HTTP are rejected at the load balancer. HSTS with a 1-year max-age is enforced on all origins.
Data at rest
All files and database records are encrypted with AES-256 at rest — files in object storage, metadata in PostgreSQL — with production infrastructure planned for the Mumbai, India region. Encryption keys are held in a dedicated key-management service, separate from the data they protect.
File lifecycle
Uploaded files and translated outputs are automatically deleted 30 days after job completion. Deleting your account triggers immediate deletion of all associated files within 24 hours.
AI processing
Documents are sent to OpenAI's API under their Data Processing Agreement. OpenAI does not use API-submitted data to train their models. We never send files to third parties beyond what is required to perform your translation.
Access controls
Short-lived JWT tokens (1-hour expiry). OAuth 2.0 via Google, GitHub, and Microsoft. MFA available on all accounts. API keys are hashed at rest and shown once. Role-based access control (RBAC) with least-privilege defaults.
Audit logging
Every action that touches a file — upload, queue, translate, download, delete — is written to an immutable audit log with user ID, timestamp, and IP address. Logs are retained for 90 days by default (configurable up to 24 months for Enterprise).
Compliance & certifications
Where we are today and where we are heading.
GDPR compliant
EU AI Act Art. 50 — compliant
India DPDP Act 2023
PCI DSS SAQ-A
SOC 2 Type II
ISO 27001
ISO 42001 (AI governance)
HIPAA
GDPR compliant
Data minimisation, data subject rights (access, correction, deletion, export), data-processing terms with all sub-processors, 72-hour breach notification, tamper-evident audit logs.
EU AI Act Art. 50 — compliant
Machine-readable AI-output disclosure embedded in all translated files (PPTX, DOCX, XLSX, PDF, HTML, EPUB). X-AI-Generated and X-AI-Disclosure headers on every download. August 2026 deadline met early.
India DPDP Act 2023
Consent capture, data principal rights, breach notification, and Records of Processing Activities implemented. DPDP Consent Manager integration in progress (November 2026 deadline).
PCI DSS SAQ-A
No card data handled or stored on Vernacia infrastructure. Payments are fully tokenized through Stripe (global) and Razorpay (India), keeping scope within SAQ-A.
SOC 2 Type II — in progress
14 formal security policies approved v1.0. Evidence collection begins at production launch. Report available to Enterprise customers under NDA (expected Q1 2027).
ISO 27001 — in progress
Statement of Applicability complete. 93 controls mapped across all Annex A domains. Stage 1 audit targeted Q3 2026.
ISO 42001 (AI governance) — in progress
AI management system controls mapped. AI impact assessment and RoPA complete. Formal certification planned post-SOC 2.
HIPAA — roadmap
HIPAA-aligned technical safeguards; BAA available on request as part of our Enterprise compliance roadmap. Not currently offered.
Responsible disclosure
If you discover a security vulnerability in Vernacia, please report it privately before disclosing it publicly. We commit to acknowledging reports within 48 hours and resolving confirmed vulnerabilities within 14 days.
Send vulnerability reports to [email protected]. Please include steps to reproduce, potential impact, and any proof-of-concept if available. We do not pursue legal action against researchers who follow responsible disclosure.
For general security questions or to request our security documentation (e.g. for vendor assessments), use the same address.
Still have questions?
Our team is happy to walk you through our security controls, answer questionnaires, or arrange a call with a solutions engineer for enterprise evaluations.
Vernacia is a product of CloudServe Digital, a division of CloudServe Infotech (RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED).
CIN: U62091KA2025PTC210162 · GST: 29AAPCR1639E1Z3
#36, WeWork Prestige Central, Infantry Road,
Mahatma Gandhi Road, Bengaluru – 560001, Karnataka, India
Tel: +91-9110618988