Your documents
are safe with us.

Enterprise customers trust us with confidential decks, legal contracts, and financial reports. Here is exactly how your document is handled, end to end.

Where your document goes

Upload

TLS 1.3 in transit

Encrypted storage

AES-256 at rest

AI translation

OpenAI DPA, no training

Encrypted output

AES-256 at rest

Auto-deleted

30 days after job

Data in transit

All connections to Vernacia use TLS 1.3. Older TLS versions and plaintext HTTP are rejected at the load balancer. HSTS with a 1-year max-age is enforced on all origins.

Data at rest

All files and database records are encrypted with AES-256 at rest — files in object storage, metadata in PostgreSQL — with production infrastructure planned for the Mumbai, India region. Encryption keys are held in a dedicated key-management service, separate from the data they protect.

File lifecycle

Uploaded files and translated outputs are automatically deleted 30 days after job completion. Deleting your account triggers immediate deletion of all associated files within 24 hours.

AI processing

Documents are sent to OpenAI's API under their Data Processing Agreement. OpenAI does not use API-submitted data to train their models. We never send files to third parties beyond what is required to perform your translation.

Access controls

Short-lived JWT tokens (1-hour expiry). OAuth 2.0 via Google, GitHub, and Microsoft. MFA available on all accounts. API keys are hashed at rest and shown once. Role-based access control (RBAC) with least-privilege defaults.

Audit logging

Every action that touches a file — upload, queue, translate, download, delete — is written to an immutable audit log with user ID, timestamp, and IP address. Logs are retained for 90 days by default (configurable up to 24 months for Enterprise).

Compliance & certifications

Where we are today and where we are heading.

GDPR compliant

EU AI Act Art. 50 — compliant

India DPDP Act 2023

PCI DSS SAQ-A

SOC 2 Type II

ISO 27001

ISO 42001 (AI governance)

HIPAA

Status: Done

GDPR compliant

Data minimisation, data subject rights (access, correction, deletion, export), data-processing terms with all sub-processors, 72-hour breach notification, tamper-evident audit logs.

Status: Done

EU AI Act Art. 50 — compliant

Machine-readable AI-output disclosure embedded in all translated files (PPTX, DOCX, XLSX, PDF, HTML, EPUB). X-AI-Generated and X-AI-Disclosure headers on every download. August 2026 deadline met early.

Status: Done

India DPDP Act 2023

Consent capture, data principal rights, breach notification, and Records of Processing Activities implemented. DPDP Consent Manager integration in progress (November 2026 deadline).

Status: Done

PCI DSS SAQ-A

No card data handled or stored on Vernacia infrastructure. Payments are fully tokenized through Stripe (global) and Razorpay (India), keeping scope within SAQ-A.

Status: In progress

SOC 2 Type II — in progress

14 formal security policies approved v1.0. Evidence collection begins at production launch. Report available to Enterprise customers under NDA (expected Q1 2027).

Status: In progress

ISO 27001 — in progress

Statement of Applicability complete. 93 controls mapped across all Annex A domains. Stage 1 audit targeted Q3 2026.

Status: In progress

ISO 42001 (AI governance) — in progress

AI management system controls mapped. AI impact assessment and RoPA complete. Formal certification planned post-SOC 2.

Status: Roadmap

HIPAA — roadmap

HIPAA-aligned technical safeguards; BAA available on request as part of our Enterprise compliance roadmap. Not currently offered.

Responsible disclosure

If you discover a security vulnerability in Vernacia, please report it privately before disclosing it publicly. We commit to acknowledging reports within 48 hours and resolving confirmed vulnerabilities within 14 days.

Send vulnerability reports to [email protected]. Please include steps to reproduce, potential impact, and any proof-of-concept if available. We do not pursue legal action against researchers who follow responsible disclosure.

For general security questions or to request our security documentation (e.g. for vendor assessments), use the same address.

Trust confirmed? Start translating securely.

Every document on Vernacia is encrypted in transit and at rest, automatically retention-limited, and never used to train AI models. Try it with your own files.

Still have questions?

Our team is happy to walk you through our security controls, answer questionnaires, or arrange a call with a solutions engineer for enterprise evaluations.

Vernacia is a product of CloudServe Digital, a division of CloudServe Infotech (RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED).
CIN: U62091KA2025PTC210162 · GST: 29AAPCR1639E1Z3
#36, WeWork Prestige Central, Infantry Road,
Mahatma Gandhi Road, Bengaluru – 560001, Karnataka, India
Tel: +91-9110618988