Security & Trust

A privacy platform built to the standard it asks of you.

Binary AIQ is engineered for regulated environments. Every action is auditable, every write is scoped to the tenant and every export leaves a receipt.

Controls

Enterprise controls, stated as facts.

Encryption at rest
AES-256, per-tenant key scoping, KMS-managed
Encryption in transit
TLS 1.3 with strong cipher preference; HSTS enforced
Authentication
Email/password, SSO (SAML 2.0, OIDC), SCIM provisioning
Authorisation
Role-based, scope-limited to org, legal entity, business unit or department
Audit trail
Append-only per entity; actor, IP, session and impersonation context recorded
Backups
Point-in-time recovery for 30 days; encrypted backups replicated across zones
Vulnerability management
Continuous dependency scanning; independent penetration test annually
Business continuity
Multi-AZ primary with failover; documented recovery targets
Sub-processors
Enumerated in the DPA and reviewed on renewal
Data residency
Primary IN-South (Mumbai). Optional EU (Frankfurt) or US (N. Virginia)
Deployment
Managed multi-tenant · single-tenant · private cloud on customer VPC
Programme alignment
DPDP Act 2023 · ISO 27001 (controls mapped) · SOC 2 Type II in progress
Data handling

What Binary AIQ does — and does not — do with your data.

We do
  • Store the records you create — processing activities, notices, consent, DSR, evidence — under your tenant.
  • Log every write with actor, timestamp and IP for audit purposes.
  • Encrypt data at rest and in transit and enforce scope-limited access.
  • Enumerate every sub-processor in the Data Processing Addendum.
We do not
  • Sell or share tenant data with third parties.
  • Train shared models on tenant content.
  • Move data out of the elected residency zone without written instruction.
  • Grant Binary staff access to tenant records without a support case and audited approval.
Deployment options

Three ways to run Binary AIQ.

Managed multi-tenant

Fastest to onboard. Shared infrastructure with per-tenant isolation, keys and audit.

Single-tenant managed

Dedicated instance operated by Binary. Independent database, keys and upgrade window.

Private cloud

Deployed to your VPC on AWS, Azure or GCP. You hold the keys and the network boundary.