Enterprise Security & Infrastructure Safeguards
At AUDIX GRC, security is not an overlay—it is our core software architecture. Our system utilizes zero-trust frameworks to audit technical controls continuously without exposing sensitive corporate databases.
1. Cryptographic encryption standards
All database transactions, compliance artifacts, and evidence files are subject to enterprise-grade encryption.
- Data-at-rest: Encrypted using advanced symmetric AES-256 keys managed through secure Key Management Services (KMS) with automatic envelope rotation.
- Data-in-transit: Secured with forced HTTPS TLS 1.3 encryption alongside robust HSTS policies. Weak cipher suites are disabled entirely at our API gateway.
2. Identity & access controls
We enforce zero-trust identity safeguards across all product lines:
- MFA enforcement: Multi-factor authentication is mandatory for all administrative access.
- Single sign-on (SSO): Full integration with SAML 2.0 and OIDC (Google Workspace, Microsoft Entra ID) with automated just-in-time de-provisioning.
- Role-based access control (RBAC): Granular permissions restricting auditor read states, compliance manager editing, and telemetry control configurations.
3. Infrastructure security
Our server containers and evidence engines run on SOC 2 and ISO 27001 certified Google Cloud Platform (GCP) datacenters.
- Data sovereignty: Databases are housed exclusively in regional Indian zones (Mumbai) to satisfy local regulator storage requirements.
- Disaster recovery: Secure hourly write-ahead log backups and redundant cloud clustering ensure rapid business continuity.
- Network isolation: Micro-segmentation with VPC network structures, secure bastion host configurations, and automatic DDoS protection layers.
4. Safeguards & privacy-by-design
We operate under a strict policy of minimal evidence ingestion. Our cloud compliance agents scan your system metadata but never clone, scrape, or read underlying database contents. All scans are non-intrusive and execute via read-only cloud APIs—no endpoint agents on production workloads.
5. Incident management & response SLA
We maintain active incident response protocols aligned with CERT-In reporting guidelines:
- Detection: Automated cloud container logging and security alert telemetry monitor active threats around the clock.
- Notification: In the event of a critical security threat, impacted corporate contacts will be notified within 6 hours of detection.
- Reporting: All incidents are officially filed with the Indian Computer Emergency Response Team (CERT-In) as required by local cyber regulations.
Certification status
AUDIX runs on Google Cloud Platform, which maintains its own independent attestations. AUDIX is not yet independently SOC 2 Type II or ISO 27001 certified—formal third-party certification is on the roadmap.
Security contact
Report vulnerabilities: security@audixgrc.com. See responsible disclosure for full policy and response timelines.
Related: privacy notice, terms, contact, platform.