Data protection & residency
We treat your data as the most sensitive part of any engagement. Data is encrypted in transit (TLS) and at rest, and we collect and retain only what a system genuinely needs. Where a jurisdiction requires it — for example EU personal data or regulated Indian financial data — we design for data residency so information stays within the required region, and we can disable cross-border replication at the infrastructure layer.
For generative and retrieval systems, we add AI-specific protections: PII detection and redaction before data reaches a model, controls over what is sent to third-party model providers, and the option to keep everything inside your own environment using private or self-hosted models.
Access control & identity
Access to any client system or data follows the principle of least privilege: people and services get only the access a task requires, and nothing more. Production access requires multi-factor authentication, is logged, and is reviewed on a regular cadence. When we build for you, AI agents and applications inherit the authorisation of the user they act for — an agent can never see or do more than the person using it.
Secure development lifecycle
Security is part of how we engineer, not a gate at the end. That means peer code review, dependency and vulnerability scanning, managed secrets (never hard-coded credentials), and separated environments for development, staging and production. Changes reach production through a controlled release process with the ability to roll back.
AI governance & responsible AI
The controls that make AI trustworthy are the same ones that get it through a security review. On every engagement we can apply:
- Grounding & citations — answers tied to retrieved sources, so claims are traceable rather than invented.
- Guardrails — input and output filtering for safety, policy and sensitive-data leakage.
- Automated evaluation — every release scored for grounding, accuracy and safety, with regressions blocked before they ship.
- Human-in-the-loop — approval gates for high-impact or irreversible actions.
- Audit trails — an immutable record of model and agent activity, so "why did the system do this?" always has an answer.
Deployment options
We meet your risk profile rather than forcing ours. The same architecture can run in:
- Your cloud — deployed into your AWS, Azure or GCP account, under your controls and billing.
- Private cloud / VPC — isolated networking, no public exposure of models or data.
- On-premise — inside your own data centre for maximum control.
- Air-gapped — fully offline private LLMs where no data may leave the environment at all.
Business continuity & incident response
Production systems are backed up, monitored, and covered by a defined incident-response process: detect, contain, communicate, remediate and review. If an incident affects your data or systems, we notify you promptly and work to the notification timelines your regulators require.
Sub-processors & vendors
Where we rely on third parties — cloud infrastructure, model providers, tooling — we choose established vendors and limit what data reaches them. For any engagement we can provide the specific list of sub-processors involved and their role, so your team can assess them as part of due diligence.
Intellectual property & clean-room development
We own the intellectual property in the platforms and engines behind our own products — including our code-intelligence and AI-governance graph engines. They are designed and implemented independently, on public, well-documented techniques (AST parsing, graph databases, GraphRAG, ABAC, attack-path analysis) — and do not incorporate any third party's proprietary code, prompts, models or confidential data.
For client work, ownership of deliverables is defined in the engagement contract. We never reuse one client's data or bespoke code for another, and our demonstrations and case studies are anonymized and stripped of client data. Everyone who contributes to our codebase does so under an IP-assignment agreement, so ownership is unambiguous.
- Independent design — clean-room development, documented from first principles and public sources.
- License hygiene — open-source and third-party dependencies tracked with their licenses; we maintain a software bill of materials (SBOM).
- Contributor assignment — written IP assignment from employees and contractors.
- On request — IP-assignment records, license inventory and a clean-room attestation for diligence.
Due diligence & data room
For investors, acquirers and enterprise procurement teams, we maintain a diligence pack available under NDA. It includes:
- Security controls & system-architecture documentation
- Sub-processor and third-party vendor list
- Open-source & third-party license inventory (SBOM)
- IP-assignment records & clean-room attestation
- Data-flow and data-residency diagrams
Request access via info@vithupro.in with the subject line "Diligence".
Certifications & standards
- ISO 9001:2015 — certified quality-management system.
- MSME registered and recognised under Startup India.
- Our information-security controls are structured around the ISO/IEC 27001 framework; formal certification is on our roadmap.
- We are structuring our controls toward SOC 2 (Type II); a formal audit is on our roadmap. We're glad to share our current control set in the meantime.
- For engagements with specific regulatory obligations — RBI cyber-security guidance, GDPR, India's DPDP Act, HIPAA — we map our controls to the relevant framework as part of scoping.
Reporting a security concern
If you believe you have found a security vulnerability in our website or systems, please email info@vithupro.in with the subject line "Security". We take reports seriously, will acknowledge them, and ask that you give us a reasonable opportunity to remediate before any public disclosure.