What we can prove today, and what we cannot yet

Written for security, procurement, legal and risk teams. It states our certification status including what we do not hold, where your data can sit, who on our side can reach it, who owns the code, how quickly you hear when something goes wrong, and what happens on the day the engagement ends.

  • ISO/IEC 27001:2022 certification in progress, certification body appointed, target Q1 2027, January to March. We are not certified today and we do not claim to be
  • AWS or Azure in your preferred cloud, region and country, including in-country deployment, confirmed in writing before onboarding
  • Built for RBI-regulated entities in India and for UAE PDPL obligations, including notification within 2 hours of detection
  • Code, documentation and intellectual property assigned to you, no exit fee, nothing held back
Send us your security questionnaire

We return completed questionnaires within 48 hours, in your format. If your policy requires a certification we do not hold, we say so in the first reply rather than the fourth.

Trust and transparency at Accucia Softwares
730+ SYSTEMS SHIPPED
500+ CLIENTS WORLDWIDE
8 YEARS
25+ INDUSTRY VERTICALS

A vendor trust page is a single published statement of a supplier's certification status, data handling, hosting locations, regulatory commitments and contractual obligations, written so that a buyer's security review can be completed without booking a meeting.

Most suppliers answer these questions in a spreadsheet, once per buyer, and the answers drift apart over time. Publishing them fixes that, and it has a second effect that is more useful: anything published has to be true, because you can check it. Where our answer is weaker than you would like, it is still the answer you will get in your questionnaire.

The questionnaire arrives after the decision

The supplier is chosen and the date is set, and then a 200 line questionnaire lands on your desk. You are the only person being asked to slow things down, and the answers coming back are optimistic.

A badge is easy to display and hard to verify

A logo in a footer tells you nothing about the issuing body, the scope statement or the expiry date, and those three things are the whole of a certification claim. You write and ask, you wait, and the certificate covers a head office rather than the team holding your credentials.

Nobody will say where the data actually sits

Cloud hosted is not a location. Your regulator asks for the country, the sub-processors, the transfer mechanism and the route a support engineer takes to reach production. Those answers usually surface in week twelve, after signature.

Control Areas

The seven control areas we operate

Governance and accountability

Information security is owned at board level by our Founder and CEO and run day to day by a named information security lead. Our ISMS is built against the ISO/IEC 27001:2022 control set and carries a risk register, a Statement of Applicability, asset and supplier registers, and internal audits tracked to closure.

Data protection and intellectual property

Code, documentation, designs and deliverables are assigned to you on payment, and work is committed to your repositories wherever you hold them. No client's code or data is reused in another client's system, and no client data trains any model. Data is encrypted in transit and at rest.

Secure project environments

Development, staging and production are separated, and credentials are never shared between clients or environments. Secrets sit in a managed secrets store. Repositories are private by default, with branch protection and review before merge. Engineer devices are company managed, disk encrypted and patched.

Access control and authorisation

Access is granted per named engineer against a named role, least privilege by default, never through shared or generic accounts. Multi-factor authentication is enforced where supported. Joiner, mover and leaver changes are actioned the same working day.

Security testing

Code is peer reviewed before merge, static analysis and dependency vulnerability scanning run in the build pipeline, and findings are triaged by severity and tracked to closure before release. We support penetration testing commissioned by you or testers you appoint.

Incident response and continuity

We run a documented incident response procedure with defined severity levels, a named incident manager and a direct communications path to your nominated contact. Critical incidents are handled 24x7 with a response within 4 hours. Notification within 2 hours of detection where your data is affected.

Client assurance

We return security questionnaires in writing within 48 hours, in your format, with the gaps marked rather than papered over. Under NDA we share our Statement of Applicability, internal audit results, control evidence, policy set and Data Processing Agreement.

Reviewed by Mr. Sumeet Katariya, Founder and Chief Executive Officer, Accucia Softwares Pvt. Ltd.

Certification status

ISO/IEC 27001:2022 - certification in progress

We are not yet certified to ISO/IEC 27001:2022 and we do not claim to be. Our Information Security Management System has been built against the ISO/IEC 27001:2022 control set, a certification body has been appointed, and we are working to a target certification date of Q1 2027. We will publish the certificate, the certifying body and the scope statement on this page on the day it is issued.

Until then we will share our Statement of Applicability, internal audit results and control evidence with your security team under NDA, and we support client-led and regulator-led audits of our controls directly.

We hold no SOC 2 report of any type and we do not describe ourselves as SOC 2 aligned. If a SOC 2 report is a hard requirement in your policy, we do not meet it today.

CERT-In empanelment - not held

Accucia does not hold CERT-In empanelment, which is a designation for organisations that perform audits. The client commissions and pays for the empanelled audit. We build to the auditor's requirements and implement every finding until it closes.

ISO 9001 - not held, in progress

ISO 9001 is not held and is in progress.

Three words, used precisely here and never blurred:

Certification - audited and certified by an independent third party - today we apply it to nothing.

Alignment / built against the control set - our controls are mapped to a published standard but not audited.

Ready / designed to support - the obligation is yours to hold and our controls and contracts are built so that you can hold it.

Hosting and data residency

Your system runs on AWS or Azure, in the cloud, region and country you prefer, including in-country deployment where your regulator or your policy requires it. The choice is yours, confirmed in writing before onboarding and named in the contract.

Hosting and data residency options
Deployment option Where data is stored Cloud account holder How our engineers reach it What it suits
India in-country An Indian region of AWS or Azure Yours, or ours where you prefer From Pune, named and logged accounts RBI-regulated workloads and any client requiring Indian residency
UAE in-country A UAE region of AWS or Azure Yours, or ours where you prefer Remote access, named, logged, revocable accounts UAE health data, CBUAE-supervised systems, government-adjacent work
EU region An EU region of AWS or Azure Yours, or ours where you prefer Remote access, named, logged, revocable accounts Clients carrying an EU data protection obligation
US region A US region of AWS or Azure Yours, or ours where you prefer Remote access, named, logged, revocable accounts US clients and agency partners hosting in their own account
Your own tenant Your cloud account, your region, your billing Yours entirely Access you provision and can withdraw at any time Any buyer whose policy requires the vendor never hold the data

In every option, data stays in the region named in your contract and our engineers reach it under named, logged and revocable access rather than by taking a copy.

For RBI-regulated clients

If you are an NBFC, a bank, a payments company or any other entity supervised by the Reserve Bank of India, your outsourcing contract is built on the RBI outsourcing Directions issued in 2025 (RBI/DOR/2025-26/363, 28 November 2025). These are our positions against the clauses your legal team will send us.

Data storage in India only (paragraph 74)

For regulated workloads your data is stored and processed in India and does not leave India. This is stated separately from our flexible region offer on purpose.

Audit rights

You, your internal auditors, your external auditors and agents you appoint may audit us and our sub-contractors, and may obtain copies of audit reports and findings.

Supply chain information

We provide information on the supply chain behind your service, including sub-contractors and sub-processors and where each part is delivered from, on request.

Prior approval for sub-contractors

No sub-contractor touching your service or your data is appointed without your prior written approval.

Regulator access

We recognise the authority of the Reserve Bank of India, and persons authorised by it, to access documents, records, systems and premises relating to your engagement.

Incident notification within 2 hours (paragraph 61)

We notify your nominated contact within 2 hours of detecting a security incident. You must report unusual cyber incidents to the RBI within 6 hours, and our commitment ensures your clock isn't spent waiting on us.

Third-party certification (paragraph 79)

The Directions permit reliance on a globally recognised third-party certification in lieu of your own audit. We do not hold one today, so that route is not open yet. Until then: audit rights in the contract, evidence under NDA, no charge for your auditors' time.

For UAE clients

UAE PDPL, Federal Decree-Law No. 45 of 2021

Where you are the controller and we process personal data on your instructions, we work to the processor obligations that law sets: process only on documented instruction, apply appropriate measures, support data subject requests, notify of a breach without delay.

Transfers to India, Article 23

Where personal data moves from the UAE to our team in India, the transfer runs on the contractual safeguards Article 23 permits. Our GDPR-style data transfer agreement is available on request.

Health data stays in the UAE

Under Federal Law No. 2 of 2019, health data generated in the UAE cannot be stored, processed or transferred outside without specific regulatory approval. Health deployments run in-country, and we say so during scoping.

CBUAE-regulated clients

For clients supervised by the Central Bank of the UAE, the Master System of Record is maintained within the UAE and customer data is not shared outside without Central Bank approval.

Invoicing

Our invoices are raised from India. UAE VAT is accounted for by you under the reverse charge mechanism (Article 48), and UAE withholding tax on cross-border service payments is currently 0%.

Sub-processors

We do not publish a general sub-processor list today, and we would rather say that than publish one that is out of date. Sub-processor information is provided on request and maintained per engagement, because the parties that can touch your data depend on what we build and where it runs. Before onboarding you receive the list for your engagement in writing: who they are, what they do, what data they can reach and the country each processes in.

We give notice before adding a sub-processor. If you object we look for an alternative, and where there is none we tell you plainly. For RBI-regulated clients no sub-contractor is appointed without your prior written approval.

Sub-processor list last reviewed on 16 August 2026. Table publishes here once every row is populated and verified. To be notified of changes, write to us and we will add you to the notification list.

Support and incident response

Critical incidents are covered 24x7, with a response within 4 hours. Where an incident affects the security of your data, notification is within 2 hours of detection, and that clock runs independently of the support window.

Support severity levels and response commitments
Severity What it covers Coverage window Our commitment
Critical Production down, or business-critical function unavailable with no workaround 24x7, every day Response within 4 hours of the incident being raised or detected
High A major function impaired, or critical function usable only via workaround Mon-Sat, 9:30am-6:30pm IST Response in the next support window, resolution target per SOW
Medium A non-critical function impaired, limited operational impact Mon-Sat, 9:30am-6:30pm IST Response in the next support window, scheduled into the delivery plan
Low Cosmetic defects, questions and change requests Mon-Sat, 9:30am-6:30pm IST Response in the next support window, prioritised with your product owner
Security incident affecting your data Any confirmed or suspected compromise of confidentiality, integrity or availability 24x7, every day, independent of support window Written notification within 2 hours of detection, named incident manager, written post-incident review

Severity is agreed with you at onboarding and recorded in the Statement of Work, along with your nominated contact for security notifications.

Frequently asked questions

Our target certification date for ISO/IEC 27001:2022 is Q1 2027. A certification body has been appointed and our ISMS has been built against the control set. We will not describe ourselves as certified before the certificate exists.

No. We hold no SOC 2 report, no Type I and no Type II. If a SOC 2 report is a hard requirement in your policy, we do not meet it today and we will say so in our first reply. What we offer instead is contractual audit rights and control evidence under NDA.

In the cloud, region and country you choose. We deploy on AWS or Azure, including in-country deployment where required, confirmed in writing before onboarding and named in the contract.

Yes. For clients requiring Indian data residency, including RBI-regulated entities, your data is stored and processed in an Indian region and does not leave India, written into the contract before onboarding.

Yes. We deploy into a UAE region where you require in-country residency. UAE health data runs in-country by default. For CBUAE-regulated clients, the Master System of Record is maintained within the UAE.

Only named engineers assigned to your engagement, against named roles, at least privilege, never through shared accounts. Joiner, mover and leaver changes are actioned the same working day.

You do. All code, documentation, designs and deliverables are assigned to you on payment, written into every contract. We do not reuse one client's code in another client's system.

Our access is revoked on the last day. You receive repository access, environment documentation and a written handover. Client data is deleted on the schedule stated in your contract, confirmed in writing.

Yes. Cloud providers and model providers are sub-processors. We do not publish a general list; you receive the list for your engagement in writing before onboarding, with notice before any addition.

Within 48 hours, in your own format, in writing. Answers that are no come back as no, with the gap marked, rather than a phrase engineered to be misread.

We notify your nominated contact within 2 hours of detection, in writing, with what we know at that point. A named incident manager runs the response and we complete a written post-incident review.

Within 2 hours of detection. That commitment sits outside the support window and applies at any hour, so regulated clients can meet their own reporting clocks including the RBI's 6-hour requirement.

Yes. You, your internal and external auditors, and agents you appoint may audit us and our sub-contractors. We provide a named contact and release control evidence under NDA at no charge.

Yes. We recognise the authority of the Reserve Bank of India, and persons authorised by it, to access documents, records, systems and premises relating to your engagement.

Yes. We sign client DPAs, and provide our own where preferred. For UAE-to-India transfers we provide a GDPR-style data transfer agreement under Article 23.

Where our answer is weaker than you'd like - such as ISO certification or SOC 2 - it is stated plainly on this page, the same answer you will get in your questionnaire.

Send us your security questionnaire

We return completed questionnaires within 48 hours, in your format. If your policy requires a certification we do not hold, we say so in the first reply.

Send us your security questionnaire
Chat With Us