Data controls
Models run where you say. Your data stays inside the boundary you draw. On-premise or air-gapped if that is what your policy requires. And a closed list of what we are certified for.
This is the overview; the security page covers the same ground in evaluator detail, every control written out. Read this page first and that one when you are building a file.
Your data stays yours, in India
Your perimeter
Deploy on-premise, on MeghRaj government cloud, on a private cloud or air-gapped.
Your data
Records, files and documents, in the store you run.
Westra products
Copilot, Juris, Nexus, Fulcrum, Tenure, Civis, Dossier, Lumen
The models
Models can run entirely inside your perimeter.
What crosses the boundary
- Replication outside India
- No. Data residency in India by default, with no replication outside the country.
- Your material in model training
- No. Nothing you enter is used for training.
- Your export, in open formats
- Yes. Full export of your data in open formats at any time. No lock-in.
Deployment options
Four shapes. All four keep the data in India and under your control; they differ in who owns the hardware and in what the system is allowed to reach.
Controls inside the boundary
- Role-based access control, single sign-on and multi-factor authentication.
- Encryption in transit and at rest, with customer-managed keys where required.
- Tamper-evident audit trails on every record and every file movement.
- Regular independent penetration testing and a documented incident response process.
- Compliance with the Digital Personal Data Protection Act, 2023 and adherence to the CERT-In directions.
What we are certified for
Westra holds ISO 27001, ISO 42001 and SOC 2. That is the complete list. If a certification is not named here we do not hold it, and we will say so in a tender response rather than leave it ambiguous.
The standard for an information security management system: how risk is assessed, how controls are chosen, and how the whole thing is reviewed.
The standard for an artificial intelligence management system: how AI is governed, risk-assessed, built and monitored, with impact assessment and human oversight.
An independent auditor's report on the controls that protect customer data, rather than a self-assessment or a questionnaire answer.
Regulatory compliance
- Digital Personal Data Protection Act, 2023
- Compliant. Westra is the Data Fiduciary for its own website and a Data Processor for personal data inside a customer's deployment, handling it only on that customer's instructions.
- CERT-In directions
- Adhered to. Clocks synchronised to Indian time sources, ICT system logs kept for a rolling 180 days within India, and reportable incidents notified within six hours of being noticed.
- Information Technology Act, 2000
- Applied as it bears on us: reasonable security practices under section 43A, and the electronic records and intermediary provisions where a deployment engages them.
You control your data
Full export of your data in open formats at any time. No lock-in.
Open formats means formats something other than Westra can read, without a tool only we hold. If taking your data out needs a project, a negotiation or a licence, it is not really yours.
Put this in front of your security team
Send their questions to hi@westra.dev, or send the technical compliance sheet from the tender. We will fill it in with the evidence we can produce and a plain no where we cannot.