Skip to content

Security

Where your data sits, who can reach it, what we are certified for, and what we do not claim.

This page is written for the person who has to decide whether Westra can be trusted with a system and then defend that decision in a file. Everything on it is specific enough to check.

We do not publish client names, uptime figures, case studies or awards on this site. If you need something evidenced for an evaluation, ask for it in writing and we will tell you plainly whether we have it.

Your data stays yours, in India

Sovereignty is a deployment decision rather than a setting. It is taken before the first install and it belongs in the contract.
  • Deploy on-premise, on MeghRaj government cloud, on a private cloud or air-gapped.
  • Data residency in India by default, with no replication outside the country.
  • Models can run entirely inside your perimeter. Nothing you enter is used for training.
  • Full export of your data in open formats at any time. No lock-in.

Deployment options

Four ways to run a Westra system. All four keep the data in India and under your control; the difference is who holds the metal.
On-premise
Installed on servers you own, in your own building. You hold the hardware, network and backups; we supply the build, the hardening and the runbook.
Private cloud
A dedicated tenancy in an Indian region of your cloud provider, isolated from other customers and operated by your team or by ours under contract.
MeghRaj government cloud
Your department's MeghRaj tenancy on MeitY-empanelled infrastructure, with the models inside it. Westra operates the application; the cloud contract stays yours.
Air-gapped
No route to the internet. The models run inside the enclave, updates arrive as signed offline bundles, and external India Stack services need a sanctioned gateway.

Built to be audited

The controls an evaluator asks about, and the certifications we actually hold.

Certifications

Westra holds ISO 27001, ISO 42001 and SOC 2. That is the complete list. If a certification is not named here we do not hold it, and we will say so in a tender response rather than leave it ambiguous.

ISO 27001
The standard for an information security management system: how risk is assessed, how controls are chosen, and how the whole thing is reviewed.
ISO 42001
The standard for an artificial intelligence management system: how AI is governed, risk-assessed, built and monitored, with impact assessment and human oversight.
SOC 2
An independent auditor's report on the controls that protect customer data, rather than a self-assessment or a questionnaire answer.

Regulatory compliance

Separate from the list above, and deliberately so: these are laws and directions we comply with. None of them is a certification, and a vendor who offers you one is telling you something that does not exist.

Digital Personal Data Protection Act, 2023
Compliant. Westra is the Data Fiduciary for its own website and a Data Processor for personal data inside a customer's deployment, handling it only on that customer's instructions.
CERT-In directions
Adhered to. Clocks synchronised to Indian time sources, ICT system logs kept for a rolling 180 days within India, and reportable incidents notified within six hours of being noticed.
Information Technology Act, 2000
Applied as it bears on us: reasonable security practices under section 43A, and the electronic records and intermediary provisions where a deployment engages them.

Controls

  • Role-based access control, single sign-on and multi-factor authentication.
  • Encryption in transit and at rest, with customer-managed keys where required.
  • Tamper-evident audit trails on every record and every file movement.
  • Regular independent penetration testing and a documented incident response process.
  • Compliance with the Digital Personal Data Protection Act, 2023 and adherence to the CERT-In directions.

Accessible by design

Public systems get used on old phones, slow connections and screen readers. Accessibility is a scored requirement in most government tenders, and it is a requirement here.
  • WCAG 2.1 AA across every product and this website.
  • Guidelines for Indian Government Websites (GIGW) compliance for public-facing portals.
  • Keyboard operable, screen-reader tested, and usable on low-end Android devices and slow networks.

Native to the India Stack

Ten services the products speak natively. Each integration runs under the approvals and credentials the deploying organisation holds: we build and operate the connection, the entitlement to use the service stays with you.
Aadhaar
e-KYC and authentication for citizens and staff
DigiLocker
Pull in verified documents and issue your own
eSign
Legally valid digital signatures
Bhashini
22 scheduled languages, text and voice
UPI
Collection of fees and payments from citizens
PFMS
Public financial management integration
GeM
Procurement-compatible workflows
CPGRAMS
Grievance interoperability
MeghRaj
Government cloud deployment
e-Office
File and record interoperability

Send us the technical criteria

If you are preparing an evaluation or a bid, send the security and compliance questions to hi@westra.dev. We will answer them line by line, including the ones where the answer is no.