Security
Where your data sits, who can reach it, what we are certified for, and what we do not claim.
This page is written for the person who has to decide whether Westra can be trusted with a system and then defend that decision in a file. Everything on it is specific enough to check.
We do not publish client names, uptime figures, case studies or awards on this site. If you need something evidenced for an evaluation, ask for it in writing and we will tell you plainly whether we have it.
Your data stays yours, in India
- Deploy on-premise, on MeghRaj government cloud, on a private cloud or air-gapped.
- Data residency in India by default, with no replication outside the country.
- Models can run entirely inside your perimeter. Nothing you enter is used for training.
- Full export of your data in open formats at any time. No lock-in.
Deployment options
- On-premise
- Installed on servers you own, in your own building. You hold the hardware, network and backups; we supply the build, the hardening and the runbook.
- Private cloud
- A dedicated tenancy in an Indian region of your cloud provider, isolated from other customers and operated by your team or by ours under contract.
- MeghRaj government cloud
- Your department's MeghRaj tenancy on MeitY-empanelled infrastructure, with the models inside it. Westra operates the application; the cloud contract stays yours.
- Air-gapped
- No route to the internet. The models run inside the enclave, updates arrive as signed offline bundles, and external India Stack services need a sanctioned gateway.
Built to be audited
Certifications
Westra holds ISO 27001, ISO 42001 and SOC 2. That is the complete list. If a certification is not named here we do not hold it, and we will say so in a tender response rather than leave it ambiguous.
- ISO 27001
- The standard for an information security management system: how risk is assessed, how controls are chosen, and how the whole thing is reviewed.
- ISO 42001
- The standard for an artificial intelligence management system: how AI is governed, risk-assessed, built and monitored, with impact assessment and human oversight.
- SOC 2
- An independent auditor's report on the controls that protect customer data, rather than a self-assessment or a questionnaire answer.
Regulatory compliance
Separate from the list above, and deliberately so: these are laws and directions we comply with. None of them is a certification, and a vendor who offers you one is telling you something that does not exist.
- Digital Personal Data Protection Act, 2023
- Compliant. Westra is the Data Fiduciary for its own website and a Data Processor for personal data inside a customer's deployment, handling it only on that customer's instructions.
- CERT-In directions
- Adhered to. Clocks synchronised to Indian time sources, ICT system logs kept for a rolling 180 days within India, and reportable incidents notified within six hours of being noticed.
- Information Technology Act, 2000
- Applied as it bears on us: reasonable security practices under section 43A, and the electronic records and intermediary provisions where a deployment engages them.
Controls
- Role-based access control, single sign-on and multi-factor authentication.
- Encryption in transit and at rest, with customer-managed keys where required.
- Tamper-evident audit trails on every record and every file movement.
- Regular independent penetration testing and a documented incident response process.
- Compliance with the Digital Personal Data Protection Act, 2023 and adherence to the CERT-In directions.
Accessible by design
- WCAG 2.1 AA across every product and this website.
- Guidelines for Indian Government Websites (GIGW) compliance for public-facing portals.
- Keyboard operable, screen-reader tested, and usable on low-end Android devices and slow networks.
Native to the India Stack
- Aadhaar
- e-KYC and authentication for citizens and staff
- DigiLocker
- Pull in verified documents and issue your own
- eSign
- Legally valid digital signatures
- Bhashini
- 22 scheduled languages, text and voice
- UPI
- Collection of fees and payments from citizens
- PFMS
- Public financial management integration
- GeM
- Procurement-compatible workflows
- CPGRAMS
- Grievance interoperability
- MeghRaj
- Government cloud deployment
- e-Office
- File and record interoperability
Send us the technical criteria
If you are preparing an evaluation or a bid, send the security and compliance questions to hi@westra.dev. We will answer them line by line, including the ones where the answer is no.
