Skip to content
Trust Center

How Varcio handles your data

Your data is stored and processed in AWS ap-south-1 (Mumbai, India), encrypted at rest and in transit. Nothing here is called certified: SOC 2 Type II is readiness programme, ISO 27001 is not started.

Every entry is checked against the running service. Enforced figures are read live, and the rest was last reviewed on 3 October 2026.

One file, no scripts, works offline. Opens in a new tab for printing.

At a glance

Hosting region
AWS ap-south-1 (Mumbai, India)
Encryption at rest
AES-256
Encryption in transit
TLS 1.2 or later
Uptime commitment
99.9% monthly uptime
Paid plans, service credits on request
SOC 2 Type II
Readiness programme
Sub-processors
8 listed
Plus integrations you turn on

Data residency and cross-border transfer

Customer data is stored and processed in AWS ap-south-1 (Mumbai, India), except AI inference, which runs on AWS Bedrock in us-east-1 (United States) for now. Sub-processors outside India are listed below with their regions. India's DPDP Act 2023 allows transfer abroad unless the Government restricts a named country under Section 16(1); no country has been restricted. The Act's core duties, including its transfer rules, take effect on 13 May 2027.

Primary region
AWS ap-south-1 (Mumbai, India)
Application, database, cache, object storage and encryption keys.
Database
Amazon RDS PostgreSQL, single-AZ
Encrypted at rest; automated backups with point-in-time recovery.
Backups
7-day point-in-time recovery
Retained in-region. Deleted data can remain in backups for up to 7 days.
Encryption at rest
AES-256
The database and object storage are encrypted with a customer-managed AWS KMS key in Mumbai, and the cache is encrypted at rest. Credentials and integration secrets are additionally wrapped per record with the same key (envelope encryption).
Encryption in transit
TLS 1.2 or later
TLS 1.0 and 1.1 are refused. HSTS is sent on every public hostname. The link to the cache is TLS-encrypted too.
Tenant isolation
Workspace-scoped at query level
Enforced in storage and query paths, not only in the UI. The only cross-workspace reads are the aggregate FinOps-score percentile (at least five peers) and the opt-in benchmark network.

Encryption keys

Mode
Envelope encryption with per-record data keys
Key wrapping
Customer-managed AWS KMS key (ap-south-1) wraps the data keys for credentials and integration secrets
Database and object storage
Encrypted with the same customer-managed AWS KMS key (ap-south-1)

India: DPDP Act 2023

  • The Act imposes no general data-localisation duty on ordinary data fiduciaries. Two provisions can require India residency: Rule 13(4), for Significant Data Fiduciaries and only for data the Government specifies (no list or designation has been published), and Section 16(2), which preserves stricter sector rules.
  • RBI's 2018 payment-data circular applies to authorised payment systems and listed banks, and reaches their vendors through them. This platform stores no card, bank-account or payment-credential data; Stripe and Razorpay hold it.
  • Customers regulated by SEBI, or buying under government cloud-procurement rules, can be required to use India-resident, MeitY-empanelled hosting; banks, NBFCs and insurers usually require a data-location clause by contract. Hosting in Mumbai meets an India-residency requirement; whether a given hosting provider is MeitY-empanelled is a separate procurement check that depends on the buyer's rules.
  • There is no EU data residency option today, and customers cannot choose a region. Every customer is served from Mumbai, India; AI inference moves back to Mumbai once AWS raises the Bedrock capacity there.
Position statement for security review, not legal advice. Reviewed when hosting changes or a restricted-country list, a Rule 15 order or a Rule 13(4) list is published.

Security controls

Controls that exist in the product today. Where one depends on the plan, it says so.

Identity and access

Identity and access
ControlHow it works
Single sign-onSAML 2.0 and OIDC on the Enterprise plan. Password sign-in can be blocked when SSO is enforced, with a break-glass exception.
SCIM provisioningSCIM 2.0 Users and Groups with explicit group-to-role mapping, on the Enterprise plan.
Multi-factor authenticationTOTP with recovery codes, and WebAuthn passkeys. An organization can require MFA: members are blocked until they enrol, and personal API keys are refused until their owner has enrolled.
Re-authenticationSSO configuration, network policy, session revocation and organization closure need a recent sign-in confirmation.
IP allowlistAn organization allowlist, enforced on sessions, API keys and sign-in (not on SCIM).
RolesAdmin and member roles on every plan. Custom scoped roles and business-unit row scopes on the Enterprise plan, enforced on every cost query.
SessionsEach session can be revoked, or all of them at once.

Logging and monitoring

Logging and monitoring
ControlHow it works
Audit logActor, action, target and timestamp for administrative actions, hash-chained per workspace so tampering is detectable, with a verify endpoint.
Audit exportCSV or JSON, up to 20,000 rows per export, within your plan's retention window. Streaming to a SIEM is not yet available.

Change management

Change management
ControlHow it works
Production changeReviewed pull requests; CI must pass before merge; migrations are reviewed for backward compatibility; schema, auth and execution-path changes need a rollback plan.

How a cloud connection is handled

  1. Encrypt on ingest

    Credentials and integration secrets are encrypted before they are persisted.

  2. Validate read plane

    Provider read access is verified before any telemetry or compliance processing runs.

  3. Gate write plane

    Write actions stay blocked until permissions and approval requirements are satisfied.

  4. Audit and retain

    Sensitive operations are logged, and audit entries are kept for your plan's retention window.

Incident response and vulnerability reports

Incident severity model
SeverityMeaning
SEV-1Multi-tenant outage, active security incident, or confirmed data exposure.
SEV-2Major degradation, failed execution controls, or sustained customer impact.
SEV-3Localized defect with an available workaround.
  • Severity is triaged within 15 minutes.
  • First public update within 30 minutes for SEV-1 and SEV-2.
  • Updates every 30 minutes until the incident is stable.
  • The closure update states the root cause, the remediation and the prevention actions.
  • A postmortem is completed within 5 business days for SEV-1 and SEV-2.

Personal-data breaches

A separate Personal Data Breach Response Procedure covers breaches of personal data. We report reportable incidents to India's CERT-In within six hours of noticing them; we notify affected customers without undue delay and within 48 hours at the latest (our internal target is 24 hours); and where we are the data fiduciary we notify the Data Protection Board and affected people as the DPDP Rules require from 13 May 2027. The procedure is shared under NDA on request.

Report a vulnerability to the security contact with reproduction steps, impact and the affected component. We acknowledge within 1 business day and triage severity within 3 business days. Report a vulnerability. Security research is authorized when performed in good faith and without data exfiltration, service disruption or privacy violations.

Data lifecycle and retention

How long each kind of data is kept, and what happens to it when you leave.

Audit log retention by plan
PlanAudit log you can read and exportNot deleted before
ExplorerNot included1 year
Pro90 days1 year
Business1 year1 year
Enterprise3 years3 years

Documented figures, reviewed 3 October 2026. Checking them against the running service.

Retention by data class
Data classRetention
Report exportsExpire after 7 days
Ended sign-in sessionsPruned after 2 days, when the person next opens their sessions, for sign-in security
Recognised devicesPruned after 180 days, at the person's next sign-in, for sign-in security
Event outbox and delivery telemetry90 days
Database backups7-day point-in-time recovery. Deleted data can remain in backups for up to 7 days.
Uploaded files (support attachments, contract documents)Deleted with the organization. Earlier file versions expire from object storage within 7 days.
Invoices, payments and partner ledgersKept as accounting records. The link to the organization is removed when it is deleted.
Incident records and postmortems24 months. This is a process commitment, not an automated deletion.

Closing an organization

  1. Request

    An organization administrator types the organization name, gives a reason and re-authenticates. Every administrator is emailed.

  2. Export window

    Nothing is deleted for 30 days and any administrator can cancel. Billing stops: the subscription does not renew while the request stands.

  3. Purge

    The organization's database records and uploaded files are deleted, and a permanent purge record is kept. The requester is emailed its reference.

Sub-processors and AI data flow

Third parties the platform itself uses to deliver the service, for every customer.

Sub-processors
Sub-processorPurposeDataRegion
Amazon Web ServicesHosting, database, object storage, key managementAll customer data at rest and in transitap-south-1 (Mumbai, India)
AWS BedrockAI inference for the Apex assistant, the Communications agent and in-product AI features, on every planPrompt context assembled from workspace data, and the text of emails the Communications agent answersus-east-1 (N. Virginia, United States), until Mumbai capacity is available
StripeSubscription billing and payment processingBilling contact and payment instrument (held by Stripe)United States
RazorpaySubscription billing for Indian customersBilling contact and payment instrument (held by Razorpay)India
Amazon SESTransactional and notification email (sign-in codes, invitations, alerts, billing notices)Recipient email address and message contentap-south-1 (Mumbai, India)
Microsoft (Graph API)The Communications Agent's mailbox, and a fallback if Amazon SES cannot deliver a messageRecipient email address and message contentPer Microsoft 365 tenant
GitHubSign-in, and pull request cost analysis when the GitHub App is installedOAuth identity; repository content the App is grantedUnited States
GoogleSign-in (OAuth)OAuth identity (email, subject identifier)United States

Integrations you turn on

These receive data only when your organization connects them, with credentials you supply.

Customer-enabled integrations
IntegrationWhat is sent
Slack and Microsoft TeamsAlert and approval messages to the channels you choose
PagerDutyIncident events for the services you map
Jira, Linear and ServiceNowTickets and change requests you raise, and their status
DatadogRead-only usage and cost queries with your API key
AI provider accounts (OpenAI, Anthropic, Google Gemini, Groq)Read-only usage and billing queries with your key, for AI cost tracking
Your cloud accounts (AWS, Azure, Google Cloud, Oracle Cloud)Read calls within the role you grant; write calls only after approval

What the AI assistant sends to a model

Every plan uses AWS Bedrock. Model calls run in us-east-1 (United States) until AWS raises Bedrock capacity in Mumbai; nothing is stored there, and no other model provider is used. Knowledge-base search is embedded inside the platform, and outside web research is switched off.

Always sent
User message, System instructions
Sent when relevant to the question
Workspace snapshot, Memory context, Knowledge snippets, Custom instructions

Email delivery

Email from the platform is sent from one authenticated domain, so your mail system can allow it by domain rather than by IP address.

Sender address
no-reply@varcio.com
This address does not take support requests. Contact support from inside the product.
Authentication
DKIM (2048-bit), SPF-aligned, DMARC
Messages are signed by varcio.com; DMARC is published for the domain.
Sent through
Amazon SES, Mumbai (ap-south-1)
Microsoft 365 is used only as a fallback if SES cannot deliver a message.
Transport security
TLS when the receiving server supports it
Delivery is encrypted in transit whenever your mail server offers TLS.
IP addresses
Shared, not fixed
Allow-list the domain and its DKIM signature, not addresses. If your policy requires fixed IPs, contact us.

For your IT team

  • Allow mail from the domain varcio.com that passes DKIM (d=varcio.com).
  • Do not rely on IP allow-lists: the sending addresses change as the provider scales.
  • If a message is quarantined, release it and report it to support so the cause can be traced.

How we handle delivery problems

  • Addresses that bounce permanently, or whose owner marks a message as spam, are stopped automatically and flagged to your administrators in Members, so an invitation to a mistyped address does not fail silently.
  • Security alerts, sign-in codes, approval requests and support replies are always sent. Optional notifications carry a one-click unsubscribe link and follow each person's notification preferences.

Compliance programme

Status as it stands. Nothing is described as certified until an auditor's report exists.

Certification and assurance status
ProgrammeStatusDetail
SOC 2 Type IIIn progress: Readiness programmeControl mapping and evidence collection in progress. Not yet audited.
ISO 27001Not started: Not startedPlanned after SOC 2. No certification is held.
Penetration testingIn progress: Programme definedScope and reporting cadence documented; a summary is published once a test completes.
Vulnerability disclosureDone: PublishedCoordinated disclosure policy with a named security contact.
Audit loggingDone: EnforcedActor, action, target and timestamp recorded, hash-chained per workspace so tampering is detectable.

Known limitations

Stated plainly so a reviewer does not have to ask.

  • No third-party penetration test report exists yet. The programme is defined.
  • No VPAT or independent accessibility audit is published. The product is designed to WCAG 2.2 level AA.
  • Customers cannot choose a data region. Every customer is served from the region shown above.
  • The database is single-AZ with 7-day point-in-time recovery. There is no cross-region recovery.
  • Legal hold is not supported.
  • Audit-log streaming to a SIEM is not yet available. Audit logs can be exported as CSV or JSON.
  • The standard Data Processing Agreement is published and applies to all customers. Customers with specific requirements can ask for changes, which we review with counsel.

Accessibility

We design to WCAG 2.2 level AA. The product has not yet been audited independently, and we do not publish a VPAT. If something stops you using Varcio with assistive technology, email support@varcio.com and we will treat it as a defect.

Availability and support

The API and web control plane for paid plans. Maintenance announced at least 48 hours ahead is excluded. Live and historical availability is on the status page.

Commitment
99.9% monthly uptime
Paid plans. Preview, beta and sandbox environments are not covered.
What counts as downtime
Minutes when the production API or web control plane is unavailable to all customer tenants because of a failure of the service.
Service credits
Monthly uptimeService credit
Below 99.9%, at or above 99.0%10% of the monthly platform fee
Below 99.0%25% of the monthly platform fee

Request a credit within 30 days after the month, with your organization and the incident times. Credits apply to future invoices. Include your organization identifier, the incident timestamps in UTC, the affected endpoints or workflows. We review platform telemetry and incident records and respond within 10 business days.

Exclusions

  • Customer-side misconfiguration, credential revocation or IAM policy changes
  • Outages of a third-party cloud provider (AWS, Azure, Google Cloud) outside our control
  • Customer network problems, ISP failures, or browser and device faults
  • Force majeure
  • Suspension or rate limits applied for abuse, non-payment or a terms violation

Support response targets

Data rights and grievance

Requests are tracked to closure. Use the form and you get a reference number and the date by which we will respond.

Data rights and how to use them
RightHow
AccessEach person downloads their own profile, settings, sessions, support tickets and audit activity from Settings, with a summary of the sub-processors that may receive it. Anyone can also ask through the privacy request form. Administrators export cost data and audit logs.
CorrectionProfile fields are editable in the app; other corrections on request.
ErasureAdministrators remove members, or close the organization from the Organization console: nothing is deleted for 30 days, then its records and uploaded files are deleted. Anyone else can ask through the privacy request form.
GrievanceUse the privacy request form. You get a reference number and a respond-by date straight away. We answer within 30 days; the DPDP Rules allow at most 90.
Nomination and withdrawing consentUse the privacy request form. It is as easy to withdraw consent as it was to give it.

Make a privacy request

For access, correction, erasure, a grievance, nomination or withdrawing consent. You do not need an account. You can also email security@varcio.com.

Open the request form

Documents for your review

Shared with customers and prospects under NDA. The Security & Compliance Pack at the top of this page summarises them. Ask the security team for the documents themselves.

  • Data retention and deletion

    Retention windows per data class and the deletion path on termination.

    Updated September 15, 2026

  • Incident response plan

    Severity classification, escalation, and customer notification timelines.

    Updated September 29, 2026

  • Personal data breach response

    How a personal-data breach is contained, reported to CERT-In within six hours, and notified to customers, the Data Protection Board and affected people.

    Updated September 29, 2026

  • Grievance and data-rights procedure

    How privacy requests and complaints are received, verified, answered and escalated, with timelines.

    Updated September 29, 2026

  • DPDP and India compliance map

    Each requirement of India's data-protection law, CERT-In and sector rules, how it is met, and its honest status.

    Updated September 29, 2026

  • Change management

    Review, approval and rollback requirements for production change.

    Updated February 26, 2026

  • Vulnerability disclosure

    How to report a vulnerability and what response to expect.

    Updated February 26, 2026

  • Penetration test programme

    Testing scope, cadence, and how findings are tracked to closure.

    Updated February 26, 2026

  • Uptime SLA

    Availability commitment, measurement and service credits.

    Updated February 22, 2026

Contacts

Who to contact
ForContact
Security questions, documents, the DPA, vulnerability reports and privacy grievancessecurity@varcio.com
Product and account supportsupport@varcio.com
Invoices and subscription billingbilling@varcio.com
Data rights requestsPrivacy request form

Position statement for security review, not legal advice. If a signed order form, MSA or DPA exists, it controls over this page to the extent of any conflict.