How Varcio handles your data
Your data is stored and processed in AWS ap-south-1 (Mumbai, India), encrypted at rest and in transit. Nothing here is called certified: SOC 2 Type II is readiness programme, ISO 27001 is not started.
Every entry is checked against the running service. Enforced figures are read live, and the rest was last reviewed on 3 October 2026.
One file, no scripts, works offline. Opens in a new tab for printing.
At a glance
- Hosting region
- AWS ap-south-1 (Mumbai, India)
- Encryption at rest
- AES-256
- Encryption in transit
- TLS 1.2 or later
- Uptime commitment
- 99.9% monthly uptime
- Paid plans, service credits on request
- SOC 2 Type II
- Readiness programme
- Sub-processors
- 8 listed
- Plus integrations you turn on
Data residency and cross-border transfer
Customer data is stored and processed in AWS ap-south-1 (Mumbai, India), except AI inference, which runs on AWS Bedrock in us-east-1 (United States) for now. Sub-processors outside India are listed below with their regions. India's DPDP Act 2023 allows transfer abroad unless the Government restricts a named country under Section 16(1); no country has been restricted. The Act's core duties, including its transfer rules, take effect on 13 May 2027.
- Primary region
- AWS ap-south-1 (Mumbai, India)
- Application, database, cache, object storage and encryption keys.
- Database
- Amazon RDS PostgreSQL, single-AZ
- Encrypted at rest; automated backups with point-in-time recovery.
- Backups
- 7-day point-in-time recovery
- Retained in-region. Deleted data can remain in backups for up to 7 days.
- Encryption at rest
- AES-256
- The database and object storage are encrypted with a customer-managed AWS KMS key in Mumbai, and the cache is encrypted at rest. Credentials and integration secrets are additionally wrapped per record with the same key (envelope encryption).
- Encryption in transit
- TLS 1.2 or later
- TLS 1.0 and 1.1 are refused. HSTS is sent on every public hostname. The link to the cache is TLS-encrypted too.
- Tenant isolation
- Workspace-scoped at query level
- Enforced in storage and query paths, not only in the UI. The only cross-workspace reads are the aggregate FinOps-score percentile (at least five peers) and the opt-in benchmark network.
Encryption keys
- Mode
- Envelope encryption with per-record data keys
- Key wrapping
- Customer-managed AWS KMS key (ap-south-1) wraps the data keys for credentials and integration secrets
- Database and object storage
- Encrypted with the same customer-managed AWS KMS key (ap-south-1)
India: DPDP Act 2023
- The Act imposes no general data-localisation duty on ordinary data fiduciaries. Two provisions can require India residency: Rule 13(4), for Significant Data Fiduciaries and only for data the Government specifies (no list or designation has been published), and Section 16(2), which preserves stricter sector rules.
- RBI's 2018 payment-data circular applies to authorised payment systems and listed banks, and reaches their vendors through them. This platform stores no card, bank-account or payment-credential data; Stripe and Razorpay hold it.
- Customers regulated by SEBI, or buying under government cloud-procurement rules, can be required to use India-resident, MeitY-empanelled hosting; banks, NBFCs and insurers usually require a data-location clause by contract. Hosting in Mumbai meets an India-residency requirement; whether a given hosting provider is MeitY-empanelled is a separate procurement check that depends on the buyer's rules.
- There is no EU data residency option today, and customers cannot choose a region. Every customer is served from Mumbai, India; AI inference moves back to Mumbai once AWS raises the Bedrock capacity there.
Security controls
Controls that exist in the product today. Where one depends on the plan, it says so.
Identity and access
| Control | How it works |
|---|---|
| Single sign-on | SAML 2.0 and OIDC on the Enterprise plan. Password sign-in can be blocked when SSO is enforced, with a break-glass exception. |
| SCIM provisioning | SCIM 2.0 Users and Groups with explicit group-to-role mapping, on the Enterprise plan. |
| Multi-factor authentication | TOTP with recovery codes, and WebAuthn passkeys. An organization can require MFA: members are blocked until they enrol, and personal API keys are refused until their owner has enrolled. |
| Re-authentication | SSO configuration, network policy, session revocation and organization closure need a recent sign-in confirmation. |
| IP allowlist | An organization allowlist, enforced on sessions, API keys and sign-in (not on SCIM). |
| Roles | Admin and member roles on every plan. Custom scoped roles and business-unit row scopes on the Enterprise plan, enforced on every cost query. |
| Sessions | Each session can be revoked, or all of them at once. |
Logging and monitoring
| Control | How it works |
|---|---|
| Audit log | Actor, action, target and timestamp for administrative actions, hash-chained per workspace so tampering is detectable, with a verify endpoint. |
| Audit export | CSV or JSON, up to 20,000 rows per export, within your plan's retention window. Streaming to a SIEM is not yet available. |
Change management
| Control | How it works |
|---|---|
| Production change | Reviewed pull requests; CI must pass before merge; migrations are reviewed for backward compatibility; schema, auth and execution-path changes need a rollback plan. |
How a cloud connection is handled
Encrypt on ingest
Credentials and integration secrets are encrypted before they are persisted.
Validate read plane
Provider read access is verified before any telemetry or compliance processing runs.
Gate write plane
Write actions stay blocked until permissions and approval requirements are satisfied.
Audit and retain
Sensitive operations are logged, and audit entries are kept for your plan's retention window.
Incident response and vulnerability reports
| Severity | Meaning |
|---|---|
| SEV-1 | Multi-tenant outage, active security incident, or confirmed data exposure. |
| SEV-2 | Major degradation, failed execution controls, or sustained customer impact. |
| SEV-3 | Localized defect with an available workaround. |
- Severity is triaged within 15 minutes.
- First public update within 30 minutes for SEV-1 and SEV-2.
- Updates every 30 minutes until the incident is stable.
- The closure update states the root cause, the remediation and the prevention actions.
- A postmortem is completed within 5 business days for SEV-1 and SEV-2.
Personal-data breaches
Report a vulnerability to the security contact with reproduction steps, impact and the affected component. We acknowledge within 1 business day and triage severity within 3 business days. Report a vulnerability. Security research is authorized when performed in good faith and without data exfiltration, service disruption or privacy violations.
Data lifecycle and retention
How long each kind of data is kept, and what happens to it when you leave.
| Plan | Audit log you can read and export | Not deleted before |
|---|---|---|
| Explorer | Not included | 1 year |
| Pro | 90 days | 1 year |
| Business | 1 year | 1 year |
| Enterprise | 3 years | 3 years |
Documented figures, reviewed 3 October 2026. Checking them against the running service.
| Data class | Retention |
|---|---|
| Report exports | Expire after 7 days |
| Ended sign-in sessions | Pruned after 2 days, when the person next opens their sessions, for sign-in security |
| Recognised devices | Pruned after 180 days, at the person's next sign-in, for sign-in security |
| Event outbox and delivery telemetry | 90 days |
| Database backups | 7-day point-in-time recovery. Deleted data can remain in backups for up to 7 days. |
| Uploaded files (support attachments, contract documents) | Deleted with the organization. Earlier file versions expire from object storage within 7 days. |
| Invoices, payments and partner ledgers | Kept as accounting records. The link to the organization is removed when it is deleted. |
| Incident records and postmortems | 24 months. This is a process commitment, not an automated deletion. |
Closing an organization
Request
An organization administrator types the organization name, gives a reason and re-authenticates. Every administrator is emailed.
Export window
Nothing is deleted for 30 days and any administrator can cancel. Billing stops: the subscription does not renew while the request stands.
Purge
The organization's database records and uploaded files are deleted, and a permanent purge record is kept. The requester is emailed its reference.
Sub-processors and AI data flow
Third parties the platform itself uses to deliver the service, for every customer.
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services | Hosting, database, object storage, key management | All customer data at rest and in transit | ap-south-1 (Mumbai, India) |
| AWS Bedrock | AI inference for the Apex assistant, the Communications agent and in-product AI features, on every plan | Prompt context assembled from workspace data, and the text of emails the Communications agent answers | us-east-1 (N. Virginia, United States), until Mumbai capacity is available |
| Stripe | Subscription billing and payment processing | Billing contact and payment instrument (held by Stripe) | United States |
| Razorpay | Subscription billing for Indian customers | Billing contact and payment instrument (held by Razorpay) | India |
| Amazon SES | Transactional and notification email (sign-in codes, invitations, alerts, billing notices) | Recipient email address and message content | ap-south-1 (Mumbai, India) |
| Microsoft (Graph API) | The Communications Agent's mailbox, and a fallback if Amazon SES cannot deliver a message | Recipient email address and message content | Per Microsoft 365 tenant |
| GitHub | Sign-in, and pull request cost analysis when the GitHub App is installed | OAuth identity; repository content the App is granted | United States |
| Sign-in (OAuth) | OAuth identity (email, subject identifier) | United States |
Integrations you turn on
These receive data only when your organization connects them, with credentials you supply.
| Integration | What is sent |
|---|---|
| Slack and Microsoft Teams | Alert and approval messages to the channels you choose |
| PagerDuty | Incident events for the services you map |
| Jira, Linear and ServiceNow | Tickets and change requests you raise, and their status |
| Datadog | Read-only usage and cost queries with your API key |
| AI provider accounts (OpenAI, Anthropic, Google Gemini, Groq) | Read-only usage and billing queries with your key, for AI cost tracking |
| Your cloud accounts (AWS, Azure, Google Cloud, Oracle Cloud) | Read calls within the role you grant; write calls only after approval |
What the AI assistant sends to a model
Every plan uses AWS Bedrock. Model calls run in us-east-1 (United States) until AWS raises Bedrock capacity in Mumbai; nothing is stored there, and no other model provider is used. Knowledge-base search is embedded inside the platform, and outside web research is switched off.
- Always sent
- User message, System instructions
- Sent when relevant to the question
- Workspace snapshot, Memory context, Knowledge snippets, Custom instructions
Email delivery
Email from the platform is sent from one authenticated domain, so your mail system can allow it by domain rather than by IP address.
- Sender address
- no-reply@varcio.com
- This address does not take support requests. Contact support from inside the product.
- Authentication
- DKIM (2048-bit), SPF-aligned, DMARC
- Messages are signed by varcio.com; DMARC is published for the domain.
- Sent through
- Amazon SES, Mumbai (ap-south-1)
- Microsoft 365 is used only as a fallback if SES cannot deliver a message.
- Transport security
- TLS when the receiving server supports it
- Delivery is encrypted in transit whenever your mail server offers TLS.
- IP addresses
- Shared, not fixed
- Allow-list the domain and its DKIM signature, not addresses. If your policy requires fixed IPs, contact us.
For your IT team
- Allow mail from the domain varcio.com that passes DKIM (d=varcio.com).
- Do not rely on IP allow-lists: the sending addresses change as the provider scales.
- If a message is quarantined, release it and report it to support so the cause can be traced.
How we handle delivery problems
- Addresses that bounce permanently, or whose owner marks a message as spam, are stopped automatically and flagged to your administrators in Members, so an invitation to a mistyped address does not fail silently.
- Security alerts, sign-in codes, approval requests and support replies are always sent. Optional notifications carry a one-click unsubscribe link and follow each person's notification preferences.
Compliance programme
Status as it stands. Nothing is described as certified until an auditor's report exists.
| Programme | Status | Detail |
|---|---|---|
| SOC 2 Type II | In progress: Readiness programme | Control mapping and evidence collection in progress. Not yet audited. |
| ISO 27001 | Not started: Not started | Planned after SOC 2. No certification is held. |
| Penetration testing | In progress: Programme defined | Scope and reporting cadence documented; a summary is published once a test completes. |
| Vulnerability disclosure | Done: Published | Coordinated disclosure policy with a named security contact. |
| Audit logging | Done: Enforced | Actor, action, target and timestamp recorded, hash-chained per workspace so tampering is detectable. |
Known limitations
Stated plainly so a reviewer does not have to ask.
- No third-party penetration test report exists yet. The programme is defined.
- No VPAT or independent accessibility audit is published. The product is designed to WCAG 2.2 level AA.
- Customers cannot choose a data region. Every customer is served from the region shown above.
- The database is single-AZ with 7-day point-in-time recovery. There is no cross-region recovery.
- Legal hold is not supported.
- Audit-log streaming to a SIEM is not yet available. Audit logs can be exported as CSV or JSON.
- The standard Data Processing Agreement is published and applies to all customers. Customers with specific requirements can ask for changes, which we review with counsel.
Accessibility
We design to WCAG 2.2 level AA. The product has not yet been audited independently, and we do not publish a VPAT. If something stops you using Varcio with assistive technology, email support@varcio.com and we will treat it as a defect.
Availability and support
The API and web control plane for paid plans. Maintenance announced at least 48 hours ahead is excluded. Live and historical availability is on the status page.
- Commitment
- 99.9% monthly uptime
- Paid plans. Preview, beta and sandbox environments are not covered.
- What counts as downtime
- Minutes when the production API or web control plane is unavailable to all customer tenants because of a failure of the service.
| Monthly uptime | Service credit |
|---|---|
| Below 99.9%, at or above 99.0% | 10% of the monthly platform fee |
| Below 99.0% | 25% of the monthly platform fee |
Request a credit within 30 days after the month, with your organization and the incident times. Credits apply to future invoices. Include your organization identifier, the incident timestamps in UTC, the affected endpoints or workflows. We review platform telemetry and incident records and respond within 10 business days.
Exclusions
- Customer-side misconfiguration, credential revocation or IAM policy changes
- Outages of a third-party cloud provider (AWS, Azure, Google Cloud) outside our control
- Customer network problems, ISP failures, or browser and device faults
- Force majeure
- Suspension or rate limits applied for abuse, non-payment or a terms violation
Support response targets
Data rights and grievance
Requests are tracked to closure. Use the form and you get a reference number and the date by which we will respond.
| Right | How |
|---|---|
| Access | Each person downloads their own profile, settings, sessions, support tickets and audit activity from Settings, with a summary of the sub-processors that may receive it. Anyone can also ask through the privacy request form. Administrators export cost data and audit logs. |
| Correction | Profile fields are editable in the app; other corrections on request. |
| Erasure | Administrators remove members, or close the organization from the Organization console: nothing is deleted for 30 days, then its records and uploaded files are deleted. Anyone else can ask through the privacy request form. |
| Grievance | Use the privacy request form. You get a reference number and a respond-by date straight away. We answer within 30 days; the DPDP Rules allow at most 90. |
| Nomination and withdrawing consent | Use the privacy request form. It is as easy to withdraw consent as it was to give it. |
Make a privacy request
For access, correction, erasure, a grievance, nomination or withdrawing consent. You do not need an account. You can also email security@varcio.com.
Documents for your review
Shared with customers and prospects under NDA. The Security & Compliance Pack at the top of this page summarises them. Ask the security team for the documents themselves.
Data retention and deletion
Retention windows per data class and the deletion path on termination.
Updated September 15, 2026
Incident response plan
Severity classification, escalation, and customer notification timelines.
Updated September 29, 2026
Personal data breach response
How a personal-data breach is contained, reported to CERT-In within six hours, and notified to customers, the Data Protection Board and affected people.
Updated September 29, 2026
Grievance and data-rights procedure
How privacy requests and complaints are received, verified, answered and escalated, with timelines.
Updated September 29, 2026
DPDP and India compliance map
Each requirement of India's data-protection law, CERT-In and sector rules, how it is met, and its honest status.
Updated September 29, 2026
Change management
Review, approval and rollback requirements for production change.
Updated February 26, 2026
Vulnerability disclosure
How to report a vulnerability and what response to expect.
Updated February 26, 2026
Penetration test programme
Testing scope, cadence, and how findings are tracked to closure.
Updated February 26, 2026
Uptime SLA
Availability commitment, measurement and service credits.
Updated February 22, 2026
Contacts
| For | Contact |
|---|---|
| Security questions, documents, the DPA, vulnerability reports and privacy grievances | security@varcio.com |
| Product and account support | support@varcio.com |
| Invoices and subscription billing | billing@varcio.com |
| Data rights requests | Privacy request form |
Position statement for security review, not legal advice. If a signed order form, MSA or DPA exists, it controls over this page to the extent of any conflict.