Trust Center

Documented figures. Checking the running service.

Varcio

Security & Compliance Pack

Data residency, security controls, retention, sub-processors, availability and assurance status

Version
1.0
Generated
4 October 2026
Facts reviewed
3 October 2026
Security contact
security@varcio.com

As of 4 October 2026. The running service could not be reached when this pack was generated. Retention figures are the documented values in the data retention policy, and support response targets are not shown. Everything is the published position reviewed on 3 October 2026. Generate the pack again for live figures.

1At a glance

This pack answers the questions a security or procurement reviewer asks first about Varcio: where data is stored, who else processes it, how long it is kept, what is and is not certified, and what is committed on availability and support. It is generated from the same facts that drive the public Trust Center, so the two agree.

Hosting region
AWS ap-south-1 (Mumbai, India)
Encryption at rest
AES-256
Encryption in transit
TLS 1.2 or later
Backups
7-day point-in-time recovery
Uptime commitment
99.9% monthly uptime
SOC 2 Type II
Readiness programme. Control mapping and evidence collection in progress. Not yet audited.
ISO 27001
Not started. Planned after SOC 2. No certification is held.
Sub-processors
8 listed under Sub-processors and AI data flow

2Data residency and cross-border transfer

Where customer data lives
ItemPositionDetail
Primary regionAWS ap-south-1 (Mumbai, India)Application, database, cache, object storage and encryption keys.
DatabaseAmazon RDS PostgreSQL, single-AZEncrypted at rest; automated backups with point-in-time recovery.
Backups7-day point-in-time recoveryRetained in-region. Deleted data can remain in backups for up to 7 days.
Encryption at restAES-256The database and object storage are encrypted with a customer-managed AWS KMS key in Mumbai, and the cache is encrypted at rest. Credentials and integration secrets are additionally wrapped per record with the same key (envelope encryption).
Encryption in transitTLS 1.2 or laterTLS 1.0 and 1.1 are refused. HSTS is sent on every public hostname. The link to the cache is TLS-encrypted too.
Tenant isolationWorkspace-scoped at query levelEnforced in storage and query paths, not only in the UI. The only cross-workspace reads are the aggregate FinOps-score percentile (at least five peers) and the opt-in benchmark network.

Encryption in detail

Encryption for credentials and stored data
ItemPosition
ModeEnvelope encryption with per-record data keys
Key wrappingCustomer-managed AWS KMS key (ap-south-1) wraps the data keys for credentials and integration secrets
Database and object storageEncrypted with the same customer-managed AWS KMS key (ap-south-1)

India (DPDP Act 2023) position

Customer data is stored and processed in AWS ap-south-1 (Mumbai, India), except AI inference, which runs on AWS Bedrock in us-east-1 (United States) for now. Sub-processors outside India are listed below with their regions. India's DPDP Act 2023 allows transfer abroad unless the Government restricts a named country under Section 16(1); no country has been restricted. The Act's core duties, including its transfer rules, take effect on 13 May 2027.

  • The Act imposes no general data-localisation duty on ordinary data fiduciaries. Two provisions can require India residency: Rule 13(4), for Significant Data Fiduciaries and only for data the Government specifies (no list or designation has been published), and Section 16(2), which preserves stricter sector rules.
  • RBI's 2018 payment-data circular applies to authorised payment systems and listed banks, and reaches their vendors through them. This platform stores no card, bank-account or payment-credential data; Stripe and Razorpay hold it.
  • Customers regulated by SEBI, or buying under government cloud-procurement rules, can be required to use India-resident, MeitY-empanelled hosting; banks, NBFCs and insurers usually require a data-location clause by contract. Hosting in Mumbai meets an India-residency requirement; whether a given hosting provider is MeitY-empanelled is a separate procurement check that depends on the buyer's rules.
  • There is no EU data residency option today, and customers cannot choose a region. Every customer is served from Mumbai, India; AI inference moves back to Mumbai once AWS raises the Bedrock capacity there.

Position statement for security review, not legal advice. Reviewed when hosting changes or a restricted-country list, a Rule 15 order or a Rule 13(4) list is published.

3Security controls

Identity and access

Identity and access
ControlHow it works
Single sign-onSAML 2.0 and OIDC on the Enterprise plan. Password sign-in can be blocked when SSO is enforced, with a break-glass exception.
SCIM provisioningSCIM 2.0 Users and Groups with explicit group-to-role mapping, on the Enterprise plan.
Multi-factor authenticationTOTP with recovery codes, and WebAuthn passkeys. An organization can require MFA: members are blocked until they enrol, and personal API keys are refused until their owner has enrolled.
Re-authenticationSSO configuration, network policy, session revocation and organization closure need a recent sign-in confirmation.
IP allowlistAn organization allowlist, enforced on sessions, API keys and sign-in (not on SCIM).
RolesAdmin and member roles on every plan. Custom scoped roles and business-unit row scopes on the Enterprise plan, enforced on every cost query.
SessionsEach session can be revoked, or all of them at once.

Logging and monitoring

Logging and monitoring
ControlHow it works
Audit logActor, action, target and timestamp for administrative actions, hash-chained per workspace so tampering is detectable, with a verify endpoint.
Audit exportCSV or JSON, up to 20,000 rows per export, within your plan's retention window. Streaming to a SIEM is not yet available.

Change management

Change management
ControlHow it works
Production changeReviewed pull requests; CI must pass before merge; migrations are reviewed for backward compatibility; schema, auth and execution-path changes need a rollback plan.

How a cloud connection is handled

  1. Encrypt on ingest. Credentials and integration secrets are encrypted before they are persisted.
  2. Validate read plane. Provider read access is verified before any telemetry or compliance processing runs.
  3. Gate write plane. Write actions stay blocked until permissions and approval requirements are satisfied.
  4. Audit and retain. Sensitive operations are logged, and audit entries are kept for your plan's retention window.

Audit logging is enforced: Actor, action, target and timestamp recorded, hash-chained per workspace so tampering is detectable.

4Data lifecycle and retention

Audit log, by plan

Audit log retention by plan
PlanReadable and exportableNot deleted before
ExplorerNot included1 year
Pro90 days1 year
Business1 year1 year
Enterprise3 years3 years

Other data classes

Retention by data class
Data classRetention
Report exportsExpire after 7 days
Ended sign-in sessionsPruned after 2 days, when the person next opens their sessions, for sign-in security
Recognised devicesPruned after 180 days, at the person's next sign-in, for sign-in security
Event outbox and delivery telemetry90 days
Database backups7-day point-in-time recovery. Deleted data can remain in backups for up to 7 days.
Uploaded files (support attachments, contract documents)Deleted with the organization. Earlier file versions expire from object storage within 7 days.
Invoices, payments and partner ledgersKept as accounting records. The link to the organization is removed when it is deleted.
Incident records and postmortems24 months. This is a process commitment, not an automated deletion.

Closing an organization

  1. Request. An organization administrator types the organization name, gives a reason and re-authenticates. Every administrator is emailed.
  2. Export window. Nothing is deleted for 30 days and any administrator can cancel. Billing stops: the subscription does not renew while the request stands.
  3. Purge. The organization's database records and uploaded files are deleted, and a permanent purge record is kept. The requester is emailed its reference.

5Sub-processors and AI data flow

Third parties the platform itself uses to deliver the service, for every customer.

Sub-processors
Sub-processorPurposeDataRegion
Amazon Web ServicesHosting, database, object storage, key managementAll customer data at rest and in transitap-south-1 (Mumbai, India)
AWS BedrockAI inference for the Apex assistant, the Communications agent and in-product AI features, on every planPrompt context assembled from workspace data, and the text of emails the Communications agent answersus-east-1 (N. Virginia, United States), until Mumbai capacity is available
StripeSubscription billing and payment processingBilling contact and payment instrument (held by Stripe)United States
RazorpaySubscription billing for Indian customersBilling contact and payment instrument (held by Razorpay)India
Amazon SESTransactional and notification email (sign-in codes, invitations, alerts, billing notices)Recipient email address and message contentap-south-1 (Mumbai, India)
Microsoft (Graph API)The Communications Agent's mailbox, and a fallback if Amazon SES cannot deliver a messageRecipient email address and message contentPer Microsoft 365 tenant
GitHubSign-in, and pull request cost analysis when the GitHub App is installedOAuth identity; repository content the App is grantedUnited States
GoogleSign-in (OAuth)OAuth identity (email, subject identifier)United States

Integrations you turn on

These receive data only when your organization connects them, with credentials you supply.

Customer-enabled integrations
IntegrationWhat is sent
Slack and Microsoft TeamsAlert and approval messages to the channels you choose
PagerDutyIncident events for the services you map
Jira, Linear and ServiceNowTickets and change requests you raise, and their status
DatadogRead-only usage and cost queries with your API key
AI provider accounts (OpenAI, Anthropic, Google Gemini, Groq)Read-only usage and billing queries with your key, for AI cost tracking
Your cloud accounts (AWS, Azure, Google Cloud, Oracle Cloud)Read calls within the role you grant; write calls only after approval

What the AI assistant sends to a model

Every plan uses AWS Bedrock. Model calls run in us-east-1 (United States) until AWS raises Bedrock capacity in Mumbai; nothing is stored there, and no other model provider is used. Knowledge-base search is embedded inside the platform, and outside web research is switched off.

Always sent
User message, System instructions
Sent when relevant to the question
Workspace snapshot, Memory context, Knowledge snippets, Custom instructions

6Compliance programme

Status as it stands today. Nothing is described as certified until an auditor's report exists.

Certification and assurance status
ProgrammeStatusDetail
SOC 2 Type IIIn progress: Readiness programmeControl mapping and evidence collection in progress. Not yet audited.
ISO 27001Not started: Not startedPlanned after SOC 2. No certification is held.
Penetration testingIn progress: Programme definedScope and reporting cadence documented; a summary is published once a test completes.
Vulnerability disclosureDone: PublishedCoordinated disclosure policy with a named security contact.
Audit loggingDone: EnforcedActor, action, target and timestamp recorded, hash-chained per workspace so tampering is detectable.

Known limitations

Stated plainly so a reviewer does not have to ask.

  • No third-party penetration test report exists yet. The programme is defined.
  • No VPAT or independent accessibility audit is published. The product is designed to WCAG 2.2 level AA.
  • Customers cannot choose a data region. Every customer is served from the region shown above.
  • The database is single-AZ with 7-day point-in-time recovery. There is no cross-region recovery.
  • Legal hold is not supported.
  • Audit-log streaming to a SIEM is not yet available. Audit logs can be exported as CSV or JSON.
  • The standard Data Processing Agreement is published and applies to all customers. Customers with specific requirements can ask for changes, which we review with counsel.

7Availability and support

Commitment
99.9% monthly uptime
Scope
The API and web control plane for paid plans. Maintenance announced at least 48 hours ahead is excluded.
Applies to
Paid plans. Preview, beta and sandbox environments are not covered.
What counts as downtime
Minutes when the production API or web control plane is unavailable to all customer tenants because of a failure of the service.
Service credits
Monthly uptimeService credit
Below 99.9%, at or above 99.0%10% of the monthly platform fee
Below 99.0%25% of the monthly platform fee

Request a credit within 30 days after the month, with your organization and the incident times. Credits apply to future invoices.

Include your organization identifier, the incident timestamps in UTC, the affected endpoints or workflows. We review platform telemetry and incident records and respond within 10 business days.

Exclusions

  • Customer-side misconfiguration, credential revocation or IAM policy changes
  • Outages of a third-party cloud provider (AWS, Azure, Google Cloud) outside our control
  • Customer network problems, ISP failures, or browser and device faults
  • Force majeure
  • Suspension or rate limits applied for abuse, non-payment or a terms violation

Support response targets

Support tiers by plan
SupportPlansNamed engineer
StandardExplorer, Pro-
PriorityBusiness-
EnterpriseEnterpriseIncluded

Response targets per priority are read from the running service. They were not available when this pack was generated; generate it again, or ask the support team for the current figures.

8Incident and breach response

Incident severity model
SeverityMeaning
SEV-1Multi-tenant outage, active security incident, or confirmed data exposure.
SEV-2Major degradation, failed execution controls, or sustained customer impact.
SEV-3Localized defect with an available workaround.

Response workflow

  1. Detect through automated health checks, alerts or a customer report.
  2. Triage severity within 15 minutes.
  3. Assign an incident commander and a communications owner.
  4. Contain the impact and apply immediate mitigations.
  5. Publish a status update to the public status page and customer channels.
  6. Resolve, validate recovery, and publish a closure update.
  7. Complete a postmortem within 5 business days for SEV-1 and SEV-2.

Communication targets

  • Severity is triaged within 15 minutes.
  • First public update within 30 minutes for SEV-1 and SEV-2.
  • Updates every 30 minutes until the incident is stable.
  • The closure update states the root cause, the remediation and the prevention actions.
  • A postmortem is completed within 5 business days for SEV-1 and SEV-2.

Personal-data breaches

A separate Personal Data Breach Response Procedure covers breaches of personal data. We report reportable incidents to India's CERT-In within six hours of noticing them; we notify affected customers without undue delay and within 48 hours at the latest (our internal target is 24 hours); and where we are the data fiduciary we notify the Data Protection Board and affected people as the DPDP Rules require from 13 May 2027. The procedure is shared under NDA on request.

Reporting a vulnerability

Report a vulnerability to the security contact with reproduction steps, impact and the affected component. We acknowledge within 1 business day and triage severity within 3 business days.

Security research is authorized when performed in good faith and without data exfiltration, service disruption or privacy violations.

Out of scope: social engineering and physical attacks; denial-of-service testing against production; vulnerabilities that need compromised third-party credentials.

9Data rights and grievance

Data rights and how to use them
RightHow
AccessEach person downloads their own profile, settings, sessions, support tickets and audit activity from Settings, with a summary of the sub-processors that may receive it. Anyone can also ask through the privacy request form. Administrators export cost data and audit logs.
CorrectionProfile fields are editable in the app; other corrections on request.
ErasureAdministrators remove members, or close the organization from the Organization console: nothing is deleted for 30 days, then its records and uploaded files are deleted. Anyone else can ask through the privacy request form.
GrievanceUse the privacy request form. You get a reference number and a respond-by date straight away. We answer within 30 days; the DPDP Rules allow at most 90.
Nomination and withdrawing consentUse the privacy request form. It is as easy to withdraw consent as it was to give it.

To make a request, including for nomination, withdrawal of consent or anything else, use the privacy request form (/privacy-request on the Varcio website). The confirmation gives a reference number and the date by which we will respond: within 30 days, and never more than the 90 days the DPDP Rules allow. Or email support@varcio.com with the subject "Privacy request". Report a security concern to security@varcio.com.

10Data Processing Agreement

Standard terms, version 1.0, effective 2026-09-29. This Data Processing Agreement (the “DPA”) forms part of the agreement between Varcio (“Varcio”, “we”) and the customer that has subscribed to the Varcio service (the “Customer”) (together, the “Agreement”). It applies to the extent Varcio processes Personal Data on the Customer’s behalf.

1. Definitions

“Personal Data”, “Data Fiduciary”, “Data Processor”, “Data Principal”, “Personal Data Breach” and “processing” have the meanings given in the Digital Personal Data Protection Act 2023 and its Rules (together, the “DPDP Law”). “Data Protection Law” means the DPDP Law and any other law on the protection of personal data that applies to the processing under this DPA, including the Information Technology Act 2000 and the rules under it while they remain in force.

“Customer Personal Data” means Personal Data contained in content the Customer or its users submit to, connect to, or generate in the service: for example cloud inventory and billing metadata, resource tags, support tickets, assistant conversations, and uploaded documents. “Sub-processor” means a third party Varcio engages to process Customer Personal Data.

2. Roles and scope

  1. For Customer Personal Data, the Customer is the Data Fiduciary and Varcio is its Data Processor. Varcio processes it only to provide, secure, support and bill for the service, and as the Customer instructs.
  2. For personal data Varcio collects for its own purposes (for example account sign-in details, billing contacts, and website and status-page visitors), Varcio is a Data Fiduciary and handles it under its Privacy Policy. This DPA does not govern that data.
  3. The Customer is responsible for having a lawful basis to give Varcio Customer Personal Data, for the accuracy of the instructions it gives, and for the notices and consents its own Data Principals are owed.

3. Instructions

Varcio processes Customer Personal Data on the Customer’s documented instructions. The Agreement, this DPA, and the Customer’s use and configuration of the service are its complete instructions. Varcio will tell the Customer if it believes an instruction infringes Data Protection Law. Varcio will not use Customer Personal Data to train machine-learning models, and will not sell it or use it for advertising.

4. Confidentiality and personnel

Varcio limits access to Customer Personal Data to personnel who need it to provide the service, and binds them to written confidentiality obligations that continue after their engagement ends.

5. Security safeguards

Varcio maintains reasonable security safeguards to protect Customer Personal Data, including those in Annex 2, and will not materially reduce them during the term. These are intended to meet the security safeguards in DPDP Rule 6, including encryption, access control, logging and monitoring, and backups for continued processing, and the retention of logs and processing records for at least one year.

6. Sub-processors

  1. The Customer gives Varcio general authorisation to engage the Sub-processors listed on the Varcio Trust Center at the date of the Agreement and in Annex 3.
  2. Varcio will give at least 30 days’ notice of a new Sub-processor, or of a change to the country in which a Sub-processor processes Customer Personal Data, by updating the Trust Center and emailing the Customer’s registered administrators.
  3. The Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve it; if they cannot, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the remainder of the term.
  4. Varcio imposes on each Sub-processor written obligations no less protective than this DPA and remains responsible for their performance.

7. Data location and transfers

  1. Customer Personal Data is hosted in the AWS region stated on the Trust Center on the effective date of the Agreement (Annex 4). Varcio will give at least 30 days’ notice before moving it to a different country, except where a move is needed to comply with law or to respond to an emergency, in which case Varcio will notify the Customer as soon as it can.
  2. Where processing involves a transfer outside India, Varcio will comply with the DPDP Law, including any restriction the Central Government notifies on transfer to a country or territory, and will tell the Customer if a restriction affects the service.
  3. Where the Customer is subject to a sector rule that requires data to be held in India, the parties will record that requirement in a signed order, and Varcio will host the Customer’s data accordingly.

8. Personal Data Breach

  1. Varcio will notify the Customer’s security contact without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Where the Customer has told Varcio in writing that it is a regulated entity with a shorter regulatory reporting period, Varcio will use reasonable efforts to notify it in time for the Customer to meet that period.
  2. The notice will describe, as far as then known: the nature of the breach and when it occurred; the categories and approximate number of Data Principals and records; the likely consequences; the measures taken or proposed; and a contact. Varcio will add detail as it learns it.
  3. Varcio will cooperate with the Customer’s investigation and with the Customer’s notices to the Data Protection Board of India, to affected Data Principals, and to any other authority.
  4. Varcio reports cyber incidents to the Indian Computer Emergency Response Team (CERT-In) as the law requires. Varcio’s process is documented in its Personal Data Breach Response Procedure, which it will make available to the Customer on request.

9. Data Principal requests

If Varcio receives a request from a Data Principal about Customer Personal Data, it will refer the person to the Customer and will not respond on the Customer’s behalf unless the Customer asks it to. Taking into account the nature of the processing, Varcio will give the Customer reasonable assistance, by product features (including export, correction and deletion) or on request, so the Customer can meet its obligations on access, correction, erasure and grievance redressal.

10. Assistance and records

Varcio will give the Customer the information reasonably needed to show compliance with this DPA and to carry out any data-protection impact assessment or audit the Customer or a regulator requires, and will keep records of the processing it carries out for the Customer.

11. Audit

  1. Varcio will make available its current security documentation, policies and any independent audit reports it holds, and will answer reasonable security questionnaires.
  2. If that is not enough, the Customer may audit Varcio’s compliance with this DPA once a year, or after a Personal Data Breach, on 30 days’ written notice, during business hours, under confidentiality, and without unreasonable disruption. Where the Customer is a regulated entity, Varcio will give the access to records and premises that its regulator requires of the Customer, and will require its Sub-processors to allow the same where the Customer’s regulator requires it.
  3. Each party bears its own costs, except that Varcio will bear the reasonable cost of an audit that finds a material breach of this DPA.

12. Return and deletion

  1. The Customer may export its data through the product during the term and during the 30-day window that follows a request to close the organisation.
  2. After that window, Varcio deletes Customer Personal Data from its production systems, including uploaded files. Copies in backups and prior file versions expire within 7 days after deletion.
  3. Varcio keeps what the law requires it to keep (for example accounting records, and processing logs for the period the DPDP Law prescribes) and a permanent record that the deletion occurred, and continues to protect it under this DPA.
  4. On request Varcio will confirm the deletion in writing.

13. Liability, term and precedence

Each party’s liability under this DPA is subject to the limitations in the Agreement. This DPA lasts as long as Varcio processes Customer Personal Data. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails. The governing law and courts are those stated in the Agreement.

Annex 1. Details of processing

Subject matter
Providing the Varcio cloud-cost management platform.
Duration
The term of the Agreement, plus the return and deletion period in clause 12.
Nature and purpose
Hosting, storing, analysing and displaying Customer Personal Data; generating recommendations and reports; sending notifications; providing support; securing and backing up the service.
Data Principals
The Customer’s employees, contractors and other users; people named in resource tags, tickets, chat and uploaded documents; and people whose data the Customer otherwise connects.
Categories of Personal Data
Names, work email addresses and other contact details; user and account identifiers; cloud resource owner and team tags; free text in tickets, conversations and documents; IP addresses and device data of users.
Sensitive data
The service is not designed to receive payment-card data, government identifiers or health data. The Customer should not submit them.

Annex 2. Security measures

  • Encryption in transit with TLS 1.2 or later on every public hostname; encryption at rest with AES-256 for the database, object storage and cache.
  • Credentials and integration secrets are additionally encrypted per record with envelope encryption under a customer-managed AWS KMS key.
  • Access control: authenticated sessions, role-based permissions, workspace-scoped queries, multi-factor authentication and passkey options, and single sign-on (SAML and OIDC) where the Customer enables it.
  • Logging and monitoring: an audit log, hash-chained per workspace so tampering is detectable, and infrastructure audit trails; logs are retained for at least one year.
  • Backups: automated database backups with point-in-time recovery for 7 days.
  • Change control, vulnerability disclosure, penetration testing programme and incident response as described in Varcio’s published policies.
  • The current, dated description of these measures is on the Varcio Trust Center, which prevails if it is more specific.

Annex 3. Sub-processors

The current list, with the purpose, the data involved and the region for each, is published on the Varcio Trust Center and is part of this DPA. Changes follow clause 6.

Annex 4. Hosting location

The AWS region that hosts Customer Personal Data on the effective date is stated on the Varcio Trust Center under “Data residency”. Clause 7 applies to any change.

11Document index

These policies are shared with customers and prospects under NDA. Ask security@varcio.com. The standard Data Processing Agreement is included in this pack and published on the Varcio website; a signed copy is available on request.

Policy documents
DocumentCoversLast updated
Data retention and deletionRetention windows per data class and the deletion path on termination.September 15, 2026
Incident response planSeverity classification, escalation, and customer notification timelines.September 29, 2026
Personal data breach responseHow a personal-data breach is contained, reported to CERT-In within six hours, and notified to customers, the Data Protection Board and affected people.September 29, 2026
Grievance and data-rights procedureHow privacy requests and complaints are received, verified, answered and escalated, with timelines.September 29, 2026
DPDP and India compliance mapEach requirement of India's data-protection law, CERT-In and sector rules, how it is met, and its honest status.September 29, 2026
Change managementReview, approval and rollback requirements for production change.February 26, 2026
Vulnerability disclosureHow to report a vulnerability and what response to expect.February 26, 2026
Penetration test programmeTesting scope, cadence, and how findings are tracked to closure.February 26, 2026
Uptime SLAAvailability commitment, measurement and service credits.February 22, 2026

12Contacts

Who to contact
ForContact
Security questions, security documents, the DPA, vulnerability reports and privacy grievancessecurity@varcio.com
Product and account supportsupport@varcio.com
Invoices and subscription billingbilling@varcio.com
Data rights requests/privacy-request on the Varcio website
Security & Compliance Pack | Varcio