1At a glance
This pack answers the questions a security or procurement reviewer asks first about Varcio: where data is stored, who else processes it, how long it is kept, what is and is not certified, and what is committed on availability and support. It is generated from the same facts that drive the public Trust Center, so the two agree.
- Hosting region
- AWS ap-south-1 (Mumbai, India)
- Encryption at rest
- AES-256
- Encryption in transit
- TLS 1.2 or later
- Backups
- 7-day point-in-time recovery
- Uptime commitment
- 99.9% monthly uptime
- SOC 2 Type II
- Readiness programme. Control mapping and evidence collection in progress. Not yet audited.
- ISO 27001
- Not started. Planned after SOC 2. No certification is held.
- Sub-processors
- 8 listed under Sub-processors and AI data flow
2Data residency and cross-border transfer
| Item | Position | Detail |
|---|---|---|
| Primary region | AWS ap-south-1 (Mumbai, India) | Application, database, cache, object storage and encryption keys. |
| Database | Amazon RDS PostgreSQL, single-AZ | Encrypted at rest; automated backups with point-in-time recovery. |
| Backups | 7-day point-in-time recovery | Retained in-region. Deleted data can remain in backups for up to 7 days. |
| Encryption at rest | AES-256 | The database and object storage are encrypted with a customer-managed AWS KMS key in Mumbai, and the cache is encrypted at rest. Credentials and integration secrets are additionally wrapped per record with the same key (envelope encryption). |
| Encryption in transit | TLS 1.2 or later | TLS 1.0 and 1.1 are refused. HSTS is sent on every public hostname. The link to the cache is TLS-encrypted too. |
| Tenant isolation | Workspace-scoped at query level | Enforced in storage and query paths, not only in the UI. The only cross-workspace reads are the aggregate FinOps-score percentile (at least five peers) and the opt-in benchmark network. |
Encryption in detail
| Item | Position |
|---|---|
| Mode | Envelope encryption with per-record data keys |
| Key wrapping | Customer-managed AWS KMS key (ap-south-1) wraps the data keys for credentials and integration secrets |
| Database and object storage | Encrypted with the same customer-managed AWS KMS key (ap-south-1) |
India (DPDP Act 2023) position
Customer data is stored and processed in AWS ap-south-1 (Mumbai, India), except AI inference, which runs on AWS Bedrock in us-east-1 (United States) for now. Sub-processors outside India are listed below with their regions. India's DPDP Act 2023 allows transfer abroad unless the Government restricts a named country under Section 16(1); no country has been restricted. The Act's core duties, including its transfer rules, take effect on 13 May 2027.
- The Act imposes no general data-localisation duty on ordinary data fiduciaries. Two provisions can require India residency: Rule 13(4), for Significant Data Fiduciaries and only for data the Government specifies (no list or designation has been published), and Section 16(2), which preserves stricter sector rules.
- RBI's 2018 payment-data circular applies to authorised payment systems and listed banks, and reaches their vendors through them. This platform stores no card, bank-account or payment-credential data; Stripe and Razorpay hold it.
- Customers regulated by SEBI, or buying under government cloud-procurement rules, can be required to use India-resident, MeitY-empanelled hosting; banks, NBFCs and insurers usually require a data-location clause by contract. Hosting in Mumbai meets an India-residency requirement; whether a given hosting provider is MeitY-empanelled is a separate procurement check that depends on the buyer's rules.
- There is no EU data residency option today, and customers cannot choose a region. Every customer is served from Mumbai, India; AI inference moves back to Mumbai once AWS raises the Bedrock capacity there.
Position statement for security review, not legal advice. Reviewed when hosting changes or a restricted-country list, a Rule 15 order or a Rule 13(4) list is published.
3Security controls
Identity and access
| Control | How it works |
|---|---|
| Single sign-on | SAML 2.0 and OIDC on the Enterprise plan. Password sign-in can be blocked when SSO is enforced, with a break-glass exception. |
| SCIM provisioning | SCIM 2.0 Users and Groups with explicit group-to-role mapping, on the Enterprise plan. |
| Multi-factor authentication | TOTP with recovery codes, and WebAuthn passkeys. An organization can require MFA: members are blocked until they enrol, and personal API keys are refused until their owner has enrolled. |
| Re-authentication | SSO configuration, network policy, session revocation and organization closure need a recent sign-in confirmation. |
| IP allowlist | An organization allowlist, enforced on sessions, API keys and sign-in (not on SCIM). |
| Roles | Admin and member roles on every plan. Custom scoped roles and business-unit row scopes on the Enterprise plan, enforced on every cost query. |
| Sessions | Each session can be revoked, or all of them at once. |
Logging and monitoring
| Control | How it works |
|---|---|
| Audit log | Actor, action, target and timestamp for administrative actions, hash-chained per workspace so tampering is detectable, with a verify endpoint. |
| Audit export | CSV or JSON, up to 20,000 rows per export, within your plan's retention window. Streaming to a SIEM is not yet available. |
Change management
| Control | How it works |
|---|---|
| Production change | Reviewed pull requests; CI must pass before merge; migrations are reviewed for backward compatibility; schema, auth and execution-path changes need a rollback plan. |
How a cloud connection is handled
- Encrypt on ingest. Credentials and integration secrets are encrypted before they are persisted.
- Validate read plane. Provider read access is verified before any telemetry or compliance processing runs.
- Gate write plane. Write actions stay blocked until permissions and approval requirements are satisfied.
- Audit and retain. Sensitive operations are logged, and audit entries are kept for your plan's retention window.
Audit logging is enforced: Actor, action, target and timestamp recorded, hash-chained per workspace so tampering is detectable.
4Data lifecycle and retention
Audit log, by plan
| Plan | Readable and exportable | Not deleted before |
|---|---|---|
| Explorer | Not included | 1 year |
| Pro | 90 days | 1 year |
| Business | 1 year | 1 year |
| Enterprise | 3 years | 3 years |
Other data classes
| Data class | Retention |
|---|---|
| Report exports | Expire after 7 days |
| Ended sign-in sessions | Pruned after 2 days, when the person next opens their sessions, for sign-in security |
| Recognised devices | Pruned after 180 days, at the person's next sign-in, for sign-in security |
| Event outbox and delivery telemetry | 90 days |
| Database backups | 7-day point-in-time recovery. Deleted data can remain in backups for up to 7 days. |
| Uploaded files (support attachments, contract documents) | Deleted with the organization. Earlier file versions expire from object storage within 7 days. |
| Invoices, payments and partner ledgers | Kept as accounting records. The link to the organization is removed when it is deleted. |
| Incident records and postmortems | 24 months. This is a process commitment, not an automated deletion. |
Closing an organization
- Request. An organization administrator types the organization name, gives a reason and re-authenticates. Every administrator is emailed.
- Export window. Nothing is deleted for 30 days and any administrator can cancel. Billing stops: the subscription does not renew while the request stands.
- Purge. The organization's database records and uploaded files are deleted, and a permanent purge record is kept. The requester is emailed its reference.
5Sub-processors and AI data flow
Third parties the platform itself uses to deliver the service, for every customer.
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services | Hosting, database, object storage, key management | All customer data at rest and in transit | ap-south-1 (Mumbai, India) |
| AWS Bedrock | AI inference for the Apex assistant, the Communications agent and in-product AI features, on every plan | Prompt context assembled from workspace data, and the text of emails the Communications agent answers | us-east-1 (N. Virginia, United States), until Mumbai capacity is available |
| Stripe | Subscription billing and payment processing | Billing contact and payment instrument (held by Stripe) | United States |
| Razorpay | Subscription billing for Indian customers | Billing contact and payment instrument (held by Razorpay) | India |
| Amazon SES | Transactional and notification email (sign-in codes, invitations, alerts, billing notices) | Recipient email address and message content | ap-south-1 (Mumbai, India) |
| Microsoft (Graph API) | The Communications Agent's mailbox, and a fallback if Amazon SES cannot deliver a message | Recipient email address and message content | Per Microsoft 365 tenant |
| GitHub | Sign-in, and pull request cost analysis when the GitHub App is installed | OAuth identity; repository content the App is granted | United States |
| Sign-in (OAuth) | OAuth identity (email, subject identifier) | United States |
Integrations you turn on
These receive data only when your organization connects them, with credentials you supply.
| Integration | What is sent |
|---|---|
| Slack and Microsoft Teams | Alert and approval messages to the channels you choose |
| PagerDuty | Incident events for the services you map |
| Jira, Linear and ServiceNow | Tickets and change requests you raise, and their status |
| Datadog | Read-only usage and cost queries with your API key |
| AI provider accounts (OpenAI, Anthropic, Google Gemini, Groq) | Read-only usage and billing queries with your key, for AI cost tracking |
| Your cloud accounts (AWS, Azure, Google Cloud, Oracle Cloud) | Read calls within the role you grant; write calls only after approval |
What the AI assistant sends to a model
Every plan uses AWS Bedrock. Model calls run in us-east-1 (United States) until AWS raises Bedrock capacity in Mumbai; nothing is stored there, and no other model provider is used. Knowledge-base search is embedded inside the platform, and outside web research is switched off.
- Always sent
- User message, System instructions
- Sent when relevant to the question
- Workspace snapshot, Memory context, Knowledge snippets, Custom instructions
6Compliance programme
Status as it stands today. Nothing is described as certified until an auditor's report exists.
| Programme | Status | Detail |
|---|---|---|
| SOC 2 Type II | In progress: Readiness programme | Control mapping and evidence collection in progress. Not yet audited. |
| ISO 27001 | Not started: Not started | Planned after SOC 2. No certification is held. |
| Penetration testing | In progress: Programme defined | Scope and reporting cadence documented; a summary is published once a test completes. |
| Vulnerability disclosure | Done: Published | Coordinated disclosure policy with a named security contact. |
| Audit logging | Done: Enforced | Actor, action, target and timestamp recorded, hash-chained per workspace so tampering is detectable. |
Known limitations
Stated plainly so a reviewer does not have to ask.
- No third-party penetration test report exists yet. The programme is defined.
- No VPAT or independent accessibility audit is published. The product is designed to WCAG 2.2 level AA.
- Customers cannot choose a data region. Every customer is served from the region shown above.
- The database is single-AZ with 7-day point-in-time recovery. There is no cross-region recovery.
- Legal hold is not supported.
- Audit-log streaming to a SIEM is not yet available. Audit logs can be exported as CSV or JSON.
- The standard Data Processing Agreement is published and applies to all customers. Customers with specific requirements can ask for changes, which we review with counsel.
7Availability and support
- Commitment
- 99.9% monthly uptime
- Scope
- The API and web control plane for paid plans. Maintenance announced at least 48 hours ahead is excluded.
- Applies to
- Paid plans. Preview, beta and sandbox environments are not covered.
- What counts as downtime
- Minutes when the production API or web control plane is unavailable to all customer tenants because of a failure of the service.
| Monthly uptime | Service credit |
|---|---|
| Below 99.9%, at or above 99.0% | 10% of the monthly platform fee |
| Below 99.0% | 25% of the monthly platform fee |
Request a credit within 30 days after the month, with your organization and the incident times. Credits apply to future invoices.
Include your organization identifier, the incident timestamps in UTC, the affected endpoints or workflows. We review platform telemetry and incident records and respond within 10 business days.
Exclusions
- Customer-side misconfiguration, credential revocation or IAM policy changes
- Outages of a third-party cloud provider (AWS, Azure, Google Cloud) outside our control
- Customer network problems, ISP failures, or browser and device faults
- Force majeure
- Suspension or rate limits applied for abuse, non-payment or a terms violation
Support response targets
| Support | Plans | Named engineer |
|---|---|---|
| Standard | Explorer, Pro | - |
| Priority | Business | - |
| Enterprise | Enterprise | Included |
Response targets per priority are read from the running service. They were not available when this pack was generated; generate it again, or ask the support team for the current figures.
8Incident and breach response
| Severity | Meaning |
|---|---|
| SEV-1 | Multi-tenant outage, active security incident, or confirmed data exposure. |
| SEV-2 | Major degradation, failed execution controls, or sustained customer impact. |
| SEV-3 | Localized defect with an available workaround. |
Response workflow
- Detect through automated health checks, alerts or a customer report.
- Triage severity within 15 minutes.
- Assign an incident commander and a communications owner.
- Contain the impact and apply immediate mitigations.
- Publish a status update to the public status page and customer channels.
- Resolve, validate recovery, and publish a closure update.
- Complete a postmortem within 5 business days for SEV-1 and SEV-2.
Communication targets
- Severity is triaged within 15 minutes.
- First public update within 30 minutes for SEV-1 and SEV-2.
- Updates every 30 minutes until the incident is stable.
- The closure update states the root cause, the remediation and the prevention actions.
- A postmortem is completed within 5 business days for SEV-1 and SEV-2.
Personal-data breaches
A separate Personal Data Breach Response Procedure covers breaches of personal data. We report reportable incidents to India's CERT-In within six hours of noticing them; we notify affected customers without undue delay and within 48 hours at the latest (our internal target is 24 hours); and where we are the data fiduciary we notify the Data Protection Board and affected people as the DPDP Rules require from 13 May 2027. The procedure is shared under NDA on request.
Reporting a vulnerability
Report a vulnerability to the security contact with reproduction steps, impact and the affected component. We acknowledge within 1 business day and triage severity within 3 business days.
Security research is authorized when performed in good faith and without data exfiltration, service disruption or privacy violations.
Out of scope: social engineering and physical attacks; denial-of-service testing against production; vulnerabilities that need compromised third-party credentials.
9Data rights and grievance
| Right | How |
|---|---|
| Access | Each person downloads their own profile, settings, sessions, support tickets and audit activity from Settings, with a summary of the sub-processors that may receive it. Anyone can also ask through the privacy request form. Administrators export cost data and audit logs. |
| Correction | Profile fields are editable in the app; other corrections on request. |
| Erasure | Administrators remove members, or close the organization from the Organization console: nothing is deleted for 30 days, then its records and uploaded files are deleted. Anyone else can ask through the privacy request form. |
| Grievance | Use the privacy request form. You get a reference number and a respond-by date straight away. We answer within 30 days; the DPDP Rules allow at most 90. |
| Nomination and withdrawing consent | Use the privacy request form. It is as easy to withdraw consent as it was to give it. |
To make a request, including for nomination, withdrawal of consent or anything else, use the privacy request form (/privacy-request on the Varcio website). The confirmation gives a reference number and the date by which we will respond: within 30 days, and never more than the 90 days the DPDP Rules allow. Or email support@varcio.com with the subject "Privacy request". Report a security concern to security@varcio.com.
10Data Processing Agreement
Standard terms, version 1.0, effective 2026-09-29. This Data Processing Agreement (the “DPA”) forms part of the agreement between Varcio (“Varcio”, “we”) and the customer that has subscribed to the Varcio service (the “Customer”) (together, the “Agreement”). It applies to the extent Varcio processes Personal Data on the Customer’s behalf.
1. Definitions
“Personal Data”, “Data Fiduciary”, “Data Processor”, “Data Principal”, “Personal Data Breach” and “processing” have the meanings given in the Digital Personal Data Protection Act 2023 and its Rules (together, the “DPDP Law”). “Data Protection Law” means the DPDP Law and any other law on the protection of personal data that applies to the processing under this DPA, including the Information Technology Act 2000 and the rules under it while they remain in force.
“Customer Personal Data” means Personal Data contained in content the Customer or its users submit to, connect to, or generate in the service: for example cloud inventory and billing metadata, resource tags, support tickets, assistant conversations, and uploaded documents. “Sub-processor” means a third party Varcio engages to process Customer Personal Data.
2. Roles and scope
- For Customer Personal Data, the Customer is the Data Fiduciary and Varcio is its Data Processor. Varcio processes it only to provide, secure, support and bill for the service, and as the Customer instructs.
- For personal data Varcio collects for its own purposes (for example account sign-in details, billing contacts, and website and status-page visitors), Varcio is a Data Fiduciary and handles it under its Privacy Policy. This DPA does not govern that data.
- The Customer is responsible for having a lawful basis to give Varcio Customer Personal Data, for the accuracy of the instructions it gives, and for the notices and consents its own Data Principals are owed.
3. Instructions
Varcio processes Customer Personal Data on the Customer’s documented instructions. The Agreement, this DPA, and the Customer’s use and configuration of the service are its complete instructions. Varcio will tell the Customer if it believes an instruction infringes Data Protection Law. Varcio will not use Customer Personal Data to train machine-learning models, and will not sell it or use it for advertising.
4. Confidentiality and personnel
Varcio limits access to Customer Personal Data to personnel who need it to provide the service, and binds them to written confidentiality obligations that continue after their engagement ends.
5. Security safeguards
Varcio maintains reasonable security safeguards to protect Customer Personal Data, including those in Annex 2, and will not materially reduce them during the term. These are intended to meet the security safeguards in DPDP Rule 6, including encryption, access control, logging and monitoring, and backups for continued processing, and the retention of logs and processing records for at least one year.
6. Sub-processors
- The Customer gives Varcio general authorisation to engage the Sub-processors listed on the Varcio Trust Center at the date of the Agreement and in Annex 3.
- Varcio will give at least 30 days’ notice of a new Sub-processor, or of a change to the country in which a Sub-processor processes Customer Personal Data, by updating the Trust Center and emailing the Customer’s registered administrators.
- The Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve it; if they cannot, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the remainder of the term.
- Varcio imposes on each Sub-processor written obligations no less protective than this DPA and remains responsible for their performance.
7. Data location and transfers
- Customer Personal Data is hosted in the AWS region stated on the Trust Center on the effective date of the Agreement (Annex 4). Varcio will give at least 30 days’ notice before moving it to a different country, except where a move is needed to comply with law or to respond to an emergency, in which case Varcio will notify the Customer as soon as it can.
- Where processing involves a transfer outside India, Varcio will comply with the DPDP Law, including any restriction the Central Government notifies on transfer to a country or territory, and will tell the Customer if a restriction affects the service.
- Where the Customer is subject to a sector rule that requires data to be held in India, the parties will record that requirement in a signed order, and Varcio will host the Customer’s data accordingly.
8. Personal Data Breach
- Varcio will notify the Customer’s security contact without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Where the Customer has told Varcio in writing that it is a regulated entity with a shorter regulatory reporting period, Varcio will use reasonable efforts to notify it in time for the Customer to meet that period.
- The notice will describe, as far as then known: the nature of the breach and when it occurred; the categories and approximate number of Data Principals and records; the likely consequences; the measures taken or proposed; and a contact. Varcio will add detail as it learns it.
- Varcio will cooperate with the Customer’s investigation and with the Customer’s notices to the Data Protection Board of India, to affected Data Principals, and to any other authority.
- Varcio reports cyber incidents to the Indian Computer Emergency Response Team (CERT-In) as the law requires. Varcio’s process is documented in its Personal Data Breach Response Procedure, which it will make available to the Customer on request.
9. Data Principal requests
If Varcio receives a request from a Data Principal about Customer Personal Data, it will refer the person to the Customer and will not respond on the Customer’s behalf unless the Customer asks it to. Taking into account the nature of the processing, Varcio will give the Customer reasonable assistance, by product features (including export, correction and deletion) or on request, so the Customer can meet its obligations on access, correction, erasure and grievance redressal.
10. Assistance and records
Varcio will give the Customer the information reasonably needed to show compliance with this DPA and to carry out any data-protection impact assessment or audit the Customer or a regulator requires, and will keep records of the processing it carries out for the Customer.
11. Audit
- Varcio will make available its current security documentation, policies and any independent audit reports it holds, and will answer reasonable security questionnaires.
- If that is not enough, the Customer may audit Varcio’s compliance with this DPA once a year, or after a Personal Data Breach, on 30 days’ written notice, during business hours, under confidentiality, and without unreasonable disruption. Where the Customer is a regulated entity, Varcio will give the access to records and premises that its regulator requires of the Customer, and will require its Sub-processors to allow the same where the Customer’s regulator requires it.
- Each party bears its own costs, except that Varcio will bear the reasonable cost of an audit that finds a material breach of this DPA.
12. Return and deletion
- The Customer may export its data through the product during the term and during the 30-day window that follows a request to close the organisation.
- After that window, Varcio deletes Customer Personal Data from its production systems, including uploaded files. Copies in backups and prior file versions expire within 7 days after deletion.
- Varcio keeps what the law requires it to keep (for example accounting records, and processing logs for the period the DPDP Law prescribes) and a permanent record that the deletion occurred, and continues to protect it under this DPA.
- On request Varcio will confirm the deletion in writing.
13. Liability, term and precedence
Each party’s liability under this DPA is subject to the limitations in the Agreement. This DPA lasts as long as Varcio processes Customer Personal Data. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails. The governing law and courts are those stated in the Agreement.
Annex 1. Details of processing
- Subject matter
- Providing the Varcio cloud-cost management platform.
- Duration
- The term of the Agreement, plus the return and deletion period in clause 12.
- Nature and purpose
- Hosting, storing, analysing and displaying Customer Personal Data; generating recommendations and reports; sending notifications; providing support; securing and backing up the service.
- Data Principals
- The Customer’s employees, contractors and other users; people named in resource tags, tickets, chat and uploaded documents; and people whose data the Customer otherwise connects.
- Categories of Personal Data
- Names, work email addresses and other contact details; user and account identifiers; cloud resource owner and team tags; free text in tickets, conversations and documents; IP addresses and device data of users.
- Sensitive data
- The service is not designed to receive payment-card data, government identifiers or health data. The Customer should not submit them.
Annex 2. Security measures
- Encryption in transit with TLS 1.2 or later on every public hostname; encryption at rest with AES-256 for the database, object storage and cache.
- Credentials and integration secrets are additionally encrypted per record with envelope encryption under a customer-managed AWS KMS key.
- Access control: authenticated sessions, role-based permissions, workspace-scoped queries, multi-factor authentication and passkey options, and single sign-on (SAML and OIDC) where the Customer enables it.
- Logging and monitoring: an audit log, hash-chained per workspace so tampering is detectable, and infrastructure audit trails; logs are retained for at least one year.
- Backups: automated database backups with point-in-time recovery for 7 days.
- Change control, vulnerability disclosure, penetration testing programme and incident response as described in Varcio’s published policies.
- The current, dated description of these measures is on the Varcio Trust Center, which prevails if it is more specific.
Annex 3. Sub-processors
The current list, with the purpose, the data involved and the region for each, is published on the Varcio Trust Center and is part of this DPA. Changes follow clause 6.
Annex 4. Hosting location
The AWS region that hosts Customer Personal Data on the effective date is stated on the Varcio Trust Center under “Data residency”. Clause 7 applies to any change.
11Document index
These policies are shared with customers and prospects under NDA. Ask security@varcio.com. The standard Data Processing Agreement is included in this pack and published on the Varcio website; a signed copy is available on request.
| Document | Covers | Last updated |
|---|---|---|
| Data retention and deletion | Retention windows per data class and the deletion path on termination. | September 15, 2026 |
| Incident response plan | Severity classification, escalation, and customer notification timelines. | September 29, 2026 |
| Personal data breach response | How a personal-data breach is contained, reported to CERT-In within six hours, and notified to customers, the Data Protection Board and affected people. | September 29, 2026 |
| Grievance and data-rights procedure | How privacy requests and complaints are received, verified, answered and escalated, with timelines. | September 29, 2026 |
| DPDP and India compliance map | Each requirement of India's data-protection law, CERT-In and sector rules, how it is met, and its honest status. | September 29, 2026 |
| Change management | Review, approval and rollback requirements for production change. | February 26, 2026 |
| Vulnerability disclosure | How to report a vulnerability and what response to expect. | February 26, 2026 |
| Penetration test programme | Testing scope, cadence, and how findings are tracked to closure. | February 26, 2026 |
| Uptime SLA | Availability commitment, measurement and service credits. | February 22, 2026 |
12Contacts
| For | Contact |
|---|---|
| Security questions, security documents, the DPA, vulnerability reports and privacy grievances | security@varcio.com |
| Product and account support | support@varcio.com |
| Invoices and subscription billing | billing@varcio.com |
| Data rights requests | /privacy-request on the Varcio website |