Keys you control, data that stays in India.
An organisation policy allows only the Mumbai and Hyderabad regions, so nothing can be created elsewhere by accident. Databases and storage are encrypted with customer-managed keys per class of data, and the most sensitive fields, like PAN and bank accounts, are encrypted again in the application.
- Regions
- ap-south-1 and ap-south-2, enforced by SCP
- At rest
- KMS customer-managed keys, rotated yearly
- Fields
- PAN and bank details encrypted in the app
- Storage
- S3 Block Public Access, organisation-wide
- In transit
- TLS everywhere, old ciphers off
We ship our own products