Trust

Security

Our platforms carry payroll, invoices and policies across borders. Here is how we protect them, in plain language.

Effective

1.Our approach

Our platforms move payroll, invoices, insurance policies and compliance evidence across borders. Security is not a feature we add; it is the condition for the business to exist. As a family-owned company, the people accountable for security have their name on the door and a horizon measured in generations, not quarters.

This page describes the controls we operate today. Customers under NDA can request our full security package, including audit reports and penetration-test summaries, through their account team.

2.Infrastructure

  • Hosted on tier-one cloud providers in ISO 27001 and SOC 2 certified facilities, with production environments in India and the United States.
  • Infrastructure is defined as code, reviewed before deployment and rebuilt from known-good images rather than patched in place.
  • Production, staging and development are fully separated; no customer data leaves production.
  • Network access is deny-by-default with segmented private networks and no direct inbound access to data stores.

3.Encryption

  • All traffic is encrypted in transit with TLS 1.2 or higher; HSTS is enforced on every public domain.
  • Data at rest is encrypted with AES-256, including databases, backups and object storage.
  • Encryption keys are managed in a hardware-backed key management service, rotated on a schedule and never stored alongside the data they protect.
  • Secrets are injected at runtime from a managed vault and are never committed to source control.

4.Access control

  • Customer access is role-based with per-organization data scoping enforced in every query, so one customer can never read another's records.
  • Employee access to production follows least privilege, requires hardware-key multi-factor authentication and is granted just-in-time for a logged, time-boxed session.
  • Access reviews run quarterly; departures are deprovisioned the same day.
  • Portal sessions use secure, HttpOnly cookies and expire after inactivity.

5.Secure development

  • Every change is peer-reviewed and passes automated static analysis, dependency vulnerability scanning and tests before it can ship.
  • Dependencies are pinned and monitored; critical vulnerabilities are patched within 72 hours.
  • Public forms use server-side validation, bot traps and rate limiting; user input is never trusted.
  • Independent penetration tests are performed at least annually and after significant architectural change.

6.Monitoring and response

  • Centralized, tamper-evident logging of authentication, administrative and data-access events, retained for 12 months.
  • Automated alerting on anomalous access, failed authentication patterns and configuration drift, monitored around the clock.
  • A documented incident-response plan with defined severity levels, on-call rotation and post-incident review.
  • Affected customers are notified of a confirmed breach of their data without undue delay and within 72 hours of confirmation.

7.Resilience and continuity

  • Databases are replicated across availability zones with point-in-time recovery.
  • Encrypted backups are taken daily, stored in a separate region and restore-tested quarterly.
  • Recovery objectives: RPO under 1 hour and RTO under 4 hours for core platform services.

8.Compliance

Our controls are mapped to SOC 2 Trust Services Criteria and ISO/IEC 27001, and our data handling meets GDPR, India's DPDP Act and applicable US state privacy laws. Our Compliance Exchange is built by the same team that runs our own program, and we hold ourselves to the standards we help customers meet. Certification status and audit reports are available to customers and prospects under NDA.

9.What we ask of you

Security is shared. Customers and users are responsible for:

  • Keeping credentials confidential and enabling multi-factor authentication where offered.
  • Granting platform roles on a least-privilege basis and removing users who leave.
  • Ensuring the data they load is lawfully obtained and accurate.
  • Reporting suspected compromise to us immediately.

10.Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability in any Transnational AI system, report it through the contact form using the Support category with the topic Security, including enough detail to reproduce the issue. Please give us a reasonable time to fix it before public disclosure, do not access or modify data that is not yours, and do not run denial-of-service or social-engineering tests.

We acknowledge reports within two business days, keep you informed of progress, and will not pursue legal action against researchers who follow these guidelines in good faith.

11.Contact

Security questions, due-diligence questionnaires and requests for our security package can be sent through the contact form on our website or by post to Transnational AI, Attn: Security, at the headquarters address on the Contact page.