Legal

Security

Last updated: June 27, 2026

Security is foundational to AramGRC. As a governance, risk and compliance platform, we hold ourselves to the standards we help our customers meet. This page summarises how we protect your data.

Infrastructure and hosting

The Services run on reputable cloud infrastructure with managed database and authentication services. Production environments are logically separated from development and testing.

Encryption

Data is encrypted in transit using TLS, and encrypted at rest using industry-standard algorithms.

Access control

We apply role-based access control and the principle of least privilege. Access to production systems is restricted to authorised personnel and protected by strong authentication. Within the platform, customer data is isolated and access is enforced by row-level security so one organisation cannot access another's data.

Application security

We follow secure development practices, manage dependencies for known vulnerabilities, and apply security review to changes. Authentication and session management follow current best practice.

Monitoring and logging

We log key system and security events and monitor for anomalous activity to support detection and investigation.

Resilience and backups

We maintain backups and recovery processes designed to protect against data loss and support service continuity.

Vulnerability management

We perform ongoing vulnerability management and welcome external reports through our Responsible Disclosure policy.

Sub-processors

We use a limited set of vetted sub-processors (such as cloud hosting and email delivery) bound by appropriate data protection and security obligations. A current list is available on request.

Incident response

We maintain an incident response process. In the event of a personal data breach, we will notify affected parties and authorities as required by applicable law, including the DPDP Act.

Personnel

Our personnel are subject to confidentiality obligations and receive security and data protection awareness guidance appropriate to their roles.

Frameworks

Our security and AI governance practices are designed with reference to recognised frameworks, including ISO/IEC 27001, ISO/IEC 42001 and India's DPDP Act. We are not currently certified against these standards; we use them as the design reference for our controls and will update this page if our certification status changes.

Contact

Security questions or reports: contact@aramgrc.com.


Questions? Contact contact@aramgrc.com. Or visit our contact page.

WhatsApp