Infrastructure Deep-Dive

Data-Center &

Transparent, audited, independent. This page covers every layer of our infrastructure โ€” from data center cages to application runtime.

Uptime
0
Last 12 months
Backups
0
PITR retention
TLS Keysize
0
Bits ยท TLS 1.3
App Sec Reviews
0
By 3rd-party firms
Data-Center Protections

Physical & Data-Center Protections

The facilities that host Credvue infrastructure are certified, guarded, and continuously audited.

A

Physical Security

Credvue products run on cloud infrastructure platforms with SOC 2 Type II and ISO 27001 certifications. Data-center campuses have dedicated security personnel, biometric access controls, mantraps, and high-resolution CCTV coverage with 90-day retention.

B

Patch Management

A formal patch-management process identifies missing patches across container hosts, VMs and managed services weekly. Critical CVE fixes roll out within 24 hours; high-severity patches within 7 days. Patch status is tracked per environment and reviewed monthly by the CISO office.

C

Security Incident Response

We maintain a documented Incident Response Plan (CSIRT runbook) with clear severity levels, investigation playbooks and communications templates. Tabletop exercises are performed every quarter; post-incident reviews produce action items with 30-day closure SLOs.

Application Security

Application-Level Security

Defense in depth from the moment an HTTP request hits the edge all the way through persistence.

A

In-Transit Encryption

All sessions use TLS 1.3 (TLS 1.2 permitted for legacy enterprise clients) with 2,048-bit or stronger keys and ephemeral ECDHE key-exchange for forward secrecy. HSTS with a 2-year max-age protects against downgrade attacks. Custom domains support customer-managed ACM certificates.

B

WAF, Firewalls & DDoS

A managed Web Application Firewall inspects every request against the OWASP Core Rule Set + Credvue-specific rules. Network ACLs, security groups and L7 firewalls enforce least-privilege ingress. Always-on L3/L4 + L7 DDoS mitigation auto-scales during volumetric attacks.

C

Secure SDLC

Engineering follows OWASP ASVS Level 2 checklists. Bi-annual application-security assessments run with CERT-IN empanelled vendors. Static analysis (SAST), Software Composition Analysis (SCA), SBOM generation and Infrastructure-as-Code scanning gate every deploy. A public bug-bounty program runs on our Responsible Disclosure page.

Audits & Testing

Audits, Assessments & Pen Testing

Independent eyes on our stack, continuously.

A

Vulnerability Assessment

Quarterly vulnerability scans cover the entire network perimeter, cloud assets and internal services. Results are triaged by the security team; critical and high findings feed the prioritized backlog with remediation SLAs tied to CVSS score.

B

Penetration Testing

CERT-IN empanelled, CREST-accredited firms perform gray-box and red-team penetration testing of web apps, mobile apps, APIs and cloud infrastructure twice a year. Remediation re-tests confirm fixes before findings are closed out.

C

External Audit & Certification

External auditors review and issue SOC 2 Type II, ISO 27001 and PCI DSS Attestation of Compliance annually. Reports and gap-remediation plans are reviewed by the Audit Committee; summary letters are available to customers under NDA via your account manager.

Resiliency

Resiliency & Availability

Uptime, redundancy, monitoring and disaster recovery โ€” architected in from day one.

A

99.9% Uptime Target

We target โ‰ฅ 99.9% monthly service availability for the core platform. Availability is measured synthetically from 8 global probes and internally via SLO tracking. Public status page displays the last 90 days of incident history.

B

24ร—7ร—365 Monitoring

Purpose-built tooling plus industry-standard APM, log aggregation and metrics platforms monitor application, software and infrastructure performance continuously. On-call engineers are paged via escalation policies for SLO breaches or anomaly alerts.

C

Data Center Redundancy

Every critical service runs across a minimum of three Availability Zones within the primary AWS region. Multi-AZ deployments, cross-AZ load balancing and redundant failover configurations eliminate single points of failure at the compute, storage and networking layers.

D

Disaster Recovery & PITR

Documented DR plans cover application and data recovery across the full stack. Automated continuous backups, cross-region replication and 35-day point-in-time recovery (PITR) allow granular restores within minutes. Full failover fire drills run twice a year with RTO < 4 hours.

Data Privacy

Data Privacy & Access

Your data stays your data. Access is restricted, audited and never stored on-premises.

A

Restricted Access to Datastores

Direct access to production databases and data-stores is restricted to named on-call engineers via just-in-time access workflows with short-lived credentials and mandatory MFA. Every query is logged, rate-limited and reviewable in the audit trail.

B

No Local / On-Premises Storage

All customer environments live on AWS cloud infrastructure inside private VPCs with VPC peering where needed. Customer data is never stored on local workstations, laptops or on-premises servers โ€” including in development, staging and testing environments.

C

Privacy Policy

Our Privacy Policy covers categories of data we collect, the legal bases for processing, international data transfers, retention schedules and your rights under DPDP, GDPR and other regimes.

Need more technical details?

Our security team can share architecture diagrams, Data Protection Impact Assessments (DPIA) and sub-processor lists on request.