Transparent, audited, independent. This page covers every layer of our infrastructure โ from data center cages to application runtime.
The facilities that host Credvue infrastructure are certified, guarded, and continuously audited.
Credvue products run on cloud infrastructure platforms with SOC 2 Type II and ISO 27001 certifications. Data-center campuses have dedicated security personnel, biometric access controls, mantraps, and high-resolution CCTV coverage with 90-day retention.
A formal patch-management process identifies missing patches across container hosts, VMs and managed services weekly. Critical CVE fixes roll out within 24 hours; high-severity patches within 7 days. Patch status is tracked per environment and reviewed monthly by the CISO office.
We maintain a documented Incident Response Plan (CSIRT runbook) with clear severity levels, investigation playbooks and communications templates. Tabletop exercises are performed every quarter; post-incident reviews produce action items with 30-day closure SLOs.
Defense in depth from the moment an HTTP request hits the edge all the way through persistence.
All sessions use TLS 1.3 (TLS 1.2 permitted for legacy enterprise clients) with 2,048-bit or stronger keys and ephemeral ECDHE key-exchange for forward secrecy. HSTS with a 2-year max-age protects against downgrade attacks. Custom domains support customer-managed ACM certificates.
A managed Web Application Firewall inspects every request against the OWASP Core Rule Set + Credvue-specific rules. Network ACLs, security groups and L7 firewalls enforce least-privilege ingress. Always-on L3/L4 + L7 DDoS mitigation auto-scales during volumetric attacks.
Engineering follows OWASP ASVS Level 2 checklists. Bi-annual application-security assessments run with CERT-IN empanelled vendors. Static analysis (SAST), Software Composition Analysis (SCA), SBOM generation and Infrastructure-as-Code scanning gate every deploy. A public bug-bounty program runs on our Responsible Disclosure page.
Independent eyes on our stack, continuously.
Quarterly vulnerability scans cover the entire network perimeter, cloud assets and internal services. Results are triaged by the security team; critical and high findings feed the prioritized backlog with remediation SLAs tied to CVSS score.
CERT-IN empanelled, CREST-accredited firms perform gray-box and red-team penetration testing of web apps, mobile apps, APIs and cloud infrastructure twice a year. Remediation re-tests confirm fixes before findings are closed out.
External auditors review and issue SOC 2 Type II, ISO 27001 and PCI DSS Attestation of Compliance annually. Reports and gap-remediation plans are reviewed by the Audit Committee; summary letters are available to customers under NDA via your account manager.
Uptime, redundancy, monitoring and disaster recovery โ architected in from day one.
We target โฅ 99.9% monthly service availability for the core platform. Availability is measured synthetically from 8 global probes and internally via SLO tracking. Public status page displays the last 90 days of incident history.
Purpose-built tooling plus industry-standard APM, log aggregation and metrics platforms monitor application, software and infrastructure performance continuously. On-call engineers are paged via escalation policies for SLO breaches or anomaly alerts.
Every critical service runs across a minimum of three Availability Zones within the primary AWS region. Multi-AZ deployments, cross-AZ load balancing and redundant failover configurations eliminate single points of failure at the compute, storage and networking layers.
Documented DR plans cover application and data recovery across the full stack. Automated continuous backups, cross-region replication and 35-day point-in-time recovery (PITR) allow granular restores within minutes. Full failover fire drills run twice a year with RTO < 4 hours.
Your data stays your data. Access is restricted, audited and never stored on-premises.
Direct access to production databases and data-stores is restricted to named on-call engineers via just-in-time access workflows with short-lived credentials and mandatory MFA. Every query is logged, rate-limited and reviewable in the audit trail.
All customer environments live on AWS cloud infrastructure inside private VPCs with VPC peering where needed. Customer data is never stored on local workstations, laptops or on-premises servers โ including in development, staging and testing environments.
Our Privacy Policy covers categories of data we collect, the legal bases for processing, international data transfers, retention schedules and your rights under DPDP, GDPR and other regimes.
Our security team can share architecture diagrams, Data Protection Impact Assessments (DPIA) and sub-processor lists on request.