SECURITY

Security is a substrate,not a setting.

This page describes our approach to information security, privacy and compliance, and the practices Janaka AI Technologies maintains across its products and infrastructure.

This page is maintained by Janaka AI Technologies to answer common security and privacy questions about our Services and does not constitute an independent certification.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest, and modern key management for every service.

Zero-trust access

SSO, MFA, least-privilege access, and continuous session verification across every product.

Continuous monitoring

24/7 observability, anomaly detection, and audit logging across the platform.

Resilient infrastructure

High-availability architecture, isolated environments, and tested disaster-recovery playbooks.

Secure SDLC

Threat modelling, code review, static/dynamic analysis, and dependency scanning in every release.

Incident response

Documented runbooks, defined SLAs and lawful, timely notifications to customers and regulators.

COMPLIANCE

Aligned with Indian and global regulations.

Digital Personal Data Protection Act, 2023 (India)

Janaka's data-handling practices are designed in line with the DPDP Act, 2023 — including lawful basis for processing, consent management, purpose limitation, storage limitation, breach notification and Data Principal rights. See our Privacy Policy for the notice required under the Act.

Information Technology Act, 2000 & SPDI Rules

We follow the “reasonable security practices and procedures” standard under Section 43A of the IT Act and the SPDI Rules, 2011, including ISO/IEC 27001-aligned controls.

Sectoral standards

For healthcare workloads (Janaka Healthcare) we align with the Ayushman Bharat Digital Mission (ABDM) health data management framework. For financial workloads, we align with applicable RBI IT governance and outsourcing directions.

International

For customers in the EEA/UK, we support GDPR-consistent contractual safeguards, including Standard Contractual Clauses (SCCs) and Data Processing Addenda (DPAs).

Sub-processors

We use a small number of vetted sub-processors to deliver the Services. A current list is available on request under NDA.

Reporting a vulnerability

We welcome coordinated disclosure. Please write to security@janaka.ai with the details of the issue. Do not perform destructive testing or access data that is not your own.

Contact

Grievance Officer / Data Protection Officer: privacy@janaka.ai.