Security and data
Our customers trust us with their operations, their clients' financial records and, in healthcare, their patients' information. This is how we protect it.
Data residency
Data residency is our standard: systems we build for Indian customers keep their data in cloud regions in India.
Where a product can run inside the customer's own environment, as our product for CA firms is designed to, the data does not leave their control at all. Where a task uses an AI service outside India, we tell the customer which service is used and what data it sees.
How we work today
In place- Each client's systems and data are kept separate from every other client's.
- Changes that affect customers, or cannot be undone, are approved by a person before they go live.
- Decisions about systems and data are recorded with their reasons, so they can be checked later.
- This website sets no cookies, runs no analytics and collects no personal data.
Built into every product we release
Product standard- Encryption of customer data in transit and at rest.
- Access controls for each organisation and each client, with logs of who did what, kept for at least one year.The DPDP Rules, 2025 require processing logs to be kept for at least a year.
- Privacy notices, consent records, and the rights to access, correct and erase personal data.Required by the Digital Personal Data Protection Act, 2023.
- A breach response plan, including notice to affected people and to the Data Protection Board of India.
- Customer data is never used to train AI models.
The rules we design for
- Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025
- Information Technology Act, 2000 and its rules on sensitive personal data
- ICAI Code of Ethics: confidentiality, for products used by CA firms
- CGST Act, 2017, section 36: retention of GST records
- Ayushman Bharat Digital Mission, where a health product connects to it
The DPDP Act's main duties for businesses apply from May 2027. Our products are designed to meet them from their first release.
For each product, we map the regulations of its domain, such as record-keeping periods for GST or consent rules for health records, and confirm them with professional advice before launch.
Report a security issue
If you believe you have found a security problem in anything we run, email hello@deepbuild.tech. Please give us a reasonable time to fix it before making it public.