Skip to main content
Trust Center

Trust, made verifiable.

This is the single place to evaluate Autroid's security, compliance, and operational reliability. Everything here routes to the underlying detail — so your security team can assess us once, from one page.

India Data Residency
DPDP Act Compliant
Daily Encrypted Backups

Reliability & Continuity

Built to stay up. Built to recover.

Security and compliance protect your data. Reliability keeps it available. Autroid runs on AWS infrastructure with daily encrypted backups, India data residency, and a structured incident response protocol.

Daily encrypted backups

Automated daily backups are encrypted and retained for point-in-time recovery — your data is recoverable, not just stored.

India data residency

All customer data is stored exclusively in the AWS Mumbai (ap-south-1) region, with no cross-border transfers without consent.

Multi-tenant isolation

Every tenant is isolated by business ID, so one organization’s data can never be reached by another.

99.9% uptime SLA

A 99.9% uptime SLA is committed on the Ultimate and Enterprise plans, backed by AWS infrastructure and continuous monitoring.

Incident response protocol

  1. Detect & containAffected systems are isolated within 30 minutes of detection.

    Automated monitoring flags anomalies around the clock, so containment begins the moment an incident is detected — not after a manual review.

  2. Notify within 72 hoursAffected users and regulators are notified within 72 hours.

    The 72-hour notification window is a statutory requirement under India’s DPDP Act, and our response protocol is built to meet it.

  3. Remediate & reviewEvery incident closes with a fix and a post-incident review.

    Root cause analysis and fix deployment are followed by a documented post-incident review, so the same class of issue does not recur.

Tenant Isolation

One platform. Every business kept apart.

Shared infrastructure is how Autroidstays affordable; isolation is how it stays trustworthy. Every inbound call and message is resolved to exactly one organisation before anything is touched, and every record carries that organisation's key. If an event cannot be resolved, it reaches no one.

Shared platform
  • One master telephony webhookserves every tenant
  • One master WhatsApp accountisolated sender per tenant
  • One AI runtimesame firewall, same guards
Tenant resolver · fail-closed
  • Inbound call → dialled number (DID) → organisation. Never a URL parameter.
  • Voice media stream → per-session signed token carrying the organisation and call id.
  • WhatsApp webhook → HMAC-SHA256 signature + 5-minute replay protection.
  • Unresolvable event → dropped. Fail-closed on every inbound path.
  • Organisation A
    • Own number
    • Own WhatsApp sender
    • Own ledger
    • Own data
    organizationId · every record
  • Organisation B
    • Own number
    • Own WhatsApp sender
    • Own ledger
    • Own data
    organizationId · every record
  • Organisation C
    • Own number
    • Own WhatsApp sender
    • Own ledger
    • Own data
    organizationId · every record

No data is shared between organisations — ever. Isolation is a property of every record and every inbound path, not a setting.

Responsible Disclosure

Found something? Tell us.

We welcome reports from security researchers and customers. If you believe you have found a security issue in Autroid, please report it to our team so we can investigate and remediate.

  • Report suspected vulnerabilities, exposures, or security concerns directly to our team.
  • Include clear reproduction steps and impact so we can triage and remediate quickly.
  • Please give us reasonable time to investigate and fix before any public disclosure.
Report a concernsupport@autroid.ai

Need a deeper review?

Our team can walk your security, procurement, or compliance stakeholders through our architecture and posture in detail.