What We Do Architecture Connect & Deploy Products Trust & Compliance Contact Us

Home › Trust & Compliance

Trust & Compliance

Certified,
Not Just Claimed

VIV.EKA holds production data — yield, cost, capacity, supplier terms and, for regulated manufacturers, protected health information. Everything your security team needs to assess us is on this page, including how to get the reports that are not.

ISO/IEC 27001Information security
SOC 2 Type IIIndependently audited
GDPREU data protection
HIPAAProtected health data

What We Hold

Four frameworks, independently assessed. Scope, registrar and report details below.

ISO/IEC 27001:2022

Certified

Our information security management system is certified against the 2022 revision. The ISMS governs how we classify, protect, monitor and retire customer data across the platform and the infrastructure it runs on.

Standard
ISO/IEC 27001:2022
Scope
VIV.EKA IMS platform, supporting cloud infrastructure and the personnel who operate them
Certificate
Number and registrar supplied on request
Surveillance
Annual audit; three-year recertification cycle

SOC 2 Type II

Audited

An independent auditor tested the design and the operating effectiveness of our controls across a defined observation window — which is what separates Type II from Type I. The full report is available under NDA.

Report type
SOC 2 Type II
Criteria
Security, Availability, Confidentiality
Availability
Full report under NDA; bridge letter on request
Cadence
Annual observation period

GDPR

Compliant

We act as processor for customer personal data. Our Data Protection Addendum is published in full — Standard Contractual Clauses, the Annex 1 processing description, technical and organisational measures, and the sub-processor list — so your counsel can review it before the first call.

Role
Processor (Customer is Controller)
Transfer basis
EU SCCs (2021/914); UK IDTA for UK-origin data

HIPAA

Compliant

For medical device, pharmaceutical and life-sciences manufacturers whose production data touches protected health information, we operate the required administrative, physical and technical safeguards and will execute a Business Associate Agreement.

Role
Business Associate
Agreement
BAA executed before any PHI is processed
Safeguards
Administrative, physical and technical, per 45 CFR Part 164
Requesting evidence. Security teams can request the SOC 2 Type II report, the ISO 27001 certificate, our penetration test summary and a completed CAIQ or SIG questionnaire by writing to connect.admin@crsn.in. We return the standard pack within two business days; anything under NDA follows once the NDA is countersigned.

Where Your Data Lives

We publish our infrastructure and sub-processors rather than describing them in the abstract. Both are contractually binding through the Data Protection Addendum.

ItemDetail
Deployment modelVIV.EKA is cloud-agnostic. It can run in your own cloud tenant, a region you nominate, on-premise, or in a CRSN-managed environment. The rows below describe the CRSN-managed option; where you host it yourself, your own controls and sub-processors apply
Infrastructure sub-processor (CRSN-managed)Microsoft Corporation (India) Private Limited — hosting, databases, storage, backup, security, logging and Microsoft Entra ID authentication. Named in full in Annex 2 of the DPA
Data residency (CRSN-managed)India. Transfers of EU-origin personal data are made under the 2021 Standard Contractual Clauses with a transfer impact assessment. Self-hosted deployments sit wherever you place them
EncryptionTLS in transit; encryption at rest on all customer data stores
TenancyMulti-tenant with logical isolation of customer data
AuthenticationMulti-factor authentication or SSO required for all administrator and end-user access
AvailabilityWorkloads deployed across multiple Availability Zones; disaster recovery tested regularly
Access controlLeast privilege and need-to-know, with formal request, review and approval
Breach notificationCustomer notified without undue delay on becoming aware of a personal data breach
Data return & deletionReturn or irreversible deletion at your election on termination

Before You Ask

Can we get your SOC 2 report before signing?

Yes. Active prospects can receive the full SOC 2 Type II report once an NDA is in place. If your review is at an earlier stage, we can send a bridge letter and the ISO 27001 certificate without an NDA.

Do you complete security questionnaires?

Yes, and most of the answers are already published here and in the DPA — sending your team these two links usually removes half the questionnaire. We complete CAIQ and SIG formats, and bespoke questionnaires on request.

Where is our data physically stored, and can we keep it in our own cloud?

That is your choice. VIV.EKA is cloud-agnostic — it can run in your own tenant, a region you nominate, on-premise, or in a CRSN-managed environment. If you self-host, your data never leaves your infrastructure. If CRSN manages it, data resides in India and we will not change the processing region without notifying you under the sub-processor provisions of the Data Protection Addendum.

We manufacture medical devices. Can you sign a BAA?

Yes. We execute a Business Associate Agreement before any protected health information is processed. Contact the DPO to start that.

Do you use customer data to train AI models?

No. Under the Data Protection Addendum we process customer personal data solely on your documented instructions and for the purposes of providing the Services. We do not sell or share it, and we do not use it for any commercial purpose of our own.

How do we report a vulnerability?

Email connect.admin@crsn.in with the details. We acknowledge reports within two business days and will keep you updated through remediation.