Bank-grade posture, before the first line of code runs.
Carbonis is engineered for institutional data — banks, regulators, and export-linked MSMEs. Every architectural decision starts with a compliance question, not a growth-hacking question.
Eight commitments a CISO can sign off on.
The controls below are the standing answer to the first ten questions a bank compliance team asks. Full DPA, sub-processor list, and architecture diagram available on request.
Encryption
Data encrypted in transit (TLS 1.3) and at rest (AES-256). Field-level encryption for PII and financial identifiers.
Hosting & Residency
India-hosted primary deployment on AWS Mumbai (ap-south-1) with restricted egress. EU / Singapore regional deployments available for regulated clients on request.
Access Control
Role-based access control, SSO via SAML 2.0 / OIDC, mandatory MFA on all privileged accounts, least-privilege service tokens with 24-hour rotation.
Audit Logging
Every read, write, and export is logged with actor, timestamp, and payload hash. Immutable audit trail available to client compliance and supervisory reviewers on request.
Compliance Posture
ISO 27001 implementation in progress. SOC 2 Type II audit scoped for FY 2026-27. GDPR-aligned data processing terms for EU-facing engagements.
Zero-Copy Read Model
Carbonis is a read-only overlay. Client core banking / ERP data is not migrated. Where ingest is required, it is via signed, versioned files or scoped API tokens — never bulk exports.
Data Segregation
Every tenant is logically isolated with per-tenant encryption keys. No cross-tenant analytics without explicit written authorisation.
Backups & Recovery
Encrypted backups every 6 hours with 30-day retention. RPO ≤ 6h · RTO ≤ 4h. Disaster-recovery drills quarterly.
Carbonis does not — and will not — sell, license, or share tenant data with any third party, ever. Aggregated benchmarks are produced only from data with explicit written authorisation, and are always anonymised at the borrower and portfolio level.
