Bank-grade posture, before the first line of code runs.

Carbonis is engineered for institutional data — banks, regulators, and export-linked MSMEs. Every architectural decision starts with a compliance question, not a growth-hacking question.

Data Governance

Eight commitments a CISO can sign off on.

The controls below are the standing answer to the first ten questions a bank compliance team asks. Full DPA, sub-processor list, and architecture diagram available on request.

01

Encryption

Data encrypted in transit (TLS 1.3) and at rest (AES-256). Field-level encryption for PII and financial identifiers.

02

Hosting & Residency

India-hosted primary deployment on AWS Mumbai (ap-south-1) with restricted egress. EU / Singapore regional deployments available for regulated clients on request.

03

Access Control

Role-based access control, SSO via SAML 2.0 / OIDC, mandatory MFA on all privileged accounts, least-privilege service tokens with 24-hour rotation.

04

Audit Logging

Every read, write, and export is logged with actor, timestamp, and payload hash. Immutable audit trail available to client compliance and supervisory reviewers on request.

05

Compliance Posture

ISO 27001 implementation in progress. SOC 2 Type II audit scoped for FY 2026-27. GDPR-aligned data processing terms for EU-facing engagements.

06

Zero-Copy Read Model

Carbonis is a read-only overlay. Client core banking / ERP data is not migrated. Where ingest is required, it is via signed, versioned files or scoped API tokens — never bulk exports.

07

Data Segregation

Every tenant is logically isolated with per-tenant encryption keys. No cross-tenant analytics without explicit written authorisation.

08

Backups & Recovery

Encrypted backups every 6 hours with 30-day retention. RPO ≤ 6h · RTO ≤ 4h. Disaster-recovery drills quarterly.

Written Position

Carbonis does not — and will not — sell, license, or share tenant data with any third party, ever. Aggregated benchmarks are produced only from data with explicit written authorisation, and are always anonymised at the borrower and portfolio level.

The Next Step

Get carbon risk off your P&L — while there is still time.

Identify
Quantify
Mitigate
Protect