Security & Trust

Security

How we follow Indian security standards and protect your data. Last updated: February 2025

Introduction

AIcann takes security seriously. We build and operate our enterprise intelligence platform in line with applicable Indian laws and security standards so that your organisation’s data and operations remain protected.

This page describes how we follow Indian security and data protection requirements in a proper, structured way.

CERT-In & Incident Response

We follow the directions and best practices issued by the Indian Computer Emergency Response Team (CERT-In) where applicable:

We maintain incident response and breach notification procedures so that we can detect, contain, and report incidents in line with CERT-In requirements and applicable law.

We retain logs and relevant data for the periods required to support incident analysis and regulatory reporting.

We coordinate with internal and, where required, external stakeholders to respond to security events in a timely and proper manner.

Technical Security Measures

We implement industry-standard technical controls to protect your data:

Encryption: Data in transit is protected using strong encryption (TLS). Data at rest is encrypted using appropriate standards.

Access control: Strict access controls, role-based permissions, and principle of least privilege so that only authorised personnel can access systems and data.

Authentication: Secure authentication mechanisms, including strong password policies and, where applicable, multi-factor authentication (MFA) for access to our platform and internal systems.

Network and infrastructure security: Secure configuration of servers, networks, and cloud infrastructure; regular patching and hardening to reduce exposure to known vulnerabilities.

Organisational & Process Security

Security is embedded in how we work:

Secure development: Our development lifecycle includes security considerations—secure coding practices, dependency management, and review of changes that could affect security.

Vendor and third-party risk: We assess and monitor third-party providers that process or have access to data, and bind them by contract to appropriate security and confidentiality obligations.

Training and awareness: Personnel with access to systems and data receive security and privacy awareness training so that they handle information in a proper and compliant manner.

Data Sovereignty & Storage

We are mindful of data localisation and sovereignty requirements under Indian law:

Where the law or our contracts require that data be stored or processed only in India, we design our systems and choose deployment options to support such requirements.

We do not use your business data to train AI models for other customers; your data remains under your control and is processed only as agreed.

Continuous Improvement

Security and compliance are ongoing commitments. We periodically review and update our security policies, procedures, and controls to keep pace with changes in law, threat landscape, and industry practice. This page is updated to reflect material changes in how we follow security standards in India.

Contact Us

For security-related questions, incident reporting, or to request security or compliance documentation:

Email: contact@aicann.in

Phone: +91 7905172087

Or use the contact options available on our website.

Have security or compliance questions? We’re here to help.