Ralixar

Trust centre

Security, compliance and privacy, built as infrastructure.

Tenant boundaries, access decisions, retention and privacy rights travel with the workflow—so control evidence is part of the operating record.

CONTROL PRINCIPLE

Trace the decision

Who, what, when, and the exact rule or model version behind it.

Control model

Six boundaries designed into the platform.

Security controls are applied where identity, data and decisions move—not added later as a reporting layer.

Hosting and residency

India-primary cells are designed for AWS ap-south-1 across three availability zones. Future-market deployments use regional cells so residency and failure boundaries remain explicit.

  • AWS ap-south-1
  • Three availability zones
  • Regional cells for future markets

Tenant isolation

A signed tenant context follows every authorised request through services, data access, events and search—not a filter added at the screen.

  • Signed tenant context
  • Row-level security
  • Per-tenant vector namespaces

Data protection

Data is encrypted in transit and at rest. Evidence requiring durable retention is stored with WORM controls designed to support customs retention of five years or more.

  • Encryption in transit
  • Encryption at rest
  • WORM evidence archive

Access control

Role-based access and maker-checker segregation keep preparation, filing and payment authority separate. SCIM supports governed joiner, mover and leaver processes.

  • RBAC
  • Maker-checker SoD
  • OIDC / SAML / SCIM

Privacy

DPDP Act 2023 and DPDP Rules 2025 alignment is designed into consent records, rights-request workflows, breach notification and retention decisions.

  • Consent records
  • Rights-request workflows
  • Statutory-retention precedence

Auditability

Every governed action records who acted, what changed, when it changed and which rule, model or policy version supported the decision.

  • Actor and timestamp
  • Before-and-after evidence
  • Rule and version trace

Statutory retention takes precedence

A privacy request does not silently erase records that law requires the organisation to retain. The rights workflow records the applicable basis, scope, decision and authorised response.

Independent assurance

Roadmap stated without implied certification.

These programmes are planned control-evidence milestones. The placeholder remains visible until Ralixar publishes a verified status.

Roadmap

SOC 2 Type II

Status: [[STATUS]]

No certification claim is made while this status is unresolved.

Roadmap

ISO 27001

Status: [[STATUS]]

No certification claim is made while this status is unresolved.

Security review

Take the control model into due diligence.

Request the security whitepaper for a structured view of the intended architecture, responsibilities and evidence programme.

Put your security and compliance questions on the table.