Security Built Into Every Layer

Security is considered throughout the Gyan VaniAi platform, from authentication and access control to application workflows and data handling.

Contact Support

Security at Gyan VaniAi

At Gyan VaniAi, we understand that CRM and revenue operations handle some of your most sensitive business data. Our approach to security relies on proven industry standards rather than obscurity.

We build security directly into our application architecture—enforcing strict tenant isolation, role-based access control, and robust API security measures to ensure that your data remains yours, accessible only by authorized personnel within your organization.

Core Principles

  • Defense in depth approach
  • Least privilege access
  • Strict tenant boundaries
  • Continuous monitoring

Security Controls

Authentication

We utilize secure, stateless JSON Web Tokens (JWT) for authentication across all APIs, ensuring sessions are strongly validated and tamper-resistant.

Authorization (RBAC)

The platform enforces strict Role-Based Access Control (Owner, Admin, Agent) to ensure users only access the data and actions necessary for their jobs.

Tenant Isolation

Data is logically separated using tenant identifiers at the database layer. Cross-tenant access is strictly prohibited at the application level.

Application Security

We enforce strict CORS policies, rate limiting, and robust input validation to protect against automated abuse and injection attacks.

Data Protection

All communication between our servers and client applications is transmitted over secure HTTPS, encrypting data in transit.

Monitoring & Logging

Critical actions and application states are securely logged to maintain an audit trail for troubleshooting and security incident detection.

How We Protect Your Data

1

Data Input

Secure connections & validated payloads

2

Authentication & Authorization

JWT & Role checks applied

3

Protected Storage

Logical tenant separation

4

Monitoring

Audit logging of critical events

Access Control & Permissions

Gyan VaniAi enforces strict organizational boundaries. Only authenticated users can access the platform, and every API request is checked against the user's role:

  • Owners: Full workspace management and billing access.
  • Admins: Operational oversight and agent management.
  • Agents: Restricted to assigned leads, tickets, and communications.

Application & Infrastructure Security

Our backend relies on the robust Spring Boot security ecosystem. We practice secure development lifecycles, ensuring dependencies are audited and patches are applied.

  • Automated security unit testing
  • Token expiration and session control
  • Strict API rate limiting constraints

Indian Regulatory & Security Compliance Checklist

Gyan VaniAi aligns with national Indian cybersecurity directives, data privacy acts, and telecommunications guidelines.

DPDP Act, 2023 Compliance

Full compliance with India's Digital Personal Data Protection Act, 2023 (Sections 5–14). Verifiable consent logs, purpose specification, data principal rights (Access/Erasure), and designated Grievance Officer.

CERT-In Cybersecurity Directives

Adherence to CERT-In directives (April 2022): Mandatory 180-day ICT audit log retention, NTP clock synchronization to Indian Standard Time (IST), and sub-6-hour incident escalation procedures.

IT Act 2000 & IT Rules 2021

Intermediary due diligence under Section 79 of IT Act, 2000 & IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, including automated content moderation & 24/7 Grievance Officer contact.

Data Localization & Encryption

Support for MeitY-empanelled cloud data residency in India, enforcing AES-256 encryption at rest and TLS 1.3 in transit across all CRM lead repositories and RAG vector databases.

Have questions about security?

Talk with our team about your security, privacy, and implementation requirements.