Security Built Into Every Layer
Security is considered throughout the Gyan VaniAi platform, from authentication and access control to application workflows and data handling.
Security at Gyan VaniAi
At Gyan VaniAi, we understand that CRM and revenue operations handle some of your most sensitive business data. Our approach to security relies on proven industry standards rather than obscurity.
We build security directly into our application architecture—enforcing strict tenant isolation, role-based access control, and robust API security measures to ensure that your data remains yours, accessible only by authorized personnel within your organization.
Core Principles
- Defense in depth approach
- Least privilege access
- Strict tenant boundaries
- Continuous monitoring
Security Controls
Authentication
We utilize secure, stateless JSON Web Tokens (JWT) for authentication across all APIs, ensuring sessions are strongly validated and tamper-resistant.
Authorization (RBAC)
The platform enforces strict Role-Based Access Control (Owner, Admin, Agent) to ensure users only access the data and actions necessary for their jobs.
Tenant Isolation
Data is logically separated using tenant identifiers at the database layer. Cross-tenant access is strictly prohibited at the application level.
Application Security
We enforce strict CORS policies, rate limiting, and robust input validation to protect against automated abuse and injection attacks.
Data Protection
All communication between our servers and client applications is transmitted over secure HTTPS, encrypting data in transit.
Monitoring & Logging
Critical actions and application states are securely logged to maintain an audit trail for troubleshooting and security incident detection.
How We Protect Your Data
Data Input
Secure connections & validated payloads
Authentication & Authorization
JWT & Role checks applied
Protected Storage
Logical tenant separation
Monitoring
Audit logging of critical events
Access Control & Permissions
Gyan VaniAi enforces strict organizational boundaries. Only authenticated users can access the platform, and every API request is checked against the user's role:
- Owners: Full workspace management and billing access.
- Admins: Operational oversight and agent management.
- Agents: Restricted to assigned leads, tickets, and communications.
Application & Infrastructure Security
Our backend relies on the robust Spring Boot security ecosystem. We practice secure development lifecycles, ensuring dependencies are audited and patches are applied.
- Automated security unit testing
- Token expiration and session control
- Strict API rate limiting constraints
Indian Regulatory & Security Compliance Checklist
Gyan VaniAi aligns with national Indian cybersecurity directives, data privacy acts, and telecommunications guidelines.
DPDP Act, 2023 Compliance
Full compliance with India's Digital Personal Data Protection Act, 2023 (Sections 5–14). Verifiable consent logs, purpose specification, data principal rights (Access/Erasure), and designated Grievance Officer.
CERT-In Cybersecurity Directives
Adherence to CERT-In directives (April 2022): Mandatory 180-day ICT audit log retention, NTP clock synchronization to Indian Standard Time (IST), and sub-6-hour incident escalation procedures.
IT Act 2000 & IT Rules 2021
Intermediary due diligence under Section 79 of IT Act, 2000 & IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, including automated content moderation & 24/7 Grievance Officer contact.
Data Localization & Encryption
Support for MeitY-empanelled cloud data residency in India, enforcing AES-256 encryption at rest and TLS 1.3 in transit across all CRM lead repositories and RAG vector databases.
Security & Privacy
Security is only half the equation. We are deeply committed to respecting your privacy and handling user data responsibly.
Read our Privacy PolicyHave questions about security?
Talk with our team about your security, privacy, and implementation requirements.