Skip to main content
Enterprise-Grade Security

Bank-Grade Security for
India's Financial Infrastructure.

Santulan AI is built from the ground up to satisfy the stringent compliance requirements of RBI-regulated banks, NBFCs, and credit institutions.

Our Security Guarantees

How we protect applicant financial data and maintain compliance across your lending pipeline.

RBI DPDP Act 2023 Compliant

Fully compliant with India's Digital Personal Data Protection Act 2023. Explicit consent enforcement, strict data minimization, purpose limitation, and automated data purging workflows.

Verified Compliant

100% Indian Data Residency

All customer financial data, bank statements, and credit reports are hosted exclusively in Tier-4 AWS & MeitY-empaneled data centers located within India (Mumbai & Hyderabad). Zero cross-border data transfer.

Verified Compliant

End-to-End Encryption

Bank statements and PII are encrypted using 256-bit AES encryption at rest and TLS 1.3 in transit. Sensitive fields (PAN, Account Numbers, Aadhaar) are masked automatically upon ingestion.

Verified Compliant

SOC 2 Type II & ISO 27001 Aligned

Our security operations, access controls, vulnerability management, and infrastructure follow SOC 2 Type II principles and ISO 27001 ISMS standards.

Verified Compliant

VAPT & Penetration Testing

Regular Vulnerability Assessment and Penetration Testing (VAPT) performed quarterly by CERT-In empaneled security auditors. Zero critical or high vulnerabilities allowed in production.

Verified Compliant

Role-Based Access Control (RBAC)

Granular RBAC with SAML 2.0 / Single Sign-On (SSO), Multi-Factor Authentication (MFA), and audit logging for every data access and report generation action.

Verified Compliant
Regulatory Alignment

Aligned with RBI Digital Lending Guidelines

Santulan AI operates as a Technology Service Provider (TSP). Our workflows follow RBI Guidelines on Digital Lending:

  • No retention of raw bank statement PDFs beyond processing retention window
  • Direct consent architecture — data accessed only upon explicit applicant authorization
  • Comprehensive audit trail for every credit report generated
  • Separation of credit policy execution from raw data storage

Request Security Audit Packet

Evaluating Santulan AI for enterprise deployment? Access our complete SOC 2 report, VAPT executive summary, and InfoSec assessment questionnaire.

Request InfoSec Packet