Back to app
Technical Controls & Vendor ArchitectureDPDP Act 2023 Aligned

Security & Sub-processors

At Sancharya (operated by Marketingko, Warangal, Telangana, India), we architect institutional-grade security safeguards into our autonomous voice employee infrastructure. This document outlines our technical security controls, encryption ciphers, India-first data handling, and verified third-party sub-processors.

Platform: Sancharya by Marketingko•Voice Engine: Swara•Last Updated: September 21, 2026 • Version 2.4-DPDP
TLS 1.3 & AES-256

Military-grade encryption for all data at rest and in transit across edge networks.

DTLS-SRTP Audio

Cryptographically secured real-time WebRTC audio streams preventing wiretapping.

India-First Residency

Lead records, call recordings, and transcripts maintained under Indian regulatory boundaries.

72-Hour Breach SLA

Guaranteed rapid statutory incident notification under Section 8(6) of the DPDP Act.

1. Infrastructure & Network Architecture

Sancharya is hosted on Vercel's global edge network, providing distributed high-availability serverless execution with built-in Layer 3, 4, and 7 DDoS mitigation and automated SSL/TLS provisioning.

Encryption in Transit

All HTTP traffic to and from Sancharya is enforced over TLS 1.3 (with TLS 1.2 minimum fallback) utilizing modern ephemeral Diffie-Hellman cipher suites with Perfect Forward Secrecy (PFS). Plaintext HTTP connections are strictly rejected.

Encryption at Rest

All databases, configuration records, prompt documents, and persistent artifacts are encrypted at rest utilizing industry-standard AES-256 algorithms. Cryptographic keys are managed through automated hardware security modules (HSM) with strict separation of duties.

2. Authentication & Access Control (IAM)

Authentication is delegated to Auth0 by Okta, an industry leader in enterprise identity security.

  • Cryptographic Session Tokens: Sessions are authenticated via signed, short-lived JSON Web Tokens (JWTs) stored in secure, HTTP-only, SameSite cookies. Tokens cannot be accessed by client-side JavaScript, neutralizing Cross-Site Scripting (XSS) credential theft.
  • Role-Based Access Control (RBAC): Access to organization workspaces, AI employee prompts, dialer controls, and billing wallets is governed by strict RBAC policies following the principle of least privilege.
  • Abuse Defense & Disposable Email Blocking: Our edge middleware actively filters disposable email domains, suspicious proxy rotations, and brute-force login attempts before requests reach core services.

3. Voice & Telephony Audio Security

Voice telephony is the core of the Sancharya platform. We implement specialized telecommunications security controls to safeguard conversational privacy:

LiveKit WebRTC & DTLS-SRTP Audio Streams

Voice interactions processed via our Swara engine utilize LiveKit WebRTC. Audio packets are encrypted end-to-end using DTLS-SRTP (Datagram Transport Layer Security - Secure Real-time Transport Protocol). Media packets cannot be decrypted or intercepted in transit across the public Internet.

Secure SIP Trunking & Ephemeral Memory Processing

Carrier connections (PSTN/DID termination) operate over dedicated, authenticated SIP trunks. Audio frames are converted to speech tokens in high-speed volatile memory for conversational reasoning. Audio buffers are purged immediately following sentence synthesis, unless explicit call recording is enabled by the customer.

4. Data Processing & India-First Data Residency

In strict adherence to the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023):

India Data Residency

Primary databases hosting lead information, customer CRM synchronizations, call records, and Indian (+91) telephony routing metadata are maintained with data residency prioritizing Indian infrastructure hubs.

Non-Training Covenant

Sancharya covenants that customer proprietary conversation transcripts, uploaded PDF knowledge bases, and audio samples are never utilized to train public foundation models.

5. Verified Sub-processor Directory

Authorized Vendors

Sancharya engages vetted third-party sub-processors to deliver core hosting, authentication, payment, and conversational AI capabilities. Each vendor undergoes strict security diligence and executes binding data protection commitments:

Sub-processorPurpose / ServiceEntity & LocationData ProcessedSecurity Safeguards
Auth0 by OktaUser authentication, JWT issuance, identity federation, and session securityUnited States (US)User email, account name, Auth0 user ID, login timestampsSOC 2 Type II, ISO 27001, TLS 1.3, Encrypted session cookies
Vercel Inc.Application hosting, global edge compute network, and static asset distributionGlobal Edge NetworkEphemeral HTTP requests, IP addresses, client headers in transitSOC 2 Type II, ISO 27001, Enterprise DDoS WAF, TLS 1.3
LiveKit Cloud / LiveKit Inc.Real-time WebRTC audio room orchestration and voice streaming infrastructureGlobal Edge NodesReal-time audio streams, session metadata, audio packet telemetryDTLS-SRTP end-to-end media encryption, ephemeral in-memory processing
Razorpay Software Pvt. Ltd.Billing gateway, UPI, credit card payments, and lifetime credit invoicingIndia (Bengaluru)Billing contact name, phone, transaction IDs, invoice line itemsPCI-DSS Level 1 Certified, RBI Payment Aggregator Guidelines, ISO 27001
Google Cloud Platform (GCP)AI/ML inference, speech-to-text transcription, and neural voice synthesisAsia (India & Singapore regions)Speech audio waveforms, prompt context tokens during active callsSOC 1/2/3, ISO 27001/27017/27018, AES-256 rest encryption, Zero-retention contracts
PostHog Inc.Onboarding UI telemetry strictly during initial AI employee setup wizardEuropean Union (EU Cloud, Frankfurt)Setup step completion events, wizard drop-offs (strictly zero PII/audio/leads)GDPR compliant, EU Data Residency, restricted to setup wizard only

6. Incident Response & DPDP 72-Hour Breach SLA

We maintain a documented, tested Incident Response Plan (IRP) overseen by our engineering and security leadership.

Statutory 72-Hour Breach Notification Guarantee:

In compliance with Section 8(6) of the Digital Personal Data Protection Act, 2023, in the event of a confirmed personal data breach affecting Customer records, Sancharya covenants to notify impacted account administrators without undue delay and within seventy-two (72) hours of confirmation.

Our incident telemetry includes details on the nature of the breach, affected records, immediate containment actions, and guidance to support Customer reporting to the Data Protection Board of India (DPBI).

Direct Emergency Incident Escalation: karthikeya@marketingko.in

7. Responsible Disclosure & Bug Bounty

We believe security is a continuous collective effort and welcome reports from ethical security researchers. If you identify a vulnerability in Sancharya's infrastructure or applications, please practice responsible disclosure:

Safe Harbor & Reporting Guidelines:
  • Submit detailed reproduction steps and proof-of-concept to karthikeya@marketingko.in.
  • Do not access, modify, or exfiltrate another customer's data or operational telephony streams.
  • Do not execute Denial-of-Service (DoS) attacks or degrade production voice availability.
  • Allow us reasonable time (up to 30 days) to remediate the vulnerability before public disclosure.

Valid, non-duplicate reports will receive formal recognition in our Security Hall of Fame and priority evaluation by Founder Karthikeya Thallapally.