Security & Sub-processors
At Sancharya (operated by Marketingko, Warangal, Telangana, India), we architect institutional-grade security safeguards into our autonomous voice employee infrastructure. This document outlines our technical security controls, encryption ciphers, India-first data handling, and verified third-party sub-processors.
Military-grade encryption for all data at rest and in transit across edge networks.
Cryptographically secured real-time WebRTC audio streams preventing wiretapping.
Lead records, call recordings, and transcripts maintained under Indian regulatory boundaries.
Guaranteed rapid statutory incident notification under Section 8(6) of the DPDP Act.
1. Infrastructure & Network Architecture
Sancharya is hosted on Vercel's global edge network, providing distributed high-availability serverless execution with built-in Layer 3, 4, and 7 DDoS mitigation and automated SSL/TLS provisioning.
All HTTP traffic to and from Sancharya is enforced over TLS 1.3 (with TLS 1.2 minimum fallback) utilizing modern ephemeral Diffie-Hellman cipher suites with Perfect Forward Secrecy (PFS). Plaintext HTTP connections are strictly rejected.
All databases, configuration records, prompt documents, and persistent artifacts are encrypted at rest utilizing industry-standard AES-256 algorithms. Cryptographic keys are managed through automated hardware security modules (HSM) with strict separation of duties.
2. Authentication & Access Control (IAM)
Authentication is delegated to Auth0 by Okta, an industry leader in enterprise identity security.
- Cryptographic Session Tokens: Sessions are authenticated via signed, short-lived JSON Web Tokens (JWTs) stored in secure, HTTP-only, SameSite cookies. Tokens cannot be accessed by client-side JavaScript, neutralizing Cross-Site Scripting (XSS) credential theft.
- Role-Based Access Control (RBAC): Access to organization workspaces, AI employee prompts, dialer controls, and billing wallets is governed by strict RBAC policies following the principle of least privilege.
- Abuse Defense & Disposable Email Blocking: Our edge middleware actively filters disposable email domains, suspicious proxy rotations, and brute-force login attempts before requests reach core services.
3. Voice & Telephony Audio Security
Voice telephony is the core of the Sancharya platform. We implement specialized telecommunications security controls to safeguard conversational privacy:
Voice interactions processed via our Swara engine utilize LiveKit WebRTC. Audio packets are encrypted end-to-end using DTLS-SRTP (Datagram Transport Layer Security - Secure Real-time Transport Protocol). Media packets cannot be decrypted or intercepted in transit across the public Internet.
Carrier connections (PSTN/DID termination) operate over dedicated, authenticated SIP trunks. Audio frames are converted to speech tokens in high-speed volatile memory for conversational reasoning. Audio buffers are purged immediately following sentence synthesis, unless explicit call recording is enabled by the customer.
4. Data Processing & India-First Data Residency
In strict adherence to the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023):
Primary databases hosting lead information, customer CRM synchronizations, call records, and Indian (+91) telephony routing metadata are maintained with data residency prioritizing Indian infrastructure hubs.
Sancharya covenants that customer proprietary conversation transcripts, uploaded PDF knowledge bases, and audio samples are never utilized to train public foundation models.
5. Verified Sub-processor Directory
Authorized VendorsSancharya engages vetted third-party sub-processors to deliver core hosting, authentication, payment, and conversational AI capabilities. Each vendor undergoes strict security diligence and executes binding data protection commitments:
| Sub-processor | Purpose / Service | Entity & Location | Data Processed | Security Safeguards |
|---|---|---|---|---|
| Auth0 by Okta | User authentication, JWT issuance, identity federation, and session security | United States (US) | User email, account name, Auth0 user ID, login timestamps | SOC 2 Type II, ISO 27001, TLS 1.3, Encrypted session cookies |
| Vercel Inc. | Application hosting, global edge compute network, and static asset distribution | Global Edge Network | Ephemeral HTTP requests, IP addresses, client headers in transit | SOC 2 Type II, ISO 27001, Enterprise DDoS WAF, TLS 1.3 |
| LiveKit Cloud / LiveKit Inc. | Real-time WebRTC audio room orchestration and voice streaming infrastructure | Global Edge Nodes | Real-time audio streams, session metadata, audio packet telemetry | DTLS-SRTP end-to-end media encryption, ephemeral in-memory processing |
| Razorpay Software Pvt. Ltd. | Billing gateway, UPI, credit card payments, and lifetime credit invoicing | India (Bengaluru) | Billing contact name, phone, transaction IDs, invoice line items | PCI-DSS Level 1 Certified, RBI Payment Aggregator Guidelines, ISO 27001 |
| Google Cloud Platform (GCP) | AI/ML inference, speech-to-text transcription, and neural voice synthesis | Asia (India & Singapore regions) | Speech audio waveforms, prompt context tokens during active calls | SOC 1/2/3, ISO 27001/27017/27018, AES-256 rest encryption, Zero-retention contracts |
| PostHog Inc. | Onboarding UI telemetry strictly during initial AI employee setup wizard | European Union (EU Cloud, Frankfurt) | Setup step completion events, wizard drop-offs (strictly zero PII/audio/leads) | GDPR compliant, EU Data Residency, restricted to setup wizard only |
6. Incident Response & DPDP 72-Hour Breach SLA
We maintain a documented, tested Incident Response Plan (IRP) overseen by our engineering and security leadership.
In compliance with Section 8(6) of the Digital Personal Data Protection Act, 2023, in the event of a confirmed personal data breach affecting Customer records, Sancharya covenants to notify impacted account administrators without undue delay and within seventy-two (72) hours of confirmation.
Our incident telemetry includes details on the nature of the breach, affected records, immediate containment actions, and guidance to support Customer reporting to the Data Protection Board of India (DPBI).
7. Responsible Disclosure & Bug Bounty
We believe security is a continuous collective effort and welcome reports from ethical security researchers. If you identify a vulnerability in Sancharya's infrastructure or applications, please practice responsible disclosure:
- Submit detailed reproduction steps and proof-of-concept to
karthikeya@marketingko.in. - Do not access, modify, or exfiltrate another customer's data or operational telephony streams.
- Do not execute Denial-of-Service (DoS) attacks or degrade production voice availability.
- Allow us reasonable time (up to 30 days) to remediate the vulnerability before public disclosure.
Valid, non-duplicate reports will receive formal recognition in our Security Hall of Fame and priority evaluation by Founder Karthikeya Thallapally.