Skip to content
AI Digital Hub

Trust

Compliance

Where we are with each framework, including the ones we have not achieved. An overstated trust page costs more than an honest one, because your security team will check.

Last updated 1 July 2026 · Exinary Technologies Private Limited

Current status

FrameworkStatusDetail
DPDP Act 2023 (India)AlignedConsent captured separately and unticked by default, purpose limitation designed into engagements, erasure supported down to retrieval-index lineage, and a documented grievance process.
GDPR (EU/UK)AlignedStandard Contractual Clauses with sub-processors where required, DPA available on request, data principal rights process, and transfer risk assessed per engagement.
ISO/IEC 27001In progress — target Q1 2027ISMS documented, controls implemented and evidence collection automated. Certification audit not yet complete. We do not claim to be certified.
SOC 2 Type IIIn progress — target Q2 2027Controls in place and evidence collected continuously. The observation window has not closed, so there is no report to share yet.
EU AI ActReadiness assessment offeredWe classify client use cases against the Act's risk tiers and build the transparency and documentation obligations that apply. Most business automation lands in limited or minimal risk.
ISO/IEC 42001 (AI management)Monitoring — not pursuing yetWe build to its principles in the governance work but are not seeking certification at our current size. We will say so rather than imply otherwise.

What 'in progress' actually means

For ISO 27001 and SOC 2, it means the controls are implemented and operating, and evidence is being collected — but the audit has not concluded. We can share our control documentation, our policies and our evidence under NDA today. What we cannot share is a certificate, because we do not have one.

In our experience that distinction matters to serious buyers and is exactly the thing vendors blur. If an unqualified certification is a hard requirement for your procurement process, tell us early and we will be straight about the timeline rather than waste your time.

Sector-specific requirements

We design around sector obligations even where we hold no sector-specific certification:

  • Financial services: RBI IT and cyber security framework expectations, data localisation, model risk documentation, audit trails at decision level.
  • Healthcare: heightened DPDP obligations for health data, ABDM standards, HIPAA-aligned handling for US-facing work. We do not build regulated medical devices.
  • Payments: we never handle raw card data — hosted checkout only, so PCI scope stays with the processor.

Security questionnaires

We complete them, and we complete them accurately including the answers that are “no”. Most of what enterprise questionnaires ask for — data flows, sub-processors, retention, access control, oversight design — is already published on our security and sub-processors pages, which usually shortens the process considerably.

Send yours to [email protected]. Turnaround is typically three to five business days.

Company details for procurement

  • Legal entity: Exinary Technologies Private Limited
  • Registered office: TC 6/199-9, SWATHY, Netaji Road, Thiruvananthapuram, Kerala 695013, India
  • CIN: U72200KL2011PTC028847
  • GSTIN: 32AACCE7672B2ZY
  • Data protection contact: [email protected]
  • Security contact: [email protected]

Questions?

Email [email protected] for anything about data or these policies, or [email protected] for security matters. See also our security page.