DataByte
Security & Trust

Hardened before you receive it.

Every module inherits the same policy model, the same audit trail, and the same catalogue. You don't harden DataByte, DataByte ships hardened.

A request evaluated by platform, module, and data enforcement, then allowed or recorded, against a security model audited to SOC 2 Type II, ISO 27001, and GDPR
Security model

Three enforcement layers. No gaps between them.

Three enforcement layers a request cannot skipThree enforcement layers drawn as solid slabs stacked with no gap between them. A request enters at the top and passes through the platform layer, which enforces role-based access, single sign-on and session management, then the module layer, which enforces approvals and deployment gates, then the data layer, which enforces row and column security, PII tagging and T1 to T5 classification. The slabs touch, so a request cannot clear one and skip the next, and each layer writes to the same audit trail on the right.ENFORCEMENT PATHa requestData layerRow, column, PII tags, T1 to T5Module layerApprovals and deployment gatesPlatform layerRBAC, SSO, session managementAudittrail
Three layers. A request clears all of them or none.
Platform layer

Access evaluated as policy, not stored as configuration.

  • Role-based access control
  • Policies written against the business object, not the table
  • Open Policy Agent as the decision point
  • User and group management
  • SSO (SAML 2.0, OIDC)
  • Administrative audit trail
Module layer

Per-module access controls and approval workflows.

  • API approval workflows
  • Pipeline access control
  • Model deployment gates
  • Module-scoped audit trail
Data layer

Row- and column-level security with PII intelligence.

  • Row-level security
  • Column-level security
  • Automated PII tagging
  • T1–T5 data classification
  • Cross-module lineage
Operational controls

What happens to data in transit and at rest.

Encryption inside a chosen region, and the one way outData stays inside the region you choose, whether that is the US, the EU, APAC or your own premises. In transit it is protected by TLS 1.2 or above, at rest by AES-256, and the keys can be customer-managed through a KMS configured per deployment. The only route out of the region is an explicit export action, and that action is written to the audit trail.DATA BOUNDARYYour regionUS, EU, APAC, or on-premisesIn transitTLS 1.2 and aboveAt restAES-256KeysCustomer-managed KMS, set per deploymentlogged exportNothing leaves without one.
Residency is a deployment decision the platform enforces.
Encryption

TLS 1.2+ for data in transit. AES-256 for data at rest. Customer-managed keys (KMS) supported, configured per deployment.

Data residency

Choose US, EU, APAC, or on-prem deployment. Data never leaves the chosen region without an explicit export action, logged in the audit trail.

Backups & recovery

Configuration and metadata backed up continuously. RPO and RTO targets are agreed per deployment, and DR runbooks are tested on a recurring schedule.

Sub-processors

Sub-processor list available on request; customers notified 30 days before material changes. Contractual flow-down of security terms.

Independent assurance

Audited by people who do not work here.

Certifications and audit reports are held by Vwaves Technologies Private Limited (VisionWaves), the entity behind DataByte. Where a report is restricted-use, we share it under NDA rather than publishing it.

SOC 2 Type II
Certified

Independent examination of the design and operating effectiveness of controls relevant to Security, Availability, and Confidentiality. Unqualified opinion. The report is restricted-use and is shared under NDA.

Auditor
Accorp Partners CPA LLC
Period
1 October 2024 to 31 March 2025
Status
Next observation period underway
ISO/IEC 27001:2022
Certified

Information Security Management System certification. The certified scope covers information security for software development and services including DataByte.

Auditor
QRO Certification LLP
Period
Certified 28 January 2026, valid to 27 January 2029
GDPR
Assessed

Controls examined against Regulation (EU) 2016/679. The assessor's opinion is that controls are adequately designed to meet GDPR requirements.

Auditor
Scrut Automation
Period
Assessed 25 April 2025
Administration

One place to administer every module.

There is no per-tool user directory to reconcile. Identities, roles, data-source credentials, and BI access are administered once at the platform level and inherited everywhere.

What the admin surface covers
  • Users, groups, and roles defined once and enforced by every module.
  • Data-source registration and credential custody, scoped by role.
  • BI and reporting enablement governed by the same permission model.
  • Single sign-on via SAML 2.0 or OIDC, with session policy applied platform-wide.
  • Administrative actions written to the same audit trail as pipeline activity.
Compliance by design

SMART is why audits become reports.

The same five primitives that run governance across every module are what compliance officers rely on at audit time. No retrofit; no sprint of tagging.

SMART governance framework with five primitives around a governed core
SMART, present in every module.
S
SLA

Per-pipeline thresholds, alerted while there is still time to act.

M
Monitoring

Continuous lifecycle monitoring across executions.

A
Actions

Automated responses: notify, retry, escalate, reroute.

R
Rules

Business and technical rules enforced at the platform level.

T
Traceability

Cross-module lineage and audit trail, source to consumer.

Your security team will ask specifics.

Book a review with our security engineer. We will walk through the SOC 2 Type II report and the ISO 27001 certificate, and share the DPA and sub-processor list.