Hardened before you receive it.
Every module inherits the same policy model, the same audit trail, and the same catalogue. You don't harden DataByte, DataByte ships hardened.
Three enforcement layers. No gaps between them.
Access evaluated as policy, not stored as configuration.
- Role-based access control
- Policies written against the business object, not the table
- Open Policy Agent as the decision point
- User and group management
- SSO (SAML 2.0, OIDC)
- Administrative audit trail
Per-module access controls and approval workflows.
- API approval workflows
- Pipeline access control
- Model deployment gates
- Module-scoped audit trail
Row- and column-level security with PII intelligence.
- Row-level security
- Column-level security
- Automated PII tagging
- T1–T5 data classification
- Cross-module lineage
What happens to data in transit and at rest.
TLS 1.2+ for data in transit. AES-256 for data at rest. Customer-managed keys (KMS) supported, configured per deployment.
Choose US, EU, APAC, or on-prem deployment. Data never leaves the chosen region without an explicit export action, logged in the audit trail.
Configuration and metadata backed up continuously. RPO and RTO targets are agreed per deployment, and DR runbooks are tested on a recurring schedule.
Sub-processor list available on request; customers notified 30 days before material changes. Contractual flow-down of security terms.
Audited by people who do not work here.
Certifications and audit reports are held by Vwaves Technologies Private Limited (VisionWaves), the entity behind DataByte. Where a report is restricted-use, we share it under NDA rather than publishing it.
Independent examination of the design and operating effectiveness of controls relevant to Security, Availability, and Confidentiality. Unqualified opinion. The report is restricted-use and is shared under NDA.
- Auditor
- Accorp Partners CPA LLC
- Period
- 1 October 2024 to 31 March 2025
- Status
- Next observation period underway
Information Security Management System certification. The certified scope covers information security for software development and services including DataByte.
- Auditor
- QRO Certification LLP
- Period
- Certified 28 January 2026, valid to 27 January 2029
- Reference
- Certificate 305026012879IS
Controls examined against Regulation (EU) 2016/679. The assessor's opinion is that controls are adequately designed to meet GDPR requirements.
- Auditor
- Scrut Automation
- Period
- Assessed 25 April 2025
One place to administer every module.
There is no per-tool user directory to reconcile. Identities, roles, data-source credentials, and BI access are administered once at the platform level and inherited everywhere.
- Users, groups, and roles defined once and enforced by every module.
- Data-source registration and credential custody, scoped by role.
- BI and reporting enablement governed by the same permission model.
- Single sign-on via SAML 2.0 or OIDC, with session policy applied platform-wide.
- Administrative actions written to the same audit trail as pipeline activity.
SMART is why audits become reports.
The same five primitives that run governance across every module are what compliance officers rely on at audit time. No retrofit; no sprint of tagging.
Per-pipeline thresholds, alerted while there is still time to act.
Continuous lifecycle monitoring across executions.
Automated responses: notify, retry, escalate, reroute.
Business and technical rules enforced at the platform level.
Cross-module lineage and audit trail, source to consumer.
Your security team will ask specifics.
Book a review with our security engineer. We will walk through the SOC 2 Type II report and the ISO 27001 certificate, and share the DPA and sub-processor list.