Skip to main content
Home Legal
Compliance and Security Updates

Compliance and Security Updates

Version 1.0 · Effective 22 August 2026

Certification status, audit reports, the change log for every document in this hub, and the semi-annual transparency report. Status, not aspiration.

Global Updated quarterly Transparency report Change log

Three words, three different meanings. Certified means an accredited body has issued a certificate we can show you. Assessed means an independent third party examined us and produced a report. Aligned means we have mapped our controls to a framework ourselves and nobody external has checked. We use the third word only where it is true, and we never use it to imply either of the others.

1. Certification and assurance status

FrameworkStatusScopeIssued / assessedNext
ISO/IEC 27001:2022[status]Platform, HUB, supporting operations[date][date]
ISO/IEC 27701 (privacy)[status]——[date]
SOC 2 Type II[status]Security, availability, confidentiality[period][date]
IRAP assessment (Australia)[status][classification][date][date]
Essential Eight maturity[assessed level]Corporate and production estate[date][date]
STQC / MeitY empanelment (India)[status]——[date]
Independent penetration test[status]Platform, API, edge[date]Annual
Independent model bias evaluation[status]FaceTrack, DriveLink[date][date]

Reports are available to customers and qualified prospective customers under NDA. Request from security@dectify.in. Where a row says a certification is in progress or not held, that is the accurate position and we will not describe it otherwise in a tender response.

2. Statutory registrations and officers

CERT-In Point of Contact[name] — registered
Grievance Officer (IT Rules 2021)Named at Grievance Redressal
Data Protection Officer contact (DPDP s.8(9))Named at Grievance Redressal
Significant Data Fiduciary designation (DPDP s.10)Not designated
SOCI Act responsible entity (Australia)Not a responsible entity for a declared asset
Modern Slavery Act 2018 reporting entityBelow threshold — not a reporting entity
Australian entity / ABNNone. Australian customers contract with the Indian entity

3. Transparency report

Published semi-annually, covering January to June and July to December.

3.1 Government and law enforcement requests

MetricJan–Jun 2026Jul–Dec 2026
Requests received — India[n]Reporting
Requests received — Australia[n]Reporting
Requests received — other jurisdictions[n]Reporting
Complied with in full[n]Reporting
Complied with in part after narrowing[n]Reporting
Refused or challenged[n]Reporting
Redirected to the customer as data controller[n]Reporting
Emergency disclosures[n]Reporting
Preservation demands received[n]Reporting
Customers affected[n]Reporting
Instances where we were prohibited from notifying the customer[n]Reporting

Methodology and what we require before disclosing anything: Government and Law Enforcement Requests. A zero is reported as zero.

3.2 Acceptable Use enforcement

MetricJan–Jun 2026
Misuse reports received[n]
Investigations opened[n]
Capabilities or accounts suspended[n]
Contracts terminated for breach[n]
Prospective deployments declined at review[n]

3.3 Privacy, grievances and model harm

MetricJan–Jun 2026
Data Principal / individual rights requests received[n]
Responded within the statutory period[n]
Routed to a customer as the responsible entity[n]
Grievances received under IT Rules 2021 r.3(2)[n]
Disposed within 15 days[n]
Model harm reports received[n]
Resulting threshold changes or capability withdrawals[n]
Accessibility barriers reported[n]

3.4 Security

MetricJan–Jun 2026
Vulnerability reports received[n]
Valid and remediated[n]
Median time to remediate — critical[n] days
Reportable incidents notified to CERT-In[n]
Eligible data breaches notified to the OAIC[n]
Customers notified of an incident affecting their data[n]

4. Document change log

DateDocumentVersionChangeNotice
22 Aug 2026Terms and Conditions3.0Rewritten as a master agreement. India and Australia country terms added; Australian Consumer Law preserved at cl.18.2; US-specific provisions removed30 days
22 Aug 2026Privacy Policy3.0Re-based on DPDP 2023 and the Privacy Act 1988. Country supplements introduced30 days
22 Aug 2026Biometric, ANPR and Facial Recognition Policy2.0Replaces the License Plate Reader Policy. BIPA/CCPA/CJIS/NCIC references removed; retention ceilings and enrolment requirements added30 days
22 Aug 2026Government and Law Enforcement Requests2.0Replaces the DECTIFY Evidence Policy. Re-based on BNSS s.94, IT Act s.69/91, the Australian warrant regime and MLAT30 days
22 Aug 2026API and Integration Terms2.0Rate limits, model-output obligations and a 90-day deprecation window added30 days
22 Aug 2026Intellectual Property and Trademark Notice2.0Mark table added; permitted referential use and logo rules stated—
22 Aug 2026Acceptable Use Policy1.0New—
22 Aug 2026Data Retention Schedule1.0New. Canonical periods for every data class—
22 Aug 2026Data Processing Addendum1.0New. DPDP Data Processor, APP 8 and GDPR Art. 28 tracks—
22 Aug 2026Sub-processors1.0New. 30-day change notice and objection right—
22 Aug 2026Grievance Redressal1.0New. Statutory officers and timelines published—
22 Aug 2026All country and remaining documents1.0New — see the hub index—

Documents removed in this revision, as inapplicable outside the United States: State-Specific Contractual Provisions, Downstream Subcontractor Business Associate Addendum (HIPAA), and the Part 91 Operational Agreement. Aerial operations are now governed by the Drone Rules 2021 and CASR Part 101 under Product-Specific Terms, Schedule H.

5. Security advisories

DateAdvisorySeverityAffectedAction
—No advisories published to date———

Subscribe to advisories by emailing security@dectify.in with the subject "advisory notifications". Service status and incident history: [status page URL].

6. How to get what you need

You needAsk
Audit reports, certificates, pen test summary, ISM or Essential Eight mappingsecurity@dectify.in — under NDA
A completed security questionnaire (CAIQ, SIG, agency-specific)security@dectify.in
A countersigned DPA, or the SCCs executedlegal@dectify.in
An accessibility conformance report (WCAG, IS 17802, AS EN 301 549)accessibility@dectify.in
A software bill of materialsopensource@dectify.in
Model cards and evaluation dataresponsible-ai@dectify.in
A deletion certificateprivacy@dectify.in

7. Review cadence

This page is updated quarterly and whenever a certification, designation or advisory changes. The transparency report is published within sixty (60) days of the end of each reporting period. Prior versions of any document in this hub are available from legal@dectify.in.

Contact

Questions about this document: legal@dectify.in

DECTIFY Technologies Pvt. Ltd., New Delhi, India