Compliance and Security Updates
Certification status, audit reports, the change log for every document in this hub, and the semi-annual transparency report. Status, not aspiration.
Three words, three different meanings. Certified means an accredited body has issued a certificate we can show you. Assessed means an independent third party examined us and produced a report. Aligned means we have mapped our controls to a framework ourselves and nobody external has checked. We use the third word only where it is true, and we never use it to imply either of the others.
1. Certification and assurance status
| Framework | Status | Scope | Issued / assessed | Next |
|---|---|---|---|---|
| ISO/IEC 27001:2022 | [status] | Platform, HUB, supporting operations | [date] | [date] |
| ISO/IEC 27701 (privacy) | [status] | — | — | [date] |
| SOC 2 Type II | [status] | Security, availability, confidentiality | [period] | [date] |
| IRAP assessment (Australia) | [status] | [classification] | [date] | [date] |
| Essential Eight maturity | [assessed level] | Corporate and production estate | [date] | [date] |
| STQC / MeitY empanelment (India) | [status] | — | — | [date] |
| Independent penetration test | [status] | Platform, API, edge | [date] | Annual |
| Independent model bias evaluation | [status] | FaceTrack, DriveLink | [date] | [date] |
Reports are available to customers and qualified prospective customers under NDA. Request from security@dectify.in. Where a row says a certification is in progress or not held, that is the accurate position and we will not describe it otherwise in a tender response.
2. Statutory registrations and officers
| CERT-In Point of Contact | [name] — registered |
| Grievance Officer (IT Rules 2021) | Named at Grievance Redressal |
| Data Protection Officer contact (DPDP s.8(9)) | Named at Grievance Redressal |
| Significant Data Fiduciary designation (DPDP s.10) | Not designated |
| SOCI Act responsible entity (Australia) | Not a responsible entity for a declared asset |
| Modern Slavery Act 2018 reporting entity | Below threshold — not a reporting entity |
| Australian entity / ABN | None. Australian customers contract with the Indian entity |
3. Transparency report
Published semi-annually, covering January to June and July to December.
3.1 Government and law enforcement requests
| Metric | Jan–Jun 2026 | Jul–Dec 2026 |
|---|---|---|
| Requests received — India | [n] | Reporting |
| Requests received — Australia | [n] | Reporting |
| Requests received — other jurisdictions | [n] | Reporting |
| Complied with in full | [n] | Reporting |
| Complied with in part after narrowing | [n] | Reporting |
| Refused or challenged | [n] | Reporting |
| Redirected to the customer as data controller | [n] | Reporting |
| Emergency disclosures | [n] | Reporting |
| Preservation demands received | [n] | Reporting |
| Customers affected | [n] | Reporting |
| Instances where we were prohibited from notifying the customer | [n] | Reporting |
Methodology and what we require before disclosing anything: Government and Law Enforcement Requests. A zero is reported as zero.
3.2 Acceptable Use enforcement
| Metric | Jan–Jun 2026 |
|---|---|
| Misuse reports received | [n] |
| Investigations opened | [n] |
| Capabilities or accounts suspended | [n] |
| Contracts terminated for breach | [n] |
| Prospective deployments declined at review | [n] |
3.3 Privacy, grievances and model harm
| Metric | Jan–Jun 2026 |
|---|---|
| Data Principal / individual rights requests received | [n] |
| Responded within the statutory period | [n] |
| Routed to a customer as the responsible entity | [n] |
| Grievances received under IT Rules 2021 r.3(2) | [n] |
| Disposed within 15 days | [n] |
| Model harm reports received | [n] |
| Resulting threshold changes or capability withdrawals | [n] |
| Accessibility barriers reported | [n] |
3.4 Security
| Metric | Jan–Jun 2026 |
|---|---|
| Vulnerability reports received | [n] |
| Valid and remediated | [n] |
| Median time to remediate — critical | [n] days |
| Reportable incidents notified to CERT-In | [n] |
| Eligible data breaches notified to the OAIC | [n] |
| Customers notified of an incident affecting their data | [n] |
4. Document change log
| Date | Document | Version | Change | Notice |
|---|---|---|---|---|
| 22 Aug 2026 | Terms and Conditions | 3.0 | Rewritten as a master agreement. India and Australia country terms added; Australian Consumer Law preserved at cl.18.2; US-specific provisions removed | 30 days |
| 22 Aug 2026 | Privacy Policy | 3.0 | Re-based on DPDP 2023 and the Privacy Act 1988. Country supplements introduced | 30 days |
| 22 Aug 2026 | Biometric, ANPR and Facial Recognition Policy | 2.0 | Replaces the License Plate Reader Policy. BIPA/CCPA/CJIS/NCIC references removed; retention ceilings and enrolment requirements added | 30 days |
| 22 Aug 2026 | Government and Law Enforcement Requests | 2.0 | Replaces the DECTIFY Evidence Policy. Re-based on BNSS s.94, IT Act s.69/91, the Australian warrant regime and MLAT | 30 days |
| 22 Aug 2026 | API and Integration Terms | 2.0 | Rate limits, model-output obligations and a 90-day deprecation window added | 30 days |
| 22 Aug 2026 | Intellectual Property and Trademark Notice | 2.0 | Mark table added; permitted referential use and logo rules stated | — |
| 22 Aug 2026 | Acceptable Use Policy | 1.0 | New | — |
| 22 Aug 2026 | Data Retention Schedule | 1.0 | New. Canonical periods for every data class | — |
| 22 Aug 2026 | Data Processing Addendum | 1.0 | New. DPDP Data Processor, APP 8 and GDPR Art. 28 tracks | — |
| 22 Aug 2026 | Sub-processors | 1.0 | New. 30-day change notice and objection right | — |
| 22 Aug 2026 | Grievance Redressal | 1.0 | New. Statutory officers and timelines published | — |
| 22 Aug 2026 | All country and remaining documents | 1.0 | New — see the hub index | — |
Documents removed in this revision, as inapplicable outside the United States: State-Specific Contractual Provisions, Downstream Subcontractor Business Associate Addendum (HIPAA), and the Part 91 Operational Agreement. Aerial operations are now governed by the Drone Rules 2021 and CASR Part 101 under Product-Specific Terms, Schedule H.
5. Security advisories
| Date | Advisory | Severity | Affected | Action |
|---|---|---|---|---|
| — | No advisories published to date | — | — | — |
Subscribe to advisories by emailing security@dectify.in with the subject "advisory notifications". Service status and incident history: [status page URL].
6. How to get what you need
| You need | Ask |
|---|---|
| Audit reports, certificates, pen test summary, ISM or Essential Eight mapping | security@dectify.in — under NDA |
| A completed security questionnaire (CAIQ, SIG, agency-specific) | security@dectify.in |
| A countersigned DPA, or the SCCs executed | legal@dectify.in |
| An accessibility conformance report (WCAG, IS 17802, AS EN 301 549) | accessibility@dectify.in |
| A software bill of materials | opensource@dectify.in |
| Model cards and evaluation data | responsible-ai@dectify.in |
| A deletion certificate | privacy@dectify.in |
7. Review cadence
This page is updated quarterly and whenever a certification, designation or advisory changes. The transparency report is published within sixty (60) days of the end of each reporting period. Prior versions of any document in this hub are available from legal@dectify.in.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India