PricorisTechnologies

Trust and hosting

Where the products run, what they keep, and what they never see.

Where the products run

Self hosted in your own India region cloud, next to the data, or hosted by us on an India region provider under a data processing agreement naming Pricoris Technologies Pvt Ltd as the processor. The public demos run on Render in Singapore with synthetic data only.

What the products keep

PII Discovery stores masked samples, never the value found. Connection passwords, mailbox passwords and API tokens are used for a scan and discarded. Consent and Rights stores what the data principal gave and the record of what was done with it; guardian verification stores a masked proof, never an Aadhaar number.

Integrity

Evidence and documents carry SHA-256 hashes and an exportable manifest. Consent artefacts are hash chained. Every scan, export and change is in an audit trail with the user and the time.

Access

Owner, analyst and viewer roles; MFA; single sign on with SAML or OIDC; read only, least privilege connections to your sources; the operator console never exposes a data principal's raw values.

Assurance we hold today

No certifications yet; the company is new. The products are built and operated by a team that implements ISO 27001, 27701 and 42001 for clients, and the same controls are applied to ourselves. We will publish certifications here when they are issued, not before.

Reporting a vulnerability

Write to sandhya@pricoris.in with the product, the version and the steps. We acknowledge within two working days and do not pursue researchers acting in good faith.