azyware
Trust centre

Everything your security review will ask.

Eazyware is the engineering brand of EasyGenTech Innovations Pvt Ltd, an Indian private limited company. We hold client data under a signed DPA, process it in the region you choose, restrict access to the engineers on your project, keep an audit trail of automated decisions, and hand over code, prompts and infrastructure definitions on payment. This page answers the questions a security review asks, without a call.

Last updated 19 September 2026

Data protection

  • A Data Processing Agreement is signed before any client data is shared, covering purpose, retention, sub-processors, breach notification and deletion.
  • We process personal data under India's DPDP Act 2023 and, for EU clients, as a processor under GDPR Article 28.
  • Retention is set per engagement. On request or at contract end, we delete client data from primary stores within 30 days and from backups within 90.
  • We do not train models on client data, and we do not allow model providers to. Zero-retention or no-training terms are confirmed in writing per provider before use.

Access control

  • Access is limited to the engineers assigned to your project, reviewed at every phase change and revoked on rotation off the team.
  • Multi-factor authentication on every account that touches client systems or data.
  • Production credentials are held in a managed secret store, never in code, tickets or chat.
  • We ask for the narrowest access that completes the work — read-only or sandbox first, production last.

Engineering practice

  • Code review before merge; no direct commits to protected branches.
  • Dependency and secret scanning in CI on every push.
  • Environments are separated: development, staging and production never share data or credentials.
  • Infrastructure is defined in code, so what runs in production is reviewable and reproducible.

AI-specific controls

  • Retrieval is permission-aware: an answer can only be built from documents the asking user could open themselves.
  • Evaluation suites gate releases; a prompt or model change that regresses accuracy does not ship.
  • Guardrails are enforced in code, not in prompts: allowed actions, spend limits, approval gates and policy checks before execution.
  • Every automated decision is logged with inputs, outputs, model version, user and timestamp, retained per your policy.
  • Prompt-injection attempts are part of the evaluation suite, so a defence that weakens fails before release.

Residency and deployment

  • Default processing region is India. EU, UK, US and Singapore regions are available on request.
  • Private deployment inside your VPC or data centre is supported, with open-weight models covering retrieval and extraction so regulated data never leaves your perimeter.
  • Where a hosted model provider is used, the region and retention terms are stated in the proposal before work starts.

Continuity

  • Client repositories, infrastructure definitions and documentation are handed over continuously, not at the end.
  • Backups are automated and restore-tested per engagement; restore targets are agreed in the care plan.
  • Care plans define response and resolution targets, and a named escalation contact.

Certifications, honestly stated

We list what we hold and what we do not. A vendor that implies a certificate it has not been issued is telling you something about how it will handle your data.

DPDP Act 2023 alignment

In effect

Notice, lawful basis, retention limits, grievance officer and rights of access and erasure are implemented in our processes and in the systems we build.

GDPR (as processor)

In effect

Article 28 processor terms available in our DPA for EU clients.

ISO/IEC 27001

Planned

Controls are being implemented against the standard; certification is targeted but not yet held. We will not claim it until an auditor issues it.

SOC 2 Type II

Not held

Not pursued yet. For clients who require it, we work inside your certified environment instead.

Sub-processors

Third parties that may process client data, and why. Named contacts are notified at least 30 days before this list changes for your project.

ProviderPurposeRegion
Amazon Web ServicesApplication and database hostingap-south-1 (Mumbai) by default; client region on request
Google Cloud PlatformApplication hosting and AI services, where selectedasia-south1 by default
MongoDB AtlasManaged databaseClient-selected region
OpenAILanguage and embedding models, where selectedUS; zero-retention terms confirmed per project
AnthropicLanguage models, where selectedUS; zero-retention terms confirmed per project
Google (Gemini)Language and embedding models, where selectedPer project configuration
CloudflareDNS, CDN and DDoS protectionGlobal edge
Google WorkspaceInternal email and documentsIndia and US
SlackInternal and shared client channelsUS

What you can request

Email hello@theeazyware.com with the subject "Trust centre request" and a named engineer responds, not a form.

Request documents
Data Processing Agreement
Sent on request before any data is shared; we can sign yours or provide ours.
Security questionnaire
We complete standard questionnaires (CAIQ, VSA or your own) within five working days.
Penetration test results
We commission tests per engagement where scope warrants; summary reports are shared under NDA.
Sub-processor change notice
Named contacts are notified at least 30 days before a new sub-processor handles your data.
Deletion or export request
Actioned within 30 days; a written confirmation of deletion is issued.

Frequently asked questions

Do you train AI models on our data?

▾

No. We do not train on client data, and we confirm no-training and zero-retention terms with each model provider in writing before that provider is used on your project.

Where is our data processed?

▾

India (ap-south-1) by default. EU, UK, US and Singapore are available, and private deployment inside your own environment is supported where residency rules require it.

Who at Eazyware can see our systems?

▾

Only the engineers assigned to your project, with multi-factor authentication and the narrowest access that completes the work. Access is reviewed at every phase change and revoked on rotation off the team.

Are you ISO 27001 or SOC 2 certified?

▾

Not yet. We implement controls against ISO/IEC 27001 and are targeting certification, but we will not claim a certificate we do not hold. For clients who require one today, we work inside your certified environment.

What happens to our data when the engagement ends?

▾

Primary stores are deleted within 30 days and backups within 90, with written confirmation. Code, prompts, fine-tuned weights and infrastructure definitions are yours and are handed over.

How do you handle a security incident?

▾

Named contacts are notified without undue delay and within 72 hours of becoming aware, with what happened, what data was involved, what we have done and what we recommend. The DPA sets this out contractually.

See also Security, Privacy policy and Terms of service.

Security review in progress?

PRJECT IN MIND?