Everything your security review will ask.
Eazyware is the engineering brand of EasyGenTech Innovations Pvt Ltd, an Indian private limited company. We hold client data under a signed DPA, process it in the region you choose, restrict access to the engineers on your project, keep an audit trail of automated decisions, and hand over code, prompts and infrastructure definitions on payment. This page answers the questions a security review asks, without a call.
Last updated 19 September 2026
Data protection
- A Data Processing Agreement is signed before any client data is shared, covering purpose, retention, sub-processors, breach notification and deletion.
- We process personal data under India's DPDP Act 2023 and, for EU clients, as a processor under GDPR Article 28.
- Retention is set per engagement. On request or at contract end, we delete client data from primary stores within 30 days and from backups within 90.
- We do not train models on client data, and we do not allow model providers to. Zero-retention or no-training terms are confirmed in writing per provider before use.
Access control
- Access is limited to the engineers assigned to your project, reviewed at every phase change and revoked on rotation off the team.
- Multi-factor authentication on every account that touches client systems or data.
- Production credentials are held in a managed secret store, never in code, tickets or chat.
- We ask for the narrowest access that completes the work — read-only or sandbox first, production last.
Engineering practice
- Code review before merge; no direct commits to protected branches.
- Dependency and secret scanning in CI on every push.
- Environments are separated: development, staging and production never share data or credentials.
- Infrastructure is defined in code, so what runs in production is reviewable and reproducible.
AI-specific controls
- Retrieval is permission-aware: an answer can only be built from documents the asking user could open themselves.
- Evaluation suites gate releases; a prompt or model change that regresses accuracy does not ship.
- Guardrails are enforced in code, not in prompts: allowed actions, spend limits, approval gates and policy checks before execution.
- Every automated decision is logged with inputs, outputs, model version, user and timestamp, retained per your policy.
- Prompt-injection attempts are part of the evaluation suite, so a defence that weakens fails before release.
Residency and deployment
- Default processing region is India. EU, UK, US and Singapore regions are available on request.
- Private deployment inside your VPC or data centre is supported, with open-weight models covering retrieval and extraction so regulated data never leaves your perimeter.
- Where a hosted model provider is used, the region and retention terms are stated in the proposal before work starts.
Continuity
- Client repositories, infrastructure definitions and documentation are handed over continuously, not at the end.
- Backups are automated and restore-tested per engagement; restore targets are agreed in the care plan.
- Care plans define response and resolution targets, and a named escalation contact.
Certifications, honestly stated
We list what we hold and what we do not. A vendor that implies a certificate it has not been issued is telling you something about how it will handle your data.
DPDP Act 2023 alignment
In effectNotice, lawful basis, retention limits, grievance officer and rights of access and erasure are implemented in our processes and in the systems we build.
GDPR (as processor)
In effectArticle 28 processor terms available in our DPA for EU clients.
ISO/IEC 27001
PlannedControls are being implemented against the standard; certification is targeted but not yet held. We will not claim it until an auditor issues it.
SOC 2 Type II
Not heldNot pursued yet. For clients who require it, we work inside your certified environment instead.
Sub-processors
Third parties that may process client data, and why. Named contacts are notified at least 30 days before this list changes for your project.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Application and database hosting | ap-south-1 (Mumbai) by default; client region on request |
| Google Cloud Platform | Application hosting and AI services, where selected | asia-south1 by default |
| MongoDB Atlas | Managed database | Client-selected region |
| OpenAI | Language and embedding models, where selected | US; zero-retention terms confirmed per project |
| Anthropic | Language models, where selected | US; zero-retention terms confirmed per project |
| Google (Gemini) | Language and embedding models, where selected | Per project configuration |
| Cloudflare | DNS, CDN and DDoS protection | Global edge |
| Google Workspace | Internal email and documents | India and US |
| Slack | Internal and shared client channels | US |
What you can request
Email hello@theeazyware.com with the subject "Trust centre request" and a named engineer responds, not a form.
Request documents- Data Processing Agreement
- Sent on request before any data is shared; we can sign yours or provide ours.
- Security questionnaire
- We complete standard questionnaires (CAIQ, VSA or your own) within five working days.
- Penetration test results
- We commission tests per engagement where scope warrants; summary reports are shared under NDA.
- Sub-processor change notice
- Named contacts are notified at least 30 days before a new sub-processor handles your data.
- Deletion or export request
- Actioned within 30 days; a written confirmation of deletion is issued.
Frequently asked questions
Do you train AI models on our data?
▾
No. We do not train on client data, and we confirm no-training and zero-retention terms with each model provider in writing before that provider is used on your project.
Where is our data processed?
▾
India (ap-south-1) by default. EU, UK, US and Singapore are available, and private deployment inside your own environment is supported where residency rules require it.
Who at Eazyware can see our systems?
▾
Only the engineers assigned to your project, with multi-factor authentication and the narrowest access that completes the work. Access is reviewed at every phase change and revoked on rotation off the team.
Are you ISO 27001 or SOC 2 certified?
▾
Not yet. We implement controls against ISO/IEC 27001 and are targeting certification, but we will not claim a certificate we do not hold. For clients who require one today, we work inside your certified environment.
What happens to our data when the engagement ends?
▾
Primary stores are deleted within 30 days and backups within 90, with written confirmation. Code, prompts, fine-tuned weights and infrastructure definitions are yours and are handed over.
How do you handle a security incident?
▾
Named contacts are notified without undue delay and within 72 hours of becoming aware, with what happened, what data was involved, what we have done and what we recommend. The DPA sets this out contractually.
See also Security, Privacy policy and Terms of service.