Ramsio Verify is engineered so the controls auditors look for are already in place — across security, privacy, payments, and AI governance, for both Indian and global markets.
Building the controls in advance turns an audit into evidence collection rather than a scramble. It does not, by itself, grant a certificate: a SOC 2 report or an ISO certificate still requires formal policies, an evidence period, and an independent accredited auditor. We state the honest status of each framework below and do not claim certifications we do not yet hold.
Built in — the control operates in the product today. Readiness — controls are implemented and mapped; a formal certificate awaits an independent audit. In progress — active work toward a dated requirement.
Trust Services Criteria — security, availability, confidentiality
Access control, encryption, audit logging, change management, and monitoring are implemented and mapped to the Trust Services Criteria. A Type II report requires an observation period and an accredited auditor — that engagement is planned, not yet completed.
Information Security Management System (ISMS)
Controls map to Annex A (A.5, A.8, A.8.15, A.8.24-28). Certification requires an accredited certification-body audit, which is planned.
AI Management System
AI features are governed with human-in-the-loop oversight and an impact-assessment process. Formal certification is on the roadmap.
Limited-risk AI + Article 50 transparency
AI-assisted features are classified limited-risk (decision support with human oversight). Machine-readable transparency labelling for AI-generated text is being finalised ahead of the August 2026 deadline.
EU / EEA personal data protection
Data-subject requests (access, deletion, portability, rectification), consent versioning, retention controls, and a breach-response process are built into the product.
California consumer privacy
A "Do Not Sell or Share My Personal Information" flow and the full data-subject request queue are available out of the box.
India — Digital Personal Data Protection
A published Grievance Officer route and consent versioning ship today. A verifiable consent-manager enhancement is in progress ahead of the Act's enforcement timeline.
Payment card data
All card data is tokenised through hosted Stripe and Razorpay checkout flows. No primary account numbers ever touch our servers, which keeps the platform in the smallest SAQ-A scope.
Where Ramsio Verify uses AI, it does so to assist, never to decide. AI-assisted output — summaries, recommendations, and draft text — is advisory and kept under human review; it is never applied automatically.
The third parties the platform relies on. Each is engaged under a data processing agreement; the current list is maintained for customers on request.
| Provider | Purpose |
|---|---|
| Google Cloud Platform | Hosting, database, secrets |
| Stripe | Global payments (tokenised — no card data stored) |
| Razorpay | India payments (tokenised — no card data stored) |
| Anthropic (Claude) | AI-assisted, advisory features |
| Resend | Transactional email |
| Twilio | SMS one-time codes (when MFA via SMS is enabled) |
| Sentry | Error monitoring (PII scrubbed before send) |
The platform team supports internal security reviews and integration-specific data processing agreements for any product connecting to Ramsio Verify.
Contact the Platform Team