Vernacore
Security and data handling

Written for the person who has to sign this off

Where your data lives, who can touch it, what we'll sign, and — the part vendors usually leave out — what we haven't done yet.

Premises and access

The physical controls are most of the answer

For this kind of work, a supervised room does more for your data than a certificate does. Here is what that means concretely.

Work happens on our machines

Client work runs on company laptops in our office. No personal devices, no working from home on your data, no files on a phone.

One room, supervised

The floor is a single supervised space. Anyone touching your process is a named employee we can identify on request.

No removable media

USB storage is disabled on work machines. Where your task genuinely needs export, it goes through an agreed channel only.

Access ends with employment

Accounts are provisioned per person per client, and revoked the day someone leaves the seat — not at the end of the month.

Paperwork

What we'll sign before you send anything

All of this is available before a pilot, not after. Ask and we'll send the drafts.

  • Mutual NDA before we see any sample data
  • Individual confidentiality undertakings signed by every person on your process
  • A written scope naming which staff may access what
  • Deletion or return of your data on request, and at contract end by default
  • Named point of contact for any incident, with a same-day response commitment
Indian law

DPDP Act, in plain terms

The Digital Personal Data Protection Act, 2023 governs personal data in India. If your batches contain personal data, this is the shape of the arrangement.

You are the Data Fiduciary

You decide why and how the data is processed. Consent, notice and the lawful basis sit with you, and we don't use your data for anything other than your task.

We are a Data Processor

We act only on your written instructions, under contract, with the access controls above — and we delete or return the data when you tell us to, or when the contract ends.

This is a description of how we work, not legal advice. Your counsel should review any agreement before you sign it.

What we haven't done

The gaps, before you find them

We are not ISO 27001 or SOC 2 certified

Those are real, expensive audits and we have not done them. Anyone our size claiming otherwise is worth a second look.

We are not a data controller for you

We process what you send us, on your instructions, for your purposes. Your privacy notice and lawful basis stay yours.

We do not subcontract without telling you

Your work stays on our floor. If a task ever needed an outside specialist, you would be asked first, in writing.

If your process needs something stricter

Some clients need controls we don't have yet — a segregated room, device-level DLP, or a specific certification. Tell us at scoping.

If it's something we can put in place for your engagement, we'll quote it honestly. If it isn't, we'll say so and you can go elsewhere with two weeks intact rather than two months.