Legal
Security overview
How Bhavyaruni is built and operated, and what a security review will find.
This is a summary, not a contract. Bhavyaruni is a demonstration product. In a live deployment this page would carry the full executed document, with a version history and an effective date. The substance below reflects the commitments the product is actually built to keep.
Architecture
- Tenant isolation is enforced at the data layer. A query without a tenant scope does not execute — this is a database-level constraint, not an application-level convention.
- All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Key rotation is automated and audited.
- Infrastructure is deployed from version-controlled configuration. There is no manual production access outside a break-glass procedure that alerts the whole engineering team.
Access and identity
- SAML 2.0 and OIDC single sign-on, SCIM 2.0 provisioning and de-provisioning, and enforceable MFA for accounts not behind SSO.
- Role-based access control with permission-level granularity. A manager sees their own line and nothing else, enforced server-side.
- Every privileged action is written to an immutable audit log with actor, timestamp, tenant and before/after state.
Application security
- Input validation and output encoding on every boundary; parameterised queries throughout, so SQL injection is structurally prevented rather than filtered.
- Uploads are validated by content type and scanned before they are made available; they are served from an isolated origin so a malicious file cannot execute in the application's context.
- Rate limiting on authentication, AI and export endpoints. Session tokens are rotated on privilege change and invalidated server-side on logout.
- Dependencies are scanned continuously, and an independent penetration test is run annually with the report available under NDA.
Operations
- 99.9% uptime SLA for Enterprise, with 99.98% achieved over the trailing twelve months.
- Backups every 15 minutes with a tested restore procedure; recovery point objective 15 minutes, recovery time objective 4 hours.
- Security incidents are disclosed to affected customers within 24 hours of confirmation, with a full postmortem within five working days.
Questions about this document? Contact us. Last reviewed 4 September 2026.
