Framework coverage
Every framework we track — current posture and what evidence is available.
GDPR
CompliantEU AI Act Art. 50
CompliantIndia DPDP 2023
CompliantPCI DSS SAQ-A
In progressSOC 2 Type II
In progressISO 27001
In progressISO 42001
In progressData minimisation, subject access rights (access, correction, deletion, export), data-processing terms with all sub-processors, 72-hour breach notification, tamper-evident audit logs.
DPA available on request
Machine-readable AI-output labeling embedded in all translated files. X-AI-Generated and X-AI-Disclosure HTTP headers on every download. August 2026 deadline met early.
Technical implementation available for review
Consent capture, data principal rights, breach notification (72 h), Records of Processing Activities, and data fiduciary designation all implemented. DPDP Consent Manager integration underway (November 2026 deadline).
RoPA available on request
No card data is handled or stored on Vernacia infrastructure. Payments are fully tokenized through Stripe (global) and Razorpay (India), keeping scope within the simplest SAQ-A posture.
Self-assessment in progress
14 formal security policies approved v1.0. All technical controls implemented and in production. Evidence collection window opens at production launch. Report expected Q1 2027.
SOC 2 report under NDA (post-certification)
Statement of Applicability complete. All 93 controls mapped across every Annex A domain. Control catalog cross-referenced to SOC 2 and ISO 42001. Stage 1 audit targeted Q3 2026.
SoA and control documentation available on request
AI management system controls mapped. AI impact assessment complete. Bias and quality controls documented in the AI Governance Policy. Certification planned post-SOC 2.
AI impact assessment available on request
Formal policy library
14 written, version-controlled, owner-approved policies covering every major compliance domain. Auditors require these alongside technical controls — we have both.
All v1.0 — approved 2026-06-16
Information Security Policy
ISO 27001 · SOC 2
Access Control Policy
SOC 2 CC6 · ISO A.5
Change Management Policy
SOC 2 CC8 · ISO A.8.32
Data Protection & Privacy Policy
GDPR · DPDP
Data Retention & Deletion Policy
GDPR · DPDP · SOC 2
Incident Response Plan
SOC 2 CC7 · ISO A.5.24–28 · GDPR/DPDP
Business Continuity & DR Plan
SOC 2 A1 · ISO A.5.29
Vendor & Sub-processor Management Policy
SOC 2 CC9 · ISO A.5.19 · GDPR Art.28
Risk Assessment & Treatment Policy
ISO 27001 Clause 6 · SOC 2 CC3
Acceptable Use Policy
SOC 2 · ISO A.5.10
AI Governance Policy
ISO 42001 · EU AI Act · NIST AI RMF
AI Acceptable Use & Transparency Policy
EU AI Act Art.50
Secure Development Policy
SOC 2 · ISO A.8.25–28
Cryptography Policy
SOC 2 · ISO A.8.24 · PCI DSS
Trust documents
Public documents your legal and procurement teams need.
Data Processing Agreement
Standard DPA for GDPR Art. 28 / India DPDP compliance. Available on request for Enterprise customers.
Privacy Policy
How we collect, process, and protect your personal data. Includes data fiduciary / controller details.
Security Overview
Technical controls: TLS 1.3, AES-256, audit logging, RBAC, MFA, and vulnerability disclosure.
Sub-processor List
Full list of third-party services (OpenAI, Google Cloud Translation, our cloud hosting provider, Resend, Sentry, Stripe, Razorpay, Twilio) with data categories.
Compliance team inquiry
Need to complete a vendor security questionnaire, request evidence for an audit, arrange a security review call, or execute a DPA? Email us — we respond within one business day.
Vernacia is a product of CloudServe Digital, a division of CloudServe Infotech (RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED).
CIN: U62091KA2025PTC210162 · GST: 29AAPCR1639E1Z3
#36, WeWork Prestige Central, Infantry Road,
Mahatma Gandhi Road, Bengaluru – 560001, Karnataka, India
Tel: +91-9110618988