Encryption, PII redaction, consent capture and audit trails are first-class — not legal fine print. Built on AWS, designed to meet PCI and HIPAA bars from day one, with ISO 27001, SOC 2 and DPDP attestations in progress.
We will only list a certification when it is real and current. Anything else is shown as in-progress.
Card data handled per Payment Card Industry Data Security Standard.
Architecture is HIPAA-eligible on AWS; BAA available for regulated workloads.
Validated AWS expertise across RDS, ECS, Lambda, WAF and CloudFormation — the stack that runs OZOO.ai.
Information security management system.
Independent attestation of security, availability and confidentiality controls.
Aligned with India's Digital Personal Data Protection Act: consent capture, data minimisation, breach reporting.
AES-256 at rest, TLS 1.2+ in transit across every service in the pipeline.
Cards, Aadhaar, PAN, mobile numbers and account IDs auto-masked before persistence and before they reach analytics.
India region by default for Indian customers; configurable to US and EU regions for global deployments.
Configurable consent prompts for inbound and outbound calls; recording disclosure logged with timestamp and channel.
Per-tenant retention windows; programmatic right-to-erasure honoured within SLA across S3, DynamoDB and Athena layers.
Every supervisor and admin action — call replay, transcript export, score override — is logged and exportable.
Tell us your compliance review needs and we'll share what's relevant. We respond within one business day.