Security & Data Protection
Your training material is often the most sensitive document a company owns. This page sets out exactly how we handle it — including the parts most vendors leave out.
Your content is not training data
We do not use your uploaded documents, voice recordings or facial data to train, fine-tune or improve any model — ours or anyone else's. Custom voice and avatar models are partitioned to your account and are never applied to another customer's output. We do not sell personal data and we do not share it with advertisers or data brokers.
Where AI processing happens
This is the question enterprise reviewers ask most, and the one most answers dodge. Ours has two parts, and the second is the one worth reading.
Narration, imagery, motion and presenter generation run on models we host on compute we control. That content is not sent to any external model provider. Most tools in this category are assembling calls to third-party generation APIs; we are not, and that is our single strongest data-protection property.
The production-planning stage is the exception, and we state it rather than bury it. Your source text is sent to Google Cloud Vertex AI to produce the lesson blueprint. That is a processing relationship governed by Google Cloud's enterprise terms, under which customer data submitted to Vertex AI is not used to train Google's foundation models. Your text is processed and returned — it does not become anyone's training data.
If your policy prohibits third-party model processing entirely, raise it during evaluation. It is addressable under an enterprise agreement.
Technical measures
Encryption in transit
TLS 1.3 enforced on every endpoint. HTTP is redirected, never served.
Encryption at rest
AES-256 server-side encryption on all object storage.
Tenant isolation
Every object is written under a path keyed to the authenticated account, and authorisation is evaluated per request rather than assumed from the client.
No passwords held
Authentication is delegated to a managed identity provider. We never receive or store a password.
Signed video delivery
HLS with short-expiry, HMAC-signed playback authorisations verified per request. A leaked link does not become a permanent public one.
No card data
Payments are handled entirely by a PCI-DSS compliant processor. Card details never reach our systems.
Fail-closed admin access
Administrative surfaces are gated by a server-side allowlist that denies access when it is unset or unreadable, rather than permitting it.
Edge protection
Global CDN with DDoS mitigation and a WAF in front of every public endpoint.
Data residency
We separate where data is stored from where it is briefly processed, because those are different answers and merging them would misrepresent our position.
- At rest — Asia-Pacific (APAC). All databases and object storage: profiles, generated videos, uploaded source documents, voice models, invoices and analytics.
- In processing — multi-region, transient. Rendering and inference run in the United States, India (Mumbai), Singapore, and for certain speech synthesis Western Europe and Sweden. Content is held only for the duration of the job, then written back to APAC storage.
- No restricted transfers. We do not transfer personal data to any territory restricted by the Government of India under Section 16 of the DPDP Act, 2023.
- Region-pinned processing can be arranged under an enterprise agreement. It is not available on self-serve plans — raise it before onboarding, not after.
Retention
Every store has an enforced upper bound applied on a timer that runs independently of whether you ever sign in again. Retention that only triggers when an account owner returns retains nothing for inactive accounts — which is precisely the data that should age out.
| Data | Bound |
|---|---|
| Generated videos and lesson history | 100 most recent per account, maximum 180 days |
| Custom voice models and recordings | Maximum 20 per account, deleted 90 days after last use |
| Intermediate render artefacts | 72 hours — purged immediately on delivery |
| Temporary render workspaces | 24 hours |
| Job logs | 6 hours |
| Enterprise hosting content and rosters | Deleted 45 days after subscription expiry |
| Account deletion | 30-day restorable grace period, then permanent purge |
| Invoices and financial records | Retained as required by Indian law (up to 8 years) |
Sub-processors
Complete as at this page's last update. We update it before adding any new sub-processor that processes customer content.
| Sub-processor | Purpose |
|---|---|
| Cloudflare | Edge delivery, object storage, serverless databases, DDoS protection |
| Amazon Web Services | GPU compute instances we operate and control |
| Microsoft Azure | Containerised render workers; speech synthesis |
| Google Cloud (Vertex AI) | Production-planning stage; certain image generation |
| Google Firebase | Authentication and identity |
| Razorpay | Payment processing (India) |
| Upstash | Job queueing and ephemeral cache |
What we are certified for — and what we are not
We would rather lose a deal on this section than win one and fail diligence later.
- We do not hold ISO/IEC 27001 certification. We do not hold a SOC 2 attestation. We do not claim either. Any document representing otherwise is not ours, and we would like to hear about it.
- No independent penetration test has been commissioned to date. It is on our roadmap.
- Our infrastructure providers are certified — Cloudflare, Amazon Web Services, Microsoft Azure and Google Cloud are all ISO/IEC 27001 certified and SOC 2 audited. That covers the physical, network and hypervisor layers beneath our application. It is not a certification of Examiverse and we will not present it as one.
- Card payments are PCI-DSS compliant at the processor. We are out of scope because we never receive, transmit or store cardholder data.
- We align to the DPDP Act 2023, GDPR and CCPA as described in our Privacy Policy.
Formal certification is on our roadmap and will be pursued as our enterprise customers require it. If it is a hard gate for your organisation, tell us — knowing a real contract depends on it changes when we start.
Documents
Each of these opens as a readable page with a contents rail, and prints straight to PDF if your procurement process needs a file to attach.
Contact
Security issues and vulnerability reports: admin@examiverse.com with "Security" in the subject. We do not pursue legal action against researchers who report in good faith, allow reasonable time to remediate, and do not access or destroy other users' data.
Grievance Officer: Darshan A C, Grievance Officer & Co-founder — admin@examiverse.com. Grievances are acknowledged within 24 hours and resolved within 30 days.
Examiverse Technologies Private Limited · CIN U62011KA2026PTC214753 · 73, KST Town, Valagerehalli, Kengeri, Bangalore South, Bengaluru – 560060, Karnataka, India