Trust Centre

Security & Data Protection

Your training material is often the most sensitive document a company owns. This page sets out exactly how we handle it — including the parts most vendors leave out.

TLS 1.3 · AES-256APAC data residencyDPDP Act aligned

Your content is not training data

We do not use your uploaded documents, voice recordings or facial data to train, fine-tune or improve any model — ours or anyone else's. Custom voice and avatar models are partitioned to your account and are never applied to another customer's output. We do not sell personal data and we do not share it with advertisers or data brokers.

Where AI processing happens

This is the question enterprise reviewers ask most, and the one most answers dodge. Ours has two parts, and the second is the one worth reading.

Narration, imagery, motion and presenter generation run on models we host on compute we control. That content is not sent to any external model provider. Most tools in this category are assembling calls to third-party generation APIs; we are not, and that is our single strongest data-protection property.

The production-planning stage is the exception, and we state it rather than bury it. Your source text is sent to Google Cloud Vertex AI to produce the lesson blueprint. That is a processing relationship governed by Google Cloud's enterprise terms, under which customer data submitted to Vertex AI is not used to train Google's foundation models. Your text is processed and returned — it does not become anyone's training data.

If your policy prohibits third-party model processing entirely, raise it during evaluation. It is addressable under an enterprise agreement.

Technical measures

Encryption in transit

TLS 1.3 enforced on every endpoint. HTTP is redirected, never served.

Encryption at rest

AES-256 server-side encryption on all object storage.

Tenant isolation

Every object is written under a path keyed to the authenticated account, and authorisation is evaluated per request rather than assumed from the client.

No passwords held

Authentication is delegated to a managed identity provider. We never receive or store a password.

Signed video delivery

HLS with short-expiry, HMAC-signed playback authorisations verified per request. A leaked link does not become a permanent public one.

No card data

Payments are handled entirely by a PCI-DSS compliant processor. Card details never reach our systems.

Fail-closed admin access

Administrative surfaces are gated by a server-side allowlist that denies access when it is unset or unreadable, rather than permitting it.

Edge protection

Global CDN with DDoS mitigation and a WAF in front of every public endpoint.

Data residency

We separate where data is stored from where it is briefly processed, because those are different answers and merging them would misrepresent our position.

  • At rest — Asia-Pacific (APAC). All databases and object storage: profiles, generated videos, uploaded source documents, voice models, invoices and analytics.
  • In processing — multi-region, transient. Rendering and inference run in the United States, India (Mumbai), Singapore, and for certain speech synthesis Western Europe and Sweden. Content is held only for the duration of the job, then written back to APAC storage.
  • No restricted transfers. We do not transfer personal data to any territory restricted by the Government of India under Section 16 of the DPDP Act, 2023.
  • Region-pinned processing can be arranged under an enterprise agreement. It is not available on self-serve plans — raise it before onboarding, not after.

Retention

Every store has an enforced upper bound applied on a timer that runs independently of whether you ever sign in again. Retention that only triggers when an account owner returns retains nothing for inactive accounts — which is precisely the data that should age out.

DataBound
Generated videos and lesson history100 most recent per account, maximum 180 days
Custom voice models and recordingsMaximum 20 per account, deleted 90 days after last use
Intermediate render artefacts72 hours — purged immediately on delivery
Temporary render workspaces24 hours
Job logs6 hours
Enterprise hosting content and rostersDeleted 45 days after subscription expiry
Account deletion30-day restorable grace period, then permanent purge
Invoices and financial recordsRetained as required by Indian law (up to 8 years)

Sub-processors

Complete as at this page's last update. We update it before adding any new sub-processor that processes customer content.

Sub-processorPurpose
CloudflareEdge delivery, object storage, serverless databases, DDoS protection
Amazon Web ServicesGPU compute instances we operate and control
Microsoft AzureContainerised render workers; speech synthesis
Google Cloud (Vertex AI)Production-planning stage; certain image generation
Google FirebaseAuthentication and identity
RazorpayPayment processing (India)
UpstashJob queueing and ephemeral cache

What we are certified for — and what we are not

We would rather lose a deal on this section than win one and fail diligence later.

  • We do not hold ISO/IEC 27001 certification. We do not hold a SOC 2 attestation. We do not claim either. Any document representing otherwise is not ours, and we would like to hear about it.
  • No independent penetration test has been commissioned to date. It is on our roadmap.
  • Our infrastructure providers are certified — Cloudflare, Amazon Web Services, Microsoft Azure and Google Cloud are all ISO/IEC 27001 certified and SOC 2 audited. That covers the physical, network and hypervisor layers beneath our application. It is not a certification of Examiverse and we will not present it as one.
  • Card payments are PCI-DSS compliant at the processor. We are out of scope because we never receive, transmit or store cardholder data.
  • We align to the DPDP Act 2023, GDPR and CCPA as described in our Privacy Policy.

Formal certification is on our roadmap and will be pursued as our enterprise customers require it. If it is a hard gate for your organisation, tell us — knowing a real contract depends on it changes when we start.

Documents

Each of these opens as a readable page with a contents rail, and prints straight to PDF if your procurement process needs a file to attach.

Contact

Security issues and vulnerability reports: admin@examiverse.com with "Security" in the subject. We do not pursue legal action against researchers who report in good faith, allow reasonable time to remediate, and do not access or destroy other users' data.

Grievance Officer: Darshan A C, Grievance Officer & Co-founder — admin@examiverse.com. Grievances are acknowledged within 24 hours and resolved within 30 days.

Examiverse Technologies Private Limited · CIN U62011KA2026PTC214753 · 73, KST Town, Valagerehalli, Kengeri, Bangalore South, Bengaluru – 560060, Karnataka, India