Skip to main content

SECURITY & GOVERNANCE

India Sovereign Data

Security built on architectural clarity, not vague badges.

Enterprise buyers care about specifics: where data lives, how permissions isolate external users, and whether AI agents can leak confidential records across departments. Here is exactly what is true today, and what is currently in audit.

100%

India Data Residency

AWS Mumbai & Hyderabad regions

100%

Customer Data Ownership

Export in open formats anytime

0

Cross-Tenant Leakage

Strict workspace boundary isolation

Oct 2026

SOC 2 Type II Target

Audit currently underway

LIVE COMMITMENTS

What is True in Production Today

Six verifiable architectural facts backing every Methodical deployment.

01 · DATA RESIDENCY

Sovereign Indian Cloud

Multi-region, multi-AZ active deployment across AWS Mumbai (ap-south-1) and AWS Hyderabad (ap-south-2). Customer data, voice notes, and vectors never leave Indian borders.

02 · DATA OWNERSHIP

100% Customer Ownership

You own your data completely. Full open-format export (Postgres schema dumps, JSON, CSV, raw audio WAVs) available at any time with zero exit penalties.

03 · PERMISSION INHERITANCE

ACL-Aware Retrieval

AI agents inherit the requesting user's exact permissions. An agent will never query, summarize, or surface records the asking user cannot open directly.

04 · ENCRYPTION

Rest & Transit Encryption

TLS 1.3 in transit with strict HSTS, and AES-256 encryption at rest across all Postgres databases, vector stores, and object buckets.

05 · DPDP COMPLIANCE

DPDP Act 2023 Aligned

Designed from day one for Indian personal data protection standards. Dedicated Data Protection Officer (DPO) and structured rights fulfillment channels.

06 · SUB-PROCESSORS

Published Sub-Processors

Published sub-processor registry with audited DPAs. No unvetted third-party tracking or session recording tools on customer data surfaces.

ARCHITECTURAL DIFFERENTIATOR (§5.4.1)

Set up in minutes. Detailed enough to survive an audit.

Enterprise access control usually fails in one of two directions: too simple to govern a real organization, or so complex that configuring it requires consulting. Methodical is deliberately both.

LAYER 01 · PLATFORM RBAC

Teams & Base Roles

Team Admin and Team Member roles governing Boards, Switchboard, Smart Tables, and Drive folders. Shared Drive folders add simple Editor and Viewer permissions. An ops lead gets started without meeting a permissions matrix.

LAYER 02 · APP RBAC

Enterprise App Roles

Arbitrarily rich roles scoped inside each Enterprise App (e.g. SalesNet Area Manager vs. Field Rep vs. Finance Lead). Granular field-level and action-level controls satisfy compliance officers.

LAYER 03 · WORKSPACES

Isolation Boundaries

Group Boards, Smart Tables, Switchboard, and People into a Workspace isolated from everything else. The answer to "can we let our external distributor or contractor in without them seeing anything else?"

CRITICAL AI SAFETY COMMITMENTAudit Verified

Agents inherit the requesting user's exact permissions.

The single biggest enterprise objection to agentic AI is data leakage across departments. In Methodical, our retrieval layer is ACL-aware rather than merely embedding-similar. An agent answering a field rep's prompt queries only what that specific rep is entitled to see across team memberships, app roles, and workspace boundaries.

MODEL PORTABILITY & DATA RESIDENCY POLICY (§6.0.1)Zero Vendor Lock-In

The AI model is a policy setting, not an architectural decision.

Choose the model per agent. Swap it without rebuilding anything. If an enterprise policy mandates: "Our sensitive financial data cannot leave for a US provider," that agent runs on a local, private, or sovereign model. It is a configuration toggle, not a code rewrite.

Supported Foundation Models:Google, OpenAI, and Anthropic enterprise endpoints.
Sovereign & Open Models:Open-weight models via OpenRouter, including self-hostable options.

Zero model obsolescence in practice: foundation model migrations execute seamlessly in the background with zero customer downtime or retraining required.

AUDIT & CERTIFICATION

Honest Certification Roadmap

We state certification timelines openly rather than claiming unearned compliance badges.

SOC 2 Type II Audit

Audit Underway · Certification Targeted October 2026

IN PROGRESS

We are currently in the formal observation and audit period for our SOC 2 Type II attestation report with an accredited independent CPA firm. We will publish the final attestation report directly on this page upon completion in October 2026.

• Scope: Security, Availability, and Confidentiality Trust Services Criteria

• Infrastructure Scope: AWS Mumbai & Hyderabad sovereign cloud clusters

• NDA-backed interim security pack available for enterprise procurement teams.

DPDP ACT 2023 REDRESSAL

Data Principal Rights & Grievance Mechanism

Under the Digital Personal Data Protection Act 2023, data principals have the right to access, correct, and request erasure of their personal records.

Data Privacy & Compliance

Designation: Privacy & Compliance Lead

Legal Entity: RedBlackTree Technologies Pvt. Ltd.

Email: privacy@methodical.ai

Address: Chennai, India

Response timeline: Acknowledged within 24 hours, resolved within 72 hours.

Grievance Redressal Mechanism

Grievance Lead: Grievance Redressal Officer

Desk Email: grievance@methodical.ai

Rights Scope: Access, Correction, Erasure, Consent Withdrawal

Requests are processed in accordance with the provisions of DPDP Act 2023.