Skip to content

Trust & Compliance

Your customers trust you with their identity. You can trust us with it.

Identity and KYC data is some of the most sensitive data a business holds. Attestr is independently certified for information security and quality management, and built around India's Digital Personal Data Protection Act.

ISO/IEC 27001:2022ISO 9001:2015VAPT TestedDPDPA CompliantRead our policies

Certifications & testing

Independently audited and tested

Information Security Management

ISO/IEC 27001:2022

SP Certification Ltd. (UK) logo

Certifies Attestr's information security management system (ISMS) covering the digital onboarding, eKYC automation and integration platform.

Certifying body
SP Certification Ltd. (UK)
Accreditation
Accredited by AFIST
Certificate no.
SPC22I7264/S1
Valid until
8 September 2027

Quality Management System

ISO 9001:2015

QFS Management Systems LLP logo

Certifies the quality management system covering Attestr's software solutions for onboarding, eKYC automation and integration services.

Certifying body
QFS Management Systems LLP
Accreditation
Accredited by Standards Council of Canada
Certificate no.
SCC/2509PQ/2943
Valid until
11 September 2028

Independent Penetration Testing

VAPT — Remediation Verified

Our production platform is independently tested for vulnerabilities by Bachao.AI (Dhisattva AI Pvt Ltd), using black-box and authenticated grey-box testing, followed by remediation re-tests.

All Critical, High, Medium and Low findings closed — fixed and re-verified, or formally risk-accepted. Two informational observations remain, neither with a data- or system-impact path.

0

Open critical

0

Open high

0

Open medium

0

Open low

Assessor
Bachao.AI (Dhisattva AI Pvt Ltd)
Scope
attestr.com production — 3 hosts, 2,860 checks
Tested · re-tested
15 August 2026 · 1, 4 and 8 September 2026
Certificate no. · issued
BVPT-ATT-2026-0908 · 8 September 2026

Certificates are held by Pegadroid IQ Solutions Private Limited, the company that operates Attestr. Copies of the ISO certificates and the VAPT certificate are available to customers and prospects on request.

DPDPA

Designed around India's Digital Personal Data Protection Act, 2023

Attestr's data handling practices align with India's Digital Personal Data Protection Act, 2023 — consent-first processing, purpose limitation, data minimisation and data principal rights.

Consent first

Personal data is processed only against a clear, specific consent — and Attestr's Consent Data Processor lets you capture and prove that consent for your own users too.

Purpose limitation

Data collected for a verification is used for that verification — never sold, and never repurposed for marketing.

Data minimisation

Each check collects and returns only what that verification needs — not a full profile of the person behind it.

Data principal rights

Requests to access, correct or erase personal data, and grievances, have a named route to a team equipped to handle them.

Need to prove consent for your own users? Attestr's Consent Data Processor gives you hosted consent pages, a consent audit trail and webhooks.

DPDPA Consent Data Processor

Policies & documentation

Everything in writing

Our commitments on data protection, storage and security are published in full — the same commitments we make in our client agreements.

For developers and compliance teams

How our DPDPA controls work at the API level — consent registration, lifecycle, revocation and audit trails.

FAQ

Security & privacy questions

Who holds Attestr's ISO certifications?

Pegadroid IQ Solutions Private Limited, the registered company that operates Attestr. The certificates cover the digital onboarding, eKYC automation and integration platform.

Is Attestr's platform penetration tested?

Yes. Bachao.AI (Dhisattva AI Pvt Ltd) performed a vulnerability assessment and penetration test of our production platform (attestr.com production — 3 hosts, 2,860 checks), first on 15 August 2026 with re-tests on 1, 4 and 8 September 2026. All critical, high, medium and low findings were closed, and certificate BVPT-ATT-2026-0908 was issued on 8 September 2026. The certificate is available on request.

Is there such a thing as a DPDPA certificate?

No. India's Digital Personal Data Protection Act, 2023 has no accredited certification scheme, so any "DPDPA certified" claim should be treated with caution. Attestr states DPDPA compliance as a self-declared commitment, backed by its consent-first practices and its ISO 27001-certified security programme.

Does Attestr sell personal data?

No. Personal information is used to provide the verification services requested and is not sold or rented to anyone.

Where is my data stored, and for how long?

All verification data is stored in India, in the AWS Mumbai region, encrypted with AES-256-GCM. Single-use verifications are not retained in identifiable form; reusable consents are stored only if the client enables it — 7 working days by default, never beyond the consent's validity. Full details are in our Data Storage Policy.

Is Attestr a Data Fiduciary or a Data Processor?

For the people our clients verify, the client is the Data Fiduciary and Attestr is its Data Processor — and, where the client opts in, a Consent Collection Facilitator through hosted consent pages. For our own customers' account and billing data, Attestr is the Data Fiduciary.

How do I raise a privacy request or grievance?

Email our Grievance Officer at harika.pogaku@attestr.com with the subject "Data Protection Request". If a business verified you using Attestr, that business is your Data Fiduciary — contact it first; we will help route your request.

Can't find what you need? See all our policies or email harika.pogaku@attestr.com.

Need our security documentation?

Talk to us for certificate copies, a security questionnaire, or a walkthrough of how Attestr handles identity data.