Skip to content
UVAMAI
Enterprise Assurance

Security is the architecture, not an add-on.

Least-privilege access, end-to-end encryption and continuous vulnerability assessment are embedded in every component we build and manage — because retrofitting them is what fails audits.

Encryption
AES-256 at rest · TLS 1.3 in transit
Isolation
Per-tenant, enforced in schema
Audit
Append-only, exportable
Model training
Never on customer data
The controls

Every claim on this page, with the mechanism behind it.

Open any control to see what it means in practice — the architecture, not the assurance language.

Control families
  1. 01Data Privacy & Sovereignty
  2. 02Audit Telemetry & Compliance
  3. 03Regulatory & Certification
  4. 04Proactive Threat Defence

Reviewing us for a procurement? The same detail is in the whitepaper below, and dpo@uvam.ai answers questionnaires directly.

Data Privacy & Sovereignty

Logical, database-level, and cryptographic segregation of all customer workloads across MIRAI CRM, MEIVERSE, and custom enterprise builds.

  • AES-256 encryption for all static volumes and database backups
  • TLS 1.3 mandated for all ingress/egress transit calls
  • Per-tenant KMS encryption key rotation available on request
  • Zero cross-tenant data bleed, enforced by PostgreSQL row-level security

Audit telemetry

An answer to “who changed that, and when?”

Every administrative action, identity transition and API call is signed and written once. Nothing in the trail can be edited afterwards — including by us — and you can stream or export the whole of it.

  • Write-once-read-many storage, retained up to seven years
  • Real-time SIEM streaming over syslog or webhook
  • Anomaly alerting on unusual access patterns
meiverse.uvam.ai / audit
Append-only · WORM storageSigned
Time (UTC)ActorActionScopeSignature
14:02:11Zk.menon@uvam.airole.grant · db.readtenant/dxb-049f2c1ab7
13:57:48Zsvc/mei-forgekey.rotate · kmstenant/che-114e80d3c9
13:41:02Zs.iyer@uvam.aiexport.requesttenant/syd-02b71a55e0
13:20:37Zapi/ingressauth.denied · mfatenant/dxb-040c93f412
12:58:19Zr.prasad@uvam.aipolicy.update · rlsestate/globald5e6a284
Retained up to 7 years · exportable · streamed to your SIEM
fig. 01A representative trail. No customer log is published here.
Security resources

The whole architecture, in one document.

Our security and compliance whitepaper — architecture overview, the SOC 2 controls summary, and the disaster recovery procedure.

What is in it
  • Estate and platform architecture, drawn
  • The SOC 2 controls matrix we align to, control by control
  • Disaster recovery procedure, with RPO and RTO stated
  • Sub-processor list and data residency by region
Standards we work to
SOC 2 Type II controls alignmentISO/IEC 27001:2022 frameworkGDPR & Australian Privacy Act (APP)UAE PDPL ready

Stated as alignment, not as certification. Where we hold a certificate we will name the auditor and the report date — ask, and we will send it.

Get the whitepaper

Sent to your work address within a minute.

We send the document to this address and nothing else.

No sales sequence attached.

Have a security questionnaire?

Talk directly to the team that owns this architecture.

Not a sales engineer reading from a control matrix — the people who wrote it and are on call for it.

Contact us