Where is CORAA hosted?+
Microsoft Azure, South India region only. No mirroring or replication outside India. This applies to production data, backups, and disaster-recovery infrastructure.
Is CORAA DPDPA 2023 compliant?+
Yes. CORAA processes data as a Data Processor on behalf of the customer (Data Fiduciary in DPDPA terminology). We comply with processor obligations under Section 8 of the Act — purpose limitation, security safeguards, breach notification, and data principal rights pass-through.
Does CORAA use customer data to train AI models?+
No. Customer ledgers, vouchers, working papers, classifications and findings are not used to train foundation models. This commitment is contractual and is enforceable via the Master Subscription Agreement.
What certifications does CORAA hold?+
ISO/IEC 27001:2022 (Information Security Management System) and SOC 2 Type II (Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality). Reports available under NDA.
Can I request a SOC 2 report?+
Yes. SOC 2 Type II reports are available to active customers and qualified prospects under NDA. Contact security@coraa.ai.
How does CORAA handle data residency for foreign-owned Indian subsidiaries?+
Data of the Indian subsidiary remains in India regardless of parent ownership. If the foreign parent requires data access from outside India (e.g., for group-audit purposes), data is provided in standardised export formats — but the source-of-truth remains India-hosted.
What happens to my data if I cancel my subscription?+
On cancellation, you can export all your data (ledgers, working papers, reports) in standard formats (CSV, Word, PDF). After a 30-day grace period, all production data and backups are deleted unless retention is required for legal compliance (e.g., active litigation hold).
Does CORAA notify customers of security incidents?+
Yes. For S0/S1 incidents involving customer data, we notify within 1 hour of confirmation. All security incidents are documented in a public quarterly transparency report. We have not had a customer-data breach to date.
Is CORAA penetration tested?+
Yes. Annual penetration test by an independent CERT-In empanelled security firm. Results are reviewed by leadership and remediations tracked to completion. Summary available to customers under NDA.