You Own Your Data &
Compliance.
Your data lives in your own private, walled-off section of Google Cloud that no other company shares. We manage the security around it, but you hold the only keys to it — not even Infinary can open your data without you. This page covers how we keep it safe, our remote lock-and-wipe, and what we promise if something ever goes wrong.
How to Check Us Out
Judge the Setup,
Not a Badge.
We don't hold up certification logos as a substitute for showing you the work. What we will do is open up the actual deployment — how your data is encrypted, who can reach it, what gets logged, and how quickly things get patched — and let your own security people form a view.
A Walkthrough With Your Team
Bring your IT lead, your security consultant, or whoever reviews vendors for you. We'll go through the architecture, answer questions directly, and hand over documentation of how the controls on this page are configured for your deployment.
Agreements in Writing
Where your business needs specific commitments in the contract — a Business Associate Agreement for handling patient information, a data processing agreement, defined breach notification timelines — we sign them per engagement rather than pointing you at a generic policy page.
Nothing Shared With Anyone
Your system runs in your own Google Cloud account, in a private section no other company touches, with encryption keys only you hold. You can verify that yourself from inside your own console — you don't have to take our word for any of it.
Life Sciences & Regulated Industries
Continuous Audit
Readiness.
For medical device makers and biopharma companies, secure software alone isn't enough — regulators want proof the whole setup is sound and documented. Because each client gets their own private, walled-off section of Google Cloud, your system can grow as you do without ever breaking the quality rules you're held to. So audits become routine, not a fire drill.
Electronic Records & Signatures
If you are held to the FDA rule on electronic records and signatures (21 CFR Part 11), the evidence burden falls on your records. We use tamper-proof digital signatures and locked logs that can't be altered to capture every change — so the trail an auditor asks for already exists. Whether your overall process satisfies the rule is a judgement for you and your quality team, not something software decides.
Validation Paperwork, Generated as We Go
Medical device makers running a quality system to ISO 13485 have to show their software was validated. Every change we ship is checked and documented automatically, with that paperwork produced as we go — so the proof is ready when your auditor asks, instead of being reconstructed under pressure.
[2026-04-12 14:02:11 UTC] VERIFYING CLOUD ARMOR RULES...
[2026-04-12 14:02:12 UTC] E-SIGNATURE PAYLOAD RECEIVED: UID_9A2F
[AUDIT_LOG_WRITE] HASH: 0x8a92fda1... COMMITTED TO COLD STORAGE.
Awaiting next lifecycle event...
Data Residency
Your Data.
Your Region.
You choose which part of the world your data sits in when we set you up. Your databases, backups, and everything else stay in that region — and nothing leaves your own space unless you specifically set it up to. So you always know exactly where your information lives.
Full GCP region catalog available on request
Supply Chain Transparency
Subprocessor Registry
A subprocessor is any outside company we rely on to deliver our service. We keep that list short and open. Here's each one, what it does, and what data — if any — it can see.
| Subprocessor | Function | Data Accessed | Location |
|---|---|---|---|
| Google Cloud Platform | Hosts the servers, storage, and AI that run your system | All your business data, kept inside your own private space | Client-selected region |
| Frappe Technologies | Makes the open-source business software (ERPNext) itself | None — the software runs on your own servers; nothing is sent to Frappe | N/A (Self-hosted) |
| Cloudflare | Keeps our public website fast and shields it from attacks | Basic visit info for our marketing site only — never your business data | Global edge |
| Google Workspace | Our own team's email and project coordination | Only our internal messages — never your live business data | US |
Last updated: April 2026 · Changes notified to active clients within 30 days
How We Encrypt Your Data
Encryption Architecture
Encryption Keys Only You Hold
All your stored data is scrambled with encryption keys that you alone control (CMEK). You hold the only keys to it — so not even Infinary can open your data without you.
TLS 1.3
Any data moving across the network is encrypted with TLS 1.3 — the same modern protection your bank uses — so it can't be read in transit. Inside Google Cloud, the parts of your system talk to each other over Google's own encrypted channels too.
Automated Rotation
Your encryption keys are automatically refreshed every 90 days — like regularly changing the locks — which keeps them strong over time. You can set your own schedule or refresh them yourself whenever you want.
Encrypted Snapshots
Your backups are scrambled with the same keys-you-control encryption as the originals, so a copy is never less safe than the real thing. You decide how long backups are kept.
Around-the-Clock Defense
AI Security &
Remote Lock-and-Wipe.
As AI agents draft more of your daily work, your defenses have to move just as fast. We run AI security guards that watch your system around the clock, plus remote lock-and-wipe — so you can remotely lock or wipe a lost or stolen device before anyone can get in.
Always-On AI Guard
An AI guard that catches suspicious or malformed requests before they ever reach your database. It learns what bad behavior looks like and blocks attackers on its own — without slowing down the real, legitimate traffic one bit.
AI-to-AI Gateway
A guarded gateway designed for the day your suppliers' AI assistants talk to yours — it would check who they really are and cap what they can ask for. AI-to-AI deals are on hold while open contract-law questions get settled, so this is not part of the product today.
Signed AI Actions
Every action an AI takes in your system is stamped with a tamper-proof signature, so there's always a clear, provable record of who did what. That gives regulated industries like medical devices the airtight audit trail that rules such as FDA 21 CFR Part 11 demand of your records.
Response Protocol
Incident Response
If something goes wrong, we follow a clear playbook based on the U.S. government's standard for handling security incidents. Every event is ranked by how serious it is, with set steps to fix it and clear deadlines for telling you — so you're never left in the dark.
Critical / Data Breach
Client notification within 24 hours. Immediate containment. Post-incident report within 72 hours.
High / Service Disruption
Client notification within 48 hours. Root cause analysis within 5 business days.
Informational
Included in next scheduled security report. No immediate client action required.
Disclosure
Vulnerability
Reporting.
Found a security flaw in anything we run or our public website? Please tell us. We welcome the heads-up, and we will never take legal action against researchers acting in good faith.
Questions About
Our Security Posture?
We're glad to walk you through exactly how we keep your data safe. Ask for our complete security questionnaire, or set up a call with the engineers who build it.
Contact Engineering