You Own Your Data &
Compliance.
Your data lives in your own private, walled-off section of Google Cloud that no other company shares. We manage the security around it, but you hold the only keys that unlock it — not even Infinary can open your data without you. This page covers how we keep it safe, our remote lock-and-wipe, and what we promise if something ever goes wrong.
Compliance Roadmap
Certifications & Frameworks
SOC 2 Type II
SOC 2 Type II is an independent audit that proves a company actually follows strong security practices. Ours is underway. Until it's signed off we won't claim to have passed it — but we'll walk you through exactly how we handle security, uptime, and your data, and you can judge for yourself.
HIPAA-Ready
HIPAA is the U.S. law that protects patient health information. Our setup is built to meet its requirements: your data is encrypted whether it's stored or moving, every access is logged, and only the right people get in. We sign the formal HIPAA agreement (a BAA) with each healthcare client.
ISO 27001
ISO 27001 is a globally recognized standard for managing information security. We follow its practices — regular risk reviews, keeping track of every asset, and always improving — so you can trust our security holds up to international scrutiny.
Life Sciences & Regulated Industries
Continuous Audit
Readiness.
For medical device makers and biopharma companies, secure software alone isn't enough — regulators want proof the whole setup is sound and documented. Because each client gets their own private, walled-off section of Google Cloud, your system can grow as you do without ever breaking the quality rules you're held to. So audits become routine, not a fire drill.
FDA 21 CFR Part 11
This FDA rule governs electronic records and signatures. We use tamper-proof digital signatures and locked logs that can't be altered to record every single change to your records — so you have a complete, trustworthy trail for any auditor.
ISO 13485 Validation
ISO 13485 is the quality standard for medical device makers. Every change we ship is checked and documented automatically, with the formal validation paperwork generated as we go — so the proof regulators ask for is already done, not a last-minute scramble.
[2026-04-12 14:02:11 UTC] VERIFYING CLOUD ARMOR RULES...
[2026-04-12 14:02:12 UTC] E-SIGNATURE PAYLOAD RECEIVED: UID_9A2F
[AUDIT_LOG_WRITE] HASH: 0x8a92fda1... COMMITTED TO COLD STORAGE.
Awaiting next lifecycle event...
Data Residency
Your Data.
Your Region.
You choose which part of the world your data sits in when we set you up. Your databases, backups, and everything else stay in that region — and nothing leaves your own space unless you specifically set it up to. So you always know exactly where your information lives.
Full GCP region catalog available on request
Supply Chain Transparency
Subprocessor Registry
A subprocessor is any outside company we rely on to deliver our service. We keep that list short and open. Here's each one, what it does, and what data — if any — it can see.
| Subprocessor | Function | Data Accessed | Location |
|---|---|---|---|
| Google Cloud Platform | Hosts the servers, storage, and AI that run your system | All your business data, kept inside your own private space | Client-selected region |
| Frappe Technologies | Makes the open-source business software (ERPNext) itself | None — the software runs on your own servers; nothing is sent to Frappe | N/A (Self-hosted) |
| Cloudflare | Keeps our public website fast and shields it from attacks | Basic visit info for our marketing site only — never your business data | Global edge |
| Google Workspace | Our own team's email and project coordination | Only our internal messages — never your live business data | US |
Last updated: April 2026 · Changes notified to active clients within 30 days
How We Encrypt Your Data
Encryption Architecture
Encryption Only You Can Unlock
All your stored data is scrambled with encryption keys that you alone control (CMEK). You hold the only keys that unlock it — so not even Infinary can open your data without you.
TLS 1.3
Any data moving across the network is encrypted with TLS 1.3 — the same modern protection your bank uses — so it can't be read in transit. Inside Google Cloud, the parts of your system talk to each other over Google's own encrypted channels too.
Automated Rotation
Your encryption keys are automatically refreshed every 90 days — like regularly changing the locks — which keeps them strong over time. You can set your own schedule or refresh them yourself whenever you want.
Encrypted Snapshots
Your backups are scrambled with the same keys-you-control encryption as the originals, so a copy is never less safe than the real thing. You decide how long backups are kept.
Around-the-Clock Defense
AI Security &
Remote Lock-and-Wipe.
As more of your work is handled by AI assistants that act on their own, your defenses have to move just as fast. We run AI security guards that watch your system around the clock, plus remote lock-and-wipe — so you can remotely lock or wipe a lost or stolen device before anyone can get in.
Always-On AI Guard
An AI guard that catches suspicious or malformed requests before they ever reach your database. It learns what bad behavior looks like and blocks attackers on its own — without slowing down the real, legitimate traffic one bit.
AI-to-AI Gateway
When your suppliers' AI assistants talk to yours, every conversation passes through a guarded gateway. It checks who they really are and caps how much they can ask for — so even a hacked partner's AI can't overload or abuse your system.
Signed AI Actions
Every action an AI takes in your system is stamped with a tamper-proof signature, so there's always a clear, provable record of who did what. That gives regulated industries like medical devices the airtight audit trail that rules such as FDA 21 CFR Part 11 and SOC 2 require.
Response Protocol
Incident Response
If something goes wrong, we follow a clear playbook based on the U.S. government's standard for handling security incidents. Every event is ranked by how serious it is, with set steps to fix it and clear deadlines for telling you — so you're never left in the dark.
Critical / Data Breach
Client notification within 24 hours. Immediate containment. Post-incident report within 72 hours.
High / Service Disruption
Client notification within 48 hours. Root cause analysis within 5 business days.
Informational
Included in next scheduled security report. No immediate client action required.
Disclosure
Vulnerability
Reporting.
Found a security flaw in anything we run or our public website? Please tell us. We welcome the heads-up, and we will never take legal action against researchers acting in good faith.
Questions About
Our Security Posture?
We're glad to walk you through exactly how we keep your data safe. Ask for our complete security questionnaire, or set up a call with the engineers who build it.
Contact Engineering