Security and compliance

Security is not a feature. It's the foundation every enterprise conversation runs on.

Rubic operates inside banking, financial services and enterprise environments, which means the security review comes before the sales conversation. Everything on this page is answerable on day one, in writing, and evidenced on request.

Certifications and standards

Certified, and verifiable.

Across the platform and the AI layer, Rubic operates to internationally recognised information security and privacy standards. Certificates and reports are available under NDA.

ISO

27001:2022

ISO 27001:2022

Information security management

ISO

9001:2015

ISO 9001:2015

Quality management systems

AICPA

SOC2

Type II

SOC 2 Type II

AICPA service organisation controls

TRAI

TRAI and DLT

Registered telemarketer, header and template compliant

INDIA
DATA

India data residency

Data stored and processed within India

Where your data lives

In India. Processed for your purposes, and nothing else.

01

Data residency

All data — call records, recordings, transcripts, documents and workflow state — is stored and processed within India. Nothing leaves the country, including for AI inference. Rubic uses Voxket models for the AI layer, running on India-hosted infrastructure.

02

Processing scope

Sensitive customer data is processed only for the operational purposes agreed in your contract. No secondary use. No analytics for our own purposes. No training of models on your data, at any layer of the stack.

03

Ownership

You retain ownership and control of your data throughout. PII is stored only with your explicit permission, and returned or deleted on request within a defined period.

04

Sub-processors

Every party in the chain is disclosed before contract and named in the DPA. If we add one, you're notified in advance with a right to object.

Retention and automatic purge

Data we don't need is data we don't keep.

Retention is a contract term, not a default. You set the window; the system enforces it without anyone having to remember.

Data typeRetention
Call recordingsTo your contracted schedule, then purged automatically
Transcripts and call metadataA window you define — commonly 7 to 30 days for retries and quality review.
Documents and mediaWritten to your storage where you prefer; otherwise held to your schedule and purged on expiry
Workflow stateAccount reference, status, attempt count and next action — retained while the workflow is active, purged on closure
Quality scores and QA evidenceTo your contracted schedule, with the underlying audio purged on the same clock
Controls

How the data is protected while we hold it.

01

Access

Role-based access control on the principle of least privilege

  • Segregated configuration and data per client
  • Full audit trail of call logs, export and configuration change
02

Protection

Encryption in transit and at rest

  • Network segmentation between environments
  • Regular vulnerability assessment and penetration testing
  • Secure development practices, with review before release
03

Continuity

Documented business continuity and disaster recovery plans

  • Defined recovery point and recovery time objectives
  • Backup and restore tested on a schedule
On every call

The regulatory obligations sit on the calling layer — and we run it.

01

Control 01

Calling windows enforced at the dialer, configured to your policy

02

Control 02

Registered telemarketer status, with DLT header and template registration maintained

03

Control 03

Preference and do-not-disturb scrubbing against the list you provide

04

Control 04

Per-account attempt trail, complete including unanswered attempts, exportable on demand

Consent and accountability

Consent for the contacts on a list remains yours as the data fiduciary. We execute against the list you provide and warrant our handling of it.

Contracting and accountability

One agreement. One accountable party.

You contract with Voixa Pvt Ltd, operating as Rubic Solution — one master services agreement, one data processing addendum, one invoice, one support line, one set of service levels. Where a component of the stack is operated by a partner, that partner is named as a sub-processor in the DPA and the delivery obligation still sits with us.

One accountable party

Your role

Data fiduciary — you own the data, the customer relationship and the consent

Our role

Data processor — we act on your documented instructions and nothing else

Breach notification

Within the window set in your DPA, with a documented incident response and escalation path

Audit

Annual audit right on 30 days' notice, or acceptance of our current assurance reports in lieu. Immediate audit right following a material incident.

Liability

Capped by contract, with a separate provision for data incidents. Cyber liability insurance in place and evidenced on request.

Start the security review in the first conversation

Data residency, retention, sub-processors, controls and contracting are documented on request.