Security at GRX10

Security your legal team can sign off on.

Customer conversations, call recordings and CRM records flow through GRX10 products every day. This page says exactly how that data is encrypted, who can touch it, how long we keep it, and what happens if something goes wrong.

AES-256Encryption at rest
TLS 1.3Encryption in transit
72hBreach notification
How we protect your data

Six commitments, in plain language.

We build each of these controls into the platform itself.

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit. Encryption keys are separated per tenant, and personally identifiable information is tokenised before it reaches application logs.

Data handling & retention

Call recordings are kept 90 days by default, configurable down to a 7-day minimum. Transcripts are retained 2 years, billing records 7 years as statute requires, and account data for the life of the account plus one year. A right-to-erasure workflow covers the rest.

Recordings & consent

Calls are recorded with consent, and a transcript-only retention option exists for customers who never want audio stored. No tenant can access another tenant's audio, ever.

Access control

Least-privilege access with MFA inside GRX10. OAuth 2.0 with API key rotation for integrations, signed webhook payloads, and isolated per-tenant compute so workloads never share a boundary.

Audit trail

Every platform action is logged, with 7-year forensic retention and SIEM-ready export. When auditors ask who did what and when, you can export the answer.

Responsible AI

Our voice agents identify themselves as AI when asked, escalate to a human when a caller is distressed, and run behind prompt-injection filters. We do not clone voices, and agent behaviour is red-team reviewed.

Hosting: primary region in Mumbai with a secondary region in India. Annual penetration testing on the platform. Uptime SLA of 99.9% is available on eligible plans.

If something goes wrong

You hear it from us. Within 72 hours.

If a breach affects your data, we notify you within 72 hours of confirming it. That is the same window our Data Processing Addendum commits to, and the window India's DPDP Act regime expects.

The notification tells you what happened, what data was involved, what we have already contained, and what we are doing next, then updates until the incident closes.

Detect & containHour 0
Incident confirmed, affected systems isolated, forensic log capture begins.
Assess scopeHours 0–48
Which tenants, which data types, which time window.
Notify affected customers< 72 hours
Written notice with facts, impact and containment status.
Remediate & reportUntil closed
Root cause, fixes shipped, and a written post-incident report on request.
Compliance, honestly

What we comply with. What is still in progress.

Certifications we hold today, and the audits we have scheduled.

FrameworkStatusNotes
DPDP Act 2023 (India)ReadySigned DPA with every customer · 72-hour breach notification · consent and erasure workflows · grievance channel on record
Telecom rules for AI callingVia licensed partnersVoice traffic terminates through licensed carrier partners; do-not-disturb scrubbing enforced platform-side on India campaigns
ISO 27001In progressCertification underway · target Q4 2026
SOC 2 Type IIPlannedAudit planned for 2027

This table is current as of July 2026. We update it when an audit completes.

Questions? Findings? Tell us.

Responsible disclosure

Report a vulnerability

Found something? Write to us with steps to reproduce. We acknowledge reports and keep you informed through the fix. We do not pursue good-faith researchers.

admin@grx10.com
Procurement & legal

Security review for your team

Need our DPA, retention schedule or answers to a security questionnaire? Send it over. We respond within a working day. Phone: +91 95025 73308.

Request the paperwork