Security your legal team can sign off on.
Customer conversations, call recordings and CRM records flow through GRX10 products every day. This page says exactly how that data is encrypted, who can touch it, how long we keep it, and what happens if something goes wrong.
Six commitments, in plain language.
We build each of these controls into the platform itself.
Encryption everywhere
AES-256 at rest, TLS 1.3 in transit. Encryption keys are separated per tenant, and personally identifiable information is tokenised before it reaches application logs.
Data handling & retention
Call recordings are kept 90 days by default, configurable down to a 7-day minimum. Transcripts are retained 2 years, billing records 7 years as statute requires, and account data for the life of the account plus one year. A right-to-erasure workflow covers the rest.
Recordings & consent
Calls are recorded with consent, and a transcript-only retention option exists for customers who never want audio stored. No tenant can access another tenant's audio, ever.
Access control
Least-privilege access with MFA inside GRX10. OAuth 2.0 with API key rotation for integrations, signed webhook payloads, and isolated per-tenant compute so workloads never share a boundary.
Audit trail
Every platform action is logged, with 7-year forensic retention and SIEM-ready export. When auditors ask who did what and when, you can export the answer.
Responsible AI
Our voice agents identify themselves as AI when asked, escalate to a human when a caller is distressed, and run behind prompt-injection filters. We do not clone voices, and agent behaviour is red-team reviewed.
Hosting: primary region in Mumbai with a secondary region in India. Annual penetration testing on the platform. Uptime SLA of 99.9% is available on eligible plans.
You hear it from us. Within 72 hours.
If a breach affects your data, we notify you within 72 hours of confirming it. That is the same window our Data Processing Addendum commits to, and the window India's DPDP Act regime expects.
The notification tells you what happened, what data was involved, what we have already contained, and what we are doing next, then updates until the incident closes.
What we comply with. What is still in progress.
Certifications we hold today, and the audits we have scheduled.
| Framework | Status | Notes |
|---|---|---|
| DPDP Act 2023 (India) | Ready | Signed DPA with every customer · 72-hour breach notification · consent and erasure workflows · grievance channel on record |
| Telecom rules for AI calling | Via licensed partners | Voice traffic terminates through licensed carrier partners; do-not-disturb scrubbing enforced platform-side on India campaigns |
| ISO 27001 | In progress | Certification underway · target Q4 2026 |
| SOC 2 Type II | Planned | Audit planned for 2027 |
This table is current as of July 2026. We update it when an audit completes.
Questions? Findings? Tell us.
Report a vulnerability
Found something? Write to us with steps to reproduce. We acknowledge reports and keep you informed through the fix. We do not pursue good-faith researchers.
admin@grx10.comSecurity review for your team
Need our DPA, retention schedule or answers to a security questionnaire? Send it over. We respond within a working day. Phone: +91 95025 73308.
Request the paperwork