Trust & security
What is true today, and what is not yet.
A list of facts you can test, and a plain list of what we have not done.
True today
- Hosted in India
- Strong sign-in
- Single sign-on on open standards
- Provisioning that follows HR
- Step-up for sensitive actions
- Roles and sessions
- Audit and monitoring
- Privacy workflows
- Documented API and SDKs
Not yet, or not offered
- Independent penetration test
- SOC 2 report
- ISO/IEC 27001 certificate
- SMS provider integration (planned)
- Government empanelment
- On-premises deployment
- Aadhaar-based verification
- Contractual uptime commitment
No badge, no certificate
Until an audit report exists, nothing here is a certification. We will update this page when something changes, and not before.
How each one works
Open any line for the detail.
Hosted in India
Data is hosted in the Google Cloud Mumbai region (asia-south1), with customer-managed encryption keys, a private database and a web application firewall.
Strong sign-in
Passkeys (WebAuthn) including Face ID, Touch ID, Windows Hello, security keys and phones, plus authenticator-app (TOTP) codes. SMS codes are available; the SMS provider integration is still planned.
Single sign-on on open standards
SAML 2.0 and OpenID Connect using the authorization code flow with PKCE, with pre-built connectors for common SaaS apps.
Provisioning that follows HR
A SCIM 2.0 server that accepts changes from HR systems, and outbound SCIM provisioning to applications, so leavers lose access promptly.
Step-up for sensitive actions
Administrators are asked to re-authenticate before sensitive admin actions, even if their session is already open.
Roles and sessions
Role-based admin (admin, IT admin, auditor, member). You can see active sessions and revoke them. Password reset is by email.
Audit and monitoring
An audit log with export, a live audit feed, and streaming to your SIEM through a signed webhook or Splunk HTTP Event Collector.
Privacy workflows
DPDP-oriented features: a grievance workflow, data export, consent records and India data residency.
Documented API and SDKs
An API with a documented OpenAPI description, SDKs for JavaScript, Python and Android, and an iOS app.
Ask us for evidence
Send your questionnaire to info@authmantra.com. To report a vulnerability, see our security note.
Have a security questionnaire?
Send it over. We would rather answer ten hard questions honestly than ten easy ones with a badge.