Grovia Vault is designed from the ground up to meet the regulatory requirements facing Indian enterprises — from the DPDP Act 2023 to RBI's IT Framework, SEBI's cybersecurity guidelines, and mandatory data residency.
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act 2023 is India's primary data protection legislation. It establishes rights for Data Principals (individuals) and obligations for Data Fiduciaries (organisations that process personal data). Grovia Vault is built to help your organisation meet these obligations when using us as a backup and data processor.
Grovia Vault processes only data you explicitly back up under your configured policy. No data is collected beyond what is necessary for the backup service.
Agent telemetry is metadata only — file names, sizes, and timestamps. File contents are never transmitted in plain text and never inspected by Grovia Vault.
Backup data is used exclusively to fulfil restore requests initiated by your account. It is never used for analytics, advertising, or third-party sharing.
Backup data is retained for exactly the retention window you configure. Automatic deletion runs on schedule. Account closure triggers deletion within 30 days.
Access, correction, and erasure requests are fulfilled within 30 days. A grievance redressal process is available via info@groviavault.com.
AES-256-GCM client-side encryption, TLS 1.3 in transit, MFA, JWT auth, and PostgreSQL RLS isolation exceed DPDP's reasonable security safeguards standard.
As a Data Processor under DPDP, Grovia Vault processes personal data on your instructions. We provide a Data Processing Agreement (DPA) on request for Business and Enterprise customers — email info@groviavault.com with subject "DPA Request".
RBI IT Framework for Banks & NBFC Cybersecurity Guidelines
The Reserve Bank of India's IT Framework for Banks (2016) and Master Direction on Information Technology Governance, Risk, Controls & Assurance Practices (2023) require regulated entities to maintain comprehensive backup and recovery capabilities. Grovia Vault addresses these requirements directly.
Policy-driven backup schedules with configurable frequency, retention windows, and file path inclusion/exclusion rules meet RBI's documented BCP/DR requirements.
Air-gapped multi-cloud storage (Wasabi + Backblaze B2) provides the geographic and network segregation required by RBI's backup location guidelines.
AES-256-GCM encryption applied before data leaves your premises. RBI requires encryption of sensitive data both in transit and at rest — we exceed both mandates.
5-layer ransomware detection (Shannon entropy, magic byte, extension analysis, ransom note detection, change velocity) provides the active threat defence RBI frameworks now require.
Every backup job, restore event, and threat alert is logged with timestamps, agent ID, and IP address — supporting RBI's audit and forensic investigation requirements.
Incremental backups with configurable schedules (as frequent as hourly) allow organisations to define and meet their Recovery Time and Recovery Point Objectives.
For BFSI customers requiring a formal compliance mapping document, contact info@groviavault.com.
SEBI Cybersecurity & Cyber Resilience Framework (CSCRF)
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), updated in 2024, requires Regulated Entities (REs) including brokers, exchanges, depositories, and AMCs to implement robust data backup, incident response, and cyber resilience capabilities. Grovia Vault maps directly to these requirements.
CSCRF requires REs to maintain a cyber resilience posture across Identify, Protect, Detect, Respond, and Recover. Grovia Vault addresses the Protect, Detect, and Recover pillars directly.
CSCRF mandates tested backup and restoration procedures. Grovia Vault's point-in-time restore with audit-logged verification events supports regular restore testing requirements.
Air-gapped copies on Backblaze B2 are write-once after archival. Network-isolated from primary infrastructure — meeting CSCRF's immutability guidance for critical data.
Real-time ransomware detection with threat alerts and acknowledgement workflow supports CSCRF's incident detection and initial response requirements.
Grovia Vault's sub-processor list, DPA, and security posture documentation support REs' third-party risk assessments required under CSCRF.
Primary backup storage in AWS Mumbai (ap-south-1) satisfies SEBI's data localisation requirements for critical data of Indian REs.
SEBI REs requiring a CSCRF compliance mapping for vendor assessments should contact info@groviavault.com.
India-first storage architecture
Data residency is a hard requirement for many Indian enterprises — particularly in BFSI, healthcare, and government. Grovia Vault's storage architecture is designed with India-first residency as the default, not an optional add-on.
All backup data, account records, and telemetry are stored on AWS Mumbai (ap-south-1) by default. No data is written to servers outside India without explicit configuration.
Wasabi's India region (Mumbai) is used for the hot backup tier — fast retrieval for recent restore operations. All data is encrypted before leaving your network.
The air-gap copy is stored on Backblaze B2 (EU) for maximum geographic isolation against regional disasters. Only AES-256-GCM ciphertext is written — the EU provider holds no plaintext or keys.
Encryption keys are derived from your passphrase using SHA-256 and never leave your devices. No encryption keys are stored on any server — India or otherwise.
Enterprise customers who cannot store any data outside India can configure a India-only storage policy (Wasabi + AWS Mumbai, no offshore air-gap). Contact us to configure.
For any cross-border data transfer, we provide documentation of the transfer mechanism (encryption + DPDP Act Section 16 compliance) on request for regulatory audits.
We provide Data Processing Agreements, security questionnaire responses, and compliance mapping documents for BFSI, healthcare, and government customers.