Regulatory Compliance

Built for Indian Compliance

Grovia Vault is designed from the ground up to meet the regulatory requirements facing Indian enterprises — from the DPDP Act 2023 to RBI's IT Framework, SEBI's cybersecurity guidelines, and mandatory data residency.

🏛️

DPDP Act 2023

Digital Personal Data Protection Act, 2023

Compliant

The Digital Personal Data Protection Act 2023 is India's primary data protection legislation. It establishes rights for Data Principals (individuals) and obligations for Data Fiduciaries (organisations that process personal data). Grovia Vault is built to help your organisation meet these obligations when using us as a backup and data processor.

Lawful Purpose & Consent

Grovia Vault processes only data you explicitly back up under your configured policy. No data is collected beyond what is necessary for the backup service.

✓ By Design

Data Minimisation

Agent telemetry is metadata only — file names, sizes, and timestamps. File contents are never transmitted in plain text and never inspected by Grovia Vault.

✓ By Design

Purpose Limitation

Backup data is used exclusively to fulfil restore requests initiated by your account. It is never used for analytics, advertising, or third-party sharing.

✓ By Design

Storage Limitation

Backup data is retained for exactly the retention window you configure. Automatic deletion runs on schedule. Account closure triggers deletion within 30 days.

✓ Configurable

Data Principal Rights

Access, correction, and erasure requests are fulfilled within 30 days. A grievance redressal process is available via info@groviavault.com.

✓ Supported

Security Safeguards

AES-256-GCM client-side encryption, TLS 1.3 in transit, MFA, JWT auth, and PostgreSQL RLS isolation exceed DPDP's reasonable security safeguards standard.

✓ Exceeds Standard

As a Data Processor under DPDP, Grovia Vault processes personal data on your instructions. We provide a Data Processing Agreement (DPA) on request for Business and Enterprise customers — email info@groviavault.com with subject "DPA Request".

🏦

RBI Guidelines

RBI IT Framework for Banks & NBFC Cybersecurity Guidelines

Aligned

The Reserve Bank of India's IT Framework for Banks (2016) and Master Direction on Information Technology Governance, Risk, Controls & Assurance Practices (2023) require regulated entities to maintain comprehensive backup and recovery capabilities. Grovia Vault addresses these requirements directly.

Backup & Recovery Policy

Policy-driven backup schedules with configurable frequency, retention windows, and file path inclusion/exclusion rules meet RBI's documented BCP/DR requirements.

✓ Supported

Offsite & Segregated Storage

Air-gapped multi-cloud storage (Wasabi + Backblaze B2) provides the geographic and network segregation required by RBI's backup location guidelines.

✓ Built-in

Encryption of Stored Data

AES-256-GCM encryption applied before data leaves your premises. RBI requires encryption of sensitive data both in transit and at rest — we exceed both mandates.

✓ Exceeds Standard

Ransomware & Malware Defence

5-layer ransomware detection (Shannon entropy, magic byte, extension analysis, ransom note detection, change velocity) provides the active threat defence RBI frameworks now require.

✓ 5-Layer Detection

Audit Trail & Logging

Every backup job, restore event, and threat alert is logged with timestamps, agent ID, and IP address — supporting RBI's audit and forensic investigation requirements.

✓ Supported

RTO / RPO Capability

Incremental backups with configurable schedules (as frequent as hourly) allow organisations to define and meet their Recovery Time and Recovery Point Objectives.

✓ Configurable

For BFSI customers requiring a formal compliance mapping document, contact info@groviavault.com.

📊

SEBI Compliance

SEBI Cybersecurity & Cyber Resilience Framework (CSCRF)

Aligned

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), updated in 2024, requires Regulated Entities (REs) including brokers, exchanges, depositories, and AMCs to implement robust data backup, incident response, and cyber resilience capabilities. Grovia Vault maps directly to these requirements.

Cyber Resilience Posture

CSCRF requires REs to maintain a cyber resilience posture across Identify, Protect, Detect, Respond, and Recover. Grovia Vault addresses the Protect, Detect, and Recover pillars directly.

✓ 3 of 5 Pillars

Data Backup & Restoration

CSCRF mandates tested backup and restoration procedures. Grovia Vault's point-in-time restore with audit-logged verification events supports regular restore testing requirements.

✓ Supported

Immutable Backup Copies

Air-gapped copies on Backblaze B2 are write-once after archival. Network-isolated from primary infrastructure — meeting CSCRF's immutability guidance for critical data.

✓ Air-Gapped

Incident Detection & Response

Real-time ransomware detection with threat alerts and acknowledgement workflow supports CSCRF's incident detection and initial response requirements.

✓ Real-Time Alerts

Third-Party Risk Management

Grovia Vault's sub-processor list, DPA, and security posture documentation support REs' third-party risk assessments required under CSCRF.

✓ Documentation Available

Data Localisation

Primary backup storage in AWS Mumbai (ap-south-1) satisfies SEBI's data localisation requirements for critical data of Indian REs.

✓ India Primary

SEBI REs requiring a CSCRF compliance mapping for vendor assessments should contact info@groviavault.com.

🇮🇳

Data Residency

India-first storage architecture

India Primary

Data residency is a hard requirement for many Indian enterprises — particularly in BFSI, healthcare, and government. Grovia Vault's storage architecture is designed with India-first residency as the default, not an optional add-on.

Primary Storage — India

All backup data, account records, and telemetry are stored on AWS Mumbai (ap-south-1) by default. No data is written to servers outside India without explicit configuration.

✓ Default

Hot Tier — Wasabi India

Wasabi's India region (Mumbai) is used for the hot backup tier — fast retrieval for recent restore operations. All data is encrypted before leaving your network.

✓ India

Air-Gap Tier — Encrypted Offshore

The air-gap copy is stored on Backblaze B2 (EU) for maximum geographic isolation against regional disasters. Only AES-256-GCM ciphertext is written — the EU provider holds no plaintext or keys.

✓ Encrypted Only

Key Residency

Encryption keys are derived from your passphrase using SHA-256 and never leave your devices. No encryption keys are stored on any server — India or otherwise.

✓ Zero-Knowledge

India-Only Option

Enterprise customers who cannot store any data outside India can configure a India-only storage policy (Wasabi + AWS Mumbai, no offshore air-gap). Contact us to configure.

✓ On Request

Transfer Documentation

For any cross-border data transfer, we provide documentation of the transfer mechanism (encryption + DPDP Act Section 16 compliance) on request for regulatory audits.

✓ Available

Storage Architecture Summary

🟢
Hot Tier
Wasabi Mumbai
India ✓
🔵
Warm Tier
AWS ap-south-1
India ✓
🟡
Air-Gap
Backblaze B2 EU
Encrypted Only
Compliance ready

Need a compliance document for your audit?

We provide Data Processing Agreements, security questionnaire responses, and compliance mapping documents for BFSI, healthcare, and government customers.