+0.00m / ZONE TS-01
Trust & security
Enterprise buyers stall without this page, so here it is — including the parts still marked TBD. We would rather show you an honest work-in-progress than a wall of badges we have not earned yet.
| Area | Status | Detail |
|---|---|---|
| Operating entity | TechUltra Solutions Pvt. Ltd. | Mapnyx is a product of TechUltra Solutions Pvt. Ltd., which is the contracting party, the data controller for this website and the processor for venue data. Registered address and company number: TBD. |
| SOC 2 | TBD | Certification status will be stated here exactly — Type I / Type II, report date, and how to request the report under NDA. |
| GDPR | TBD | Data processing terms, lawful bases and DPA availability. The controller is an Indian entity, so the transfer mechanism for EU customers (SCCs) and the hosting region will be stated here explicitly rather than assumed. |
| India DPDP Act | TBD | The operating entity is Indian, so the Digital Personal Data Protection Act applies alongside GDPR for EU customers. Notice, consent and grievance-officer details: TBD. |
| Data residency | TBD | Hosting regions and residency options per plan. Enterprise deployments can pin region. |
| WCAG | 2.2 AA target | This site and product surfaces target WCAG 2.2 AA. Independent audit status: TBD. We sell accessible wayfinding; our own conformance is part of the product. |
| Positioning privacy | Policy | Asset tracking is the default; any people-location feature is opt-in, aggregated where possible, and governed by the venue's workplace policy. We do not sell location data. |
| Subprocessors | TBD | The full subprocessor list (hosting, video streaming, email) publishes here with change notifications. |
| Vulnerability reporting | Open | security@ address and disclosure policy: TBD. Reports are answered by an engineer, not a form. |
PRACTICES
- Encryption in transit (TLS 1.2+) and at rest for all venue and sync data.
- Scoped API keys per venue and environment; viewer tokens carry no write access.
- Data connections use the source system's own auth (OAuth/API keys) with least-privilege scopes; credentials are stored encrypted and never logged.
- Every published map change and sync rule change is audit-logged: who, what, when.
+0.00m / EXIT
Need the security questionnaire answered?
Send yours over — a real answer beats a badge wall.