# Examiverse — Standard Security Questionnaire (pre-filled)

**Examiverse Technologies Private Limited** · CIN U62011KA2026PTC214753  
*Version 1.0 — 29 August 2026* · Contact: admin@examiverse.com

> **How to use this.** When a prospect sends their own questionnaire, the answers are
> almost always already here — find the matching row, paste the answer, do not
> improvise. If a question is not covered, do not invent an answer: write "will
> confirm" and come back to it. One wrong answer discovered in diligence costs more
> than one slow answer given honestly.
>
> **The rule that overrides everything below: never claim a certification we do not
> hold.** See section 7.

---

## 1. Company & contact

| # | Question | Answer |
|---|---|---|
| 1.1 | Legal entity name | Examiverse Technologies Private Limited |
| 1.2 | Registration number | CIN U62011KA2026PTC214753, incorporated under the Companies Act, 2013 |
| 1.3 | Registered address | 73, KST Town, Valagerehalli, Kengeri, Bangalore South, Bengaluru – 560060, Karnataka, India |
| 1.4 | Year founded | 2026 |
| 1.5 | Security contact | admin@examiverse.com |
| 1.6 | Data protection / Grievance Officer | Darshan A C, Grievance Officer & Co-founder, admin@examiverse.com |
| 1.7 | Do you have a dedicated security team? | No. We are an early-stage company; security is owned directly by the technical founder. We state this rather than imply a function we do not staff. |

## 2. Data handling

| # | Question | Answer |
|---|---|---|
| 2.1 | What customer data do you process? | Source documents uploaded for video generation; account profile data (name, email); optional voice recordings and facial reference images for custom voice/avatar; usage telemetry. For enterprise hosting: learner email addresses supplied by the customer. |
| 2.2 | Do you process special-category / sensitive data? | Voice and facial reference data are processed only on explicit opt-in during the avatar/voice creation flow, and only to render output for that account. We do not require or request health, financial or government-ID data. |
| 2.3 | Is customer data used to train AI models? | No. We do not use customer documents, voice recordings or facial data to train, fine-tune or improve any model. Custom voice and avatar models are partitioned per account and never applied to another customer's output. |
| 2.4 | Is customer data sent to third-party AI providers? | **Yes, for one stage, and we state it explicitly.** Source text is sent to Google Cloud Vertex AI for the production-planning stage. This is governed by Google Cloud enterprise terms under which customer data is not used to train Google's foundation models. All other generation — narration, imagery, motion, presenter — runs on models we host on compute we control and is not sent externally. |
| 2.5 | Do you sell or share data with third parties? | No. We never sell personal data and never share it with advertisers or data brokers. |
| 2.6 | Data ownership | The customer retains all rights in their uploaded content and in the generated output. |

## 3. Data residency

| # | Question | Answer |
|---|---|---|
| 3.1 | Where is data stored at rest? | Asia-Pacific (APAC) region — all databases and object storage. |
| 3.2 | Where is data processed? | Multi-region and transient: United States, India (Mumbai), Singapore, and for certain speech synthesis Western Europe and Sweden. Content is held only for the job duration and written back to APAC storage. |
| 3.3 | Can you guarantee single-region processing? | Not on self-serve plans. Region-pinned processing can be scoped under an enterprise agreement — raise it before onboarding. |
| 3.4 | Restricted-territory transfers | We do not transfer personal data to any territory restricted by the Government of India under Section 16 of the DPDP Act, 2023. |

## 4. Access control & authentication

| # | Question | Answer |
|---|---|---|
| 4.1 | How do users authenticate? | Via a managed identity provider, including federated SSO. We never receive or store passwords. |
| 4.2 | Session management | Short-lived, cryptographically signed JWTs in API headers, re-verified server-side on every request touching user content. |
| 4.3 | Is customer data isolated between tenants? | Yes. Every object is written under a path keyed to the authenticated account identifier, and storage rules restrict authorisation to that path. Authorisation is evaluated per request. |
| 4.4 | Administrative access controls | Administrative surfaces that grant access or move money are gated by a server-side super-admin allowlist that **fails closed** — unset or unreadable means denied, not permitted. |
| 4.5 | Is MFA available? | Available through the federated identity provider where the customer's own identity provider enforces it. |
| 4.6 | SSO / SAML support | Federated SSO is supported. Custom SAML integration is scoped per enterprise agreement. |

## 5. Encryption & infrastructure

| # | Question | Answer |
|---|---|---|
| 5.1 | Encryption in transit | TLS 1.3 enforced on all endpoints. HTTP is redirected, not served. |
| 5.2 | Encryption at rest | AES-256 server-side encryption on all object storage. |
| 5.3 | Key management | Managed by the underlying cloud providers' key management services. |
| 5.4 | Secrets handling | Held in platform secret stores and container environment variables; never present in client-side code. |
| 5.5 | Content delivery security | HLS with HMAC-signed, short-expiry playback authorisations verified per request. A leaked URL does not become a permanent public link. |
| 5.6 | DDoS / WAF | Global CDN with DDoS mitigation and WAF in front of every public endpoint. |
| 5.7 | Hosting providers | Cloudflare, Amazon Web Services, Microsoft Azure, Google Cloud. |

## 6. Retention & deletion

| # | Question | Answer |
|---|---|---|
| 6.1 | How long is customer content retained? | Generated videos: 100 most recent per account, maximum 180 days. Voice models: max 20, deleted 90 days after last use. Intermediate render artefacts: 72 hours. Job logs: 6 hours. |
| 6.2 | Enterprise hosting retention | Hosted content and learner rosters permanently deleted 45 days after subscription expiry, or earlier on verified owner request. |
| 6.3 | Is retention enforced automatically? | Yes — on scheduled timers that run **independently of user activity**. Retention driven by owner activity would retain nothing for inactive accounts, which is the data that most needs to age out. |
| 6.4 | Deletion on request | Self-service account deletion. Immediate deactivation, 30-day restorable grace period, then permanent purge of profile records, credentials, uploaded materials, voice models and generated videos. |
| 6.5 | What cannot be deleted? | Invoices and financial records, retained as required by the Companies Act 2013 and Indian tax law (up to 8 years). |
| 6.6 | Data export / portability | Generated output is downloadable at any time. A personal data summary is available on request. |

## 7. Certifications & compliance

| # | Question | Answer |
|---|---|---|
| 7.1 | ISO/IEC 27001 certified? | **No.** We do not hold this certification and do not claim it. On our roadmap. |
| 7.2 | SOC 2 Type I or II? | **No.** We do not hold an attestation and do not claim one. On our roadmap. |
| 7.3 | Are you PCI-DSS compliant? | We are out of scope. Card payments are handled entirely by a PCI-DSS compliant processor; we do not receive, transmit or store cardholder data. |
| 7.4 | GDPR / CCPA | Our practices are aligned to both, including access, correction, erasure and portability rights. |
| 7.5 | DPDP Act 2023 (India) | Aligned. Data Fiduciary for our own account holders; Data Processor for personal data an organisation enters about its employees and learners. Grievance Officer published. |
| 7.6 | Is your infrastructure certified? | Yes — Cloudflare, AWS, Azure and Google Cloud are ISO/IEC 27001 certified and SOC 2 audited. **This covers the layers beneath our application and is not a certification of Examiverse.** We will not present it as one. |
| 7.7 | Penetration testing | No independent third-party penetration test has been commissioned to date. This is on our roadmap and can be prioritised where a contract depends on it. |
| 7.8 | Cyber liability insurance | Not currently held. |

## 8. Incident response & continuity

| # | Question | Answer |
|---|---|---|
| 8.1 | Breach notification timeline | Enterprise customers notified without undue delay and in any event within 72 hours of our becoming aware. Regulatory notification to the Data Protection Board of India as required by the DPDP Act 2023. |
| 8.2 | Vulnerability disclosure | admin@examiverse.com with "Security" in the subject. Good-faith researchers who allow reasonable remediation time and do not access or destroy other users' data will not face legal action. |
| 8.3 | Redundancy | Render workers containerised across two cloud providers with cross-cloud failover. Long renders checkpoint per scene and resume rather than restart. |
| 8.4 | Model provider dependency | The blueprint stage runs against a primary provider with a self-hosted fallback, so no single vendor outage or rate limit halts generation. |
| 8.5 | Backups | Managed backup and point-in-time recovery on databases; redundant object storage. |
| 8.6 | Documented RTO / RPO | Not formally defined at this stage. We will not quote a number we have not tested. |

## 9. Sub-processors

| Sub-processor | Purpose |
|---|---|
| Cloudflare | Edge delivery, object storage, serverless databases, DDoS protection |
| Amazon Web Services | GPU compute instances we operate and control |
| Microsoft Azure | Containerised render workers; speech synthesis |
| Google Cloud (Vertex AI) | Production-planning stage; certain image generation |
| Google Firebase | Authentication and identity |
| Razorpay | Payment processing (India) |
| Upstash | Job queueing and ephemeral cache |

We update this list before adding any new sub-processor that processes customer
content.

---

## Answering questions not covered here

Three rules, in order of importance:

1. **Never claim a certification, audit, test or insurance policy we do not hold.** If
   the honest answer is no, the answer is no. Section 7 is written to be read out
   loud without amendment.
2. **Never state a number we have not measured** — uptime percentages, RTO/RPO,
   headcount, test coverage. "Not formally defined at this stage" is a complete and
   respectable answer.
3. **Escalate rather than guess.** Anything touching architecture, encryption or model
   processing goes to the technical founder before it is sent.
