# Examiverse AI Studio — Security & Data Protection Whitepaper

**Examiverse Technologies Private Limited**  
CIN: U62011KA2026PTC214753  
73, KST Town, Valagerehalli, Kengeri, Bangalore South, Bengaluru – 560060, Karnataka, India

*Version 1.0 — 29 August 2026*  
*Current version: https://studio-static.examiverse.com/security/security-whitepaper.md*

---

## 1. Purpose of this document

This is the document to send to a security reviewer, an IT team, or a procurement
function that has asked "is this safe to put our training content into?"

It is written to be checkable. Every claim here is either something a reviewer can
verify externally, or something we will demonstrate on a call. Where we do **not**
hold something — a certification, an attestation — we say so in plain terms rather
than gesturing at our infrastructure providers' credentials and hoping the
distinction is not noticed. Section 8 is that list.

---

## 2. What the platform does with your data

You supply a source document — a policy, an SOP, an onboarding guide, a compliance
update, a syllabus. The platform returns a finished training video: narration
synchronised to on-screen visuals, animated diagrams, an optional presenter, and an
auto-marked knowledge assessment generated from the same source.

Three properties of that pipeline matter for security review:

**Output is grounded in your document.** The system is built as a deterministic
orchestration backend that triggers models on-spec, rather than a wrapper that hands
your document to one generative model and hopes. Content in the finished video comes
from your source material.

**Your content is not training data.** We do not use your uploaded documents, voice
recordings or facial data to train, fine-tune or improve any model. Custom voice and
avatar models are partitioned to your account and are never applied to another
customer's output. See section 5 for the precise position on third-party models,
including the one place your text does leave our infrastructure.

**Processing is transient.** Source material is held for the duration of the render
and then subject to the retention bounds in section 6. Intermediate artefacts are
purged within 72 hours.

---

## 3. Architecture and access control

**Identity.** Authentication is delegated to a managed identity provider. We never
receive or store passwords. Sessions use short-lived, cryptographically signed JWTs
passed in API headers; every request that touches user content re-verifies the token
server-side.

**Storage isolation.** Every object is written under a path keyed to the
authenticated account identifier, and storage rules restrict read and write
authorisation to that path. A user cannot enumerate or reach another user's objects,
because authorisation is evaluated per request rather than assumed from the client.

**Administrative access.** Administrative surfaces that can grant access or move
money are gated by a server-side super-admin allowlist that **fails closed** — if the
allowlist is unset or unreadable, access is denied rather than granted. UI-level
gating exists as a courtesy and is never the security boundary.

**Payment data.** Card details are entered directly with a PCI-DSS compliant payment
processor and never traverse or rest on our systems. We hold a payment reference and
an invoice record; we do not hold card numbers.

**Content delivery.** Video is delivered over HLS with short-lived signed URLs. Every
stream request is individually verified — a URL that leaks does not become a
permanent public link.

---

## 4. Encryption and network security

| Layer | Control |
|---|---|
| In transit | TLS 1.3 enforced on all endpoints; HTTP is redirected, not served |
| At rest | AES-256 server-side encryption on all object storage |
| Edge | Global CDN with DDoS mitigation and WAF in front of every public endpoint |
| Secrets | Held in platform secret stores and container environment, never in client code |
| Streaming | HMAC-signed, short-expiry playback authorisations, verified per request |

---

## 5. Sub-processors and AI model providers

We engage the following sub-processors. This list is complete as of the version date,
and we update it before adding any new sub-processor that touches customer content.

| Sub-processor | Purpose |
|---|---|
| Cloudflare | Edge delivery, object storage, serverless databases, DDoS protection |
| Amazon Web Services | GPU compute instances that we operate and control |
| Microsoft Azure | Containerised render workers; speech synthesis |
| Google Cloud (Vertex AI) | Production-planning stage; certain image generation |
| Google Firebase | Account authentication and identity |
| Razorpay | Payment processing (India) |
| Upstash | Job queueing and ephemeral cache |

### The AI model question, answered precisely

This is the question enterprise reviewers ask most, and the one most vendors answer
imprecisely. Our position, in three parts:

**Narration, imagery, motion and presenter generation run on models we host on
compute we control.** That content is not sent to any external model provider. This
is unusual — most tools in this category are assembling calls to third-party
generation APIs — and it is the single strongest data-protection property we have.

**The production-planning stage is the exception, and we state it rather than bury
it.** Your source text is sent to Google Cloud Vertex AI to produce the lesson
blueprint. This is a processing relationship governed by Google Cloud's enterprise
terms, under which customer data submitted to Vertex AI is not used to train Google's
foundation models. Your text is processed and returned; it does not become training
data for anyone.

**We do not sell personal data,** and we do not share it with advertisers or data
brokers.

If your policy prohibits any third-party model processing whatsoever, tell us during
evaluation. That constraint is addressable under an enterprise agreement; it is not
available on self-serve plans.

---

## 6. Data residency and retention

### Residency

We separate where data is **stored** from where it is briefly **processed**, because
those are different answers and merging them would misrepresent our position.

- **At rest — Asia-Pacific (APAC).** All databases and object storage: user profiles,
  generated videos, uploaded source documents, voice models, invoices, analytics.
- **In processing — multi-region, transient.** Rendering and inference run in the
  United States, India (Mumbai), Singapore, and for certain speech synthesis Western
  Europe and Sweden. Content is held only for the duration of the job and written
  back to APAC storage.
- We do not transfer personal data to any territory restricted by the Government of
  India under Section 16 of the DPDP Act, 2023.
- **Region-pinned processing can be arranged for enterprise agreements.** If you have
  a hard residency requirement, raise it before onboarding rather than after.

### Retention

Every store has an enforced upper bound applied **on a timer that runs independently
of user activity**. This is a deliberate design decision worth stating: retention that
only triggers when the account owner returns retains nothing for inactive
accounts — which is precisely the data that should age out.

| Data | Bound |
|---|---|
| Generated videos and lesson history | 100 most recent per account, max 180 days |
| Custom voice models and source recordings | Max 20 per account, deleted 90 days after last use |
| Brand logos and avatar images | Max 20 each (count-capped: deliberately created reusable assets) |
| Intermediate render artefacts, checkpoints | 72 hours; purged immediately on delivery |
| Temporary render workspaces | 24 hours |
| Job logs | 6 hours |
| Enterprise hosting content and learner rosters | Deleted 45 days after subscription expiry |
| Account deletion | 30-day restorable grace period, then permanent purge |
| Invoices and financial records | Retained as required by the Companies Act 2013 and Indian tax law (up to 8 years) — these cannot be deleted on request |

---

## 7. Privacy rights and governance

**Role.** Examiverse acts as a **Data Fiduciary** under the DPDP Act, 2023 for its own
account holders, and as a **Data Processor** for personal data an organisation uploads
or enters about its employees and learners.

**Rights.** Data Principals may access a summary of their personal data and the
sub-processors it has been shared with; correct, complete, update or erase it;
withdraw consent at any time; nominate someone to exercise these rights on their
behalf; and have a grievance heard.

**Consent is purpose-specific.** Accepting our terms in order to use the service is
not treated as consent to receive marketing, and declining marketing does not affect
platform access or account credits.

**Frameworks.** Our practices are aligned to the DPDP Act 2023 (India), the GDPR and
the CCPA. Access, portability and erasure are implemented as product features, not as
manual exception handling: account deletion is self-service, and generated output is
downloadable at any time.

**Grievance Officer**  
Darshan A C — Grievance Officer & Co-founder  
admin@examiverse.com  
73, KST Town, Valagerehalli, Kengeri, Bangalore South, Bengaluru – 560060, Karnataka, India

Grievances are acknowledged within 24 hours and resolved within 30 days. Unsatisfied
complainants may escalate to the Data Protection Board of India.

---

## 8. Certifications — what we hold, and what we do not

We would rather lose a deal on this section than win one and fail diligence later.

**We do not currently hold ISO/IEC 27001 certification. We do not currently hold a
SOC 2 attestation.** We do not claim either. Any document representing otherwise is
not ours, and we would like to know about it.

What is true:

- Our platform runs on infrastructure operated by **Cloudflare, Amazon Web Services,
  Microsoft Azure and Google Cloud**, all of which are ISO/IEC 27001 certified and
  SOC 2 audited. That covers the physical, network and hypervisor layers beneath our
  application. It is not a certification of Examiverse, and we will not present it as
  one.
- Card payments are handled entirely by a **PCI-DSS compliant** processor. We do not
  receive, transmit or store cardholder data.
- We align to the **DPDP Act 2023, GDPR and CCPA** as described above.

Formal certification is on our roadmap and will be pursued as our enterprise customer
base requires it. If certification is a hard gate for your organisation, tell us — it
is a scheduling question, and knowing that a real contract depends on it changes when
we start.

---

## 9. Incident response

We maintain a documented process covering detection, containment, assessment,
notification and post-incident review.

- **Regulatory notification.** In the event of a personal data breach we notify the
  Data Protection Board of India and affected Data Principals without undue delay, as
  required by the DPDP Act 2023.
- **Customer notification.** Enterprise customers are notified without undue delay and
  in any event **within 72 hours** of our becoming aware of a breach affecting their
  data, with the detail needed to meet their own obligations.
- **Vulnerability disclosure.** Email **admin@examiverse.com** with "Security" in the
  subject. We do not pursue legal action against researchers who report in good
  faith, allow reasonable time to remediate, and do not access or destroy other users'
  data.

---

## 10. Business continuity

- Render workers are containerised and run **across two cloud providers with
  cross-cloud failover**, so a single provider's regional outage does not stop
  production.
- Long renders **checkpoint per scene**, so an evicted job resumes rather than
  restarting.
- The blueprint stage runs against a primary model provider with a **self-hosted
  fallback**, so no single vendor's rate limit or outage halts generation.
- Storage is on a provider with built-in redundancy; databases have managed backup and
  point-in-time recovery.

---

## 11. Requesting more

Available on request to **admin@examiverse.com**:

- Completed security questionnaire (pre-filled, standard format)
- Data Processing Agreement (DPA) for signature
- Sub-processor list with change notification
- Architecture walkthrough call with the technical founder
- Region-pinned processing scoping, for enterprise agreements

---

*Examiverse Technologies Private Limited · CIN U62011KA2026PTC214753 · admin@examiverse.com*
