Security and Trust
Batoi combines Platform controls, DevSecOps, the Guard capability, governance practices, and current trust documentation to protect data, support accountable operations, and strengthen assurance across Platform, Flex, consulting engagements, Academy programs, and partner delivery.
At a glance
Describes Batoi security practices, assurance boundaries, certifications, examinations, reporting, and trust information.
- Security practices span delivery pipelines, Platform controls, privacy governance, incident response, and assurance evidence.
- Certifications and examinations do not automatically apply to every affiliate, product, deployment, or customer environment.
- Eligible customers and partners may request appropriate assurance material through an approved secure channel.
This summary helps you navigate the document. The complete policy text and any controlling agreement remain authoritative.
On this page
Security commitment
Security is embedded into Batoi Platform, delivery pipelines, and operating practices.
DevSecOps framework
Batoi’s DevSecOps framework connects security checks, reviewed controls, workflow-based response, and measurable evidence.
- Layer: Development
- Key Controls and Practices: Code scanning (SAST/DAST), dependency management, and secure repositories.
- Layer: Security Integration
- Key Controls and Practices: Policy-as-code enforcement, identity and access control, and vulnerability remediation.
- Layer: Operations
- Key Controls and Practices: Continuous monitoring, telemetry, audit trails, and automated patching.
- Layer: Compliance Automation
- Key Controls and Practices: Framework mapping to ISO, SOC, NIST, GDPR, and ESG metrics.
- Layer: Incident Management
- Key Controls and Practices: Threat detection, workflow-based response orchestration, and governed incident handling through the Guard capability of Batoi Platform.
Platform delivery uses shared security, governance, identity, and evidence controls, with scope determined by the selected deployment and service arrangement.
Assurance scope and meaning
ISO certifications and the SOC 2 examination are held by Batoi Systems Private Limited within their documented scopes. No certification or examination should be read as covering every affiliate, product, deployment, or customer environment.
| Trust Item | Scope | Description |
|---|---|---|
| ISO 9001:2015 | Certified Quality Management System | Issued by TÜV SÜD South Asia and currently valid through 15 August 2028, subject to surveillance audits and the certificate scope. |
| ISO/IEC 27001:2022 | Certified Information Security Management System | Issued by TÜV SÜD South Asia and currently valid through 15 August 2028, subject to surveillance audits and the certificate scope. |
| SOC 2 Type II | Independent Examination | Covers Security, Availability, Processing Integrity, and Confidentiality from September 1, 2024, through August 31, 2025. This is not a certification; the restricted-use report is shared securely with eligible parties. |
| GDPR | Independent Assessment and Ongoing Privacy Program | An independent assessment was completed in 2025. GDPR is a legal regime, not a certification, and applicability depends on role, processing context, services, location, and contract. |
| HIPAA | Safeguards and Readiness Program | Supported by contractual safeguards, internal assessment, and external readiness work for applicable healthcare services. This is not a certification. |
| DORA & NIST | Digital Operational Resilience and Security Controls | Available as control-mapping and readiness references where relevant; this does not represent certification or a blanket claim of regulatory compliance. |
| AI Governance (OECD, EU AI Act) | Responsible AI Principles | Embedded into Batoi governance, assurance, and consulting frameworks. |
| Trust Item | ISO 9001:2015 |
| Scope | Certified Quality Management System |
| Description | Issued by TÜV SÜD South Asia and currently valid through 15 August 2028, subject to surveillance audits and the certificate scope. |
| Trust Item | ISO/IEC 27001:2022 |
| Scope | Certified Information Security Management System |
| Description | Issued by TÜV SÜD South Asia and currently valid through 15 August 2028, subject to surveillance audits and the certificate scope. |
| Trust Item | SOC 2 Type II |
| Scope | Independent Examination |
| Description | Covers Security, Availability, Processing Integrity, and Confidentiality from September 1, 2024, through August 31, 2025. This is not a certification; the restricted-use report is shared securely with eligible parties. |
| Trust Item | GDPR |
| Scope | Independent Assessment and Ongoing Privacy Program |
| Description | An independent assessment was completed in 2025. GDPR is a legal regime, not a certification, and applicability depends on role, processing context, services, location, and contract. |
| Trust Item | HIPAA |
| Scope | Safeguards and Readiness Program |
| Description | Supported by contractual safeguards, internal assessment, and external readiness work for applicable healthcare services. This is not a certification. |
| Trust Item | DORA & NIST |
| Scope | Digital Operational Resilience and Security Controls |
| Description | Available as control-mapping and readiness references where relevant; this does not represent certification or a blanket claim of regulatory compliance. |
| Trust Item | AI Governance (OECD, EU AI Act) |
| Scope | Responsible AI Principles |
| Description | Embedded into Batoi governance, assurance, and consulting frameworks. |
Continuous Assurance Program
Batoi’s Continuous Assurance Model combines controls, automation, and governance to support security beyond periodic audits:
- Risk Maturity Scoring: Measured through governance and assurance reviews across platform and product environments.
- Automated Evidence Collection: Policy and control evidence gathered through governed workflows and platform controls.
- Audit Trail Visibility: Traceable logs and evidence views for customer, partner, and internal review.
- Partner Review: Screening, KYC, enablement, certification, and continuing review apply according to partner level, domain, activity, risk, and the applicable agreement.
Ongoing reviews and evidence help teams understand control operation between formal audits.
Data Protection and Privacy Governance
Batoi applies comprehensive privacy and data protection practices globally:
- Encryption: In transit and at rest according to the applicable service architecture and documented configuration.
- Access Controls: Identity, role, least-privilege, and additional verification controls according to deployment scope.
- Data Residency: Regional hosting options (India, USA, Canada).
- Third-Party Management: Vendor risk assessments and DPAs in place.
- User Control: Governed request handling for data export, deletion, and privacy actions through customer and support channels.
Security in the Batoi Ecosystem
Batoi extends its governance and compliance model across platform, services, and institutional surfaces:
Batoi Platform
Identity, auditability, DevSecOps, encryption, and tenancy controls according to the applicable service architecture, configuration, deployment, and assurance scope.Consulting
Security advisory and assurance for customers, partners, and regulated delivery environments.Academy
Safe learning environments with privacy-protected labs.Research
Ethical data handling, responsible AI methods, and governance-oriented inquiry.Partner Network
Governed delivery under defined security, quality, and assurance policies.Trust is enforced through ecosystem-wide accountability.
Responsible AI and Ethics
Through Batoi Research, Consulting, and governance controls, we embed responsible AI principles:
Transparent algorithms in analytics.
Fairness validation through structured review and governance workflows.
Auditable workflows for AI-driven decisions.
Green AI initiatives aligning with ESG and SDG goals.
Customer and Partner Assurance
Batoi customers and partners can:
Request security documentation and attestations.
Conduct joint compliance assessments under NDA.
Access relevant audit reports and assurance summaries through secure customer or partner channels.
Transparency builds confidence. Every customer and partner should be able to understand the assurance posture behind the environment they use.