Security & Compliance

Enterprise Security & Indian Compliance by Design

Data is encrypted on your own machine before it moves, backups can be locked so nothing can delete them inside the period you set, and every action is written to a trail you can hand to a reviewer.

Secured by Serverstock|Satkosh Cloud Backup Console
Monitoring
Tamper-evident activity logs and real-time operational status
SA
Serverstock AdminSERVERSTOCK TENANT
👁 Overview⚡ Operations🔔 Alerts🛡 Audit Logs
All actions ▾
User email or target id...
dd-mm-yyyy 📅
dd-mm-yyyy 📅
Apply
WHENACTIONUSERTENANTSUMMARY
2m agoRESTOREServerstockStatus: SUCCESS · Hostname: WIN-SRV-DC01 · Target Path: D:\...
2m agoCREATE_RESTOREServerstockTarget Path: D:\ · Cross Device: no · Restore Onto: WIN-SRV-DC01...
18m agoCREATE_POLICYServerstockPolicy: Linux Infrastructure Policy · Daily 01:00 AM · S3 Mumbai
2h agoLOGINServerstockEmail: admin@serverstock.co · Method: Microsoft 365 SSO
6h agoDEVICE_ENROLLServerstockHostname: WIN-SRV-DC01 · Platform: Windows Server 2022
Architecture & Controls

Security and compliance built into every layer

Included across every protected machine without premium tier upgrades.

Client-Side AES-256 Encryption

Data is encrypted directly on your machine before moving and stays encrypted in transit and at rest. You choose who holds the encryption password: we can manage it for you, or in zero-knowledge mode you hold it alone and we cannot read your backups.

Locked Backups Nobody Can Delete

Lock backup copies for a retention period you define. During that period, backups cannot be modified, overwritten or deleted by ransomware, by someone holding stolen credentials, or by us. That we cannot delete it either is what makes this a control rather than a promise.

Indian Data Sovereignty

You decide where data physically resides: your own local disk, or your own cloud bucket with any S3-compatible provider, in India or anywhere else you choose. We do not move it elsewhere.

DPDP Act (2023) Aligned

Built to fulfill statutory personal data protection obligations with tenant isolation, documented retention schedules, and exportable audit evidence.

MFA & Granular Access Controls

Authenticator app MFA with emergency recovery codes, brute-force rate limiting, and instant session termination on password resets.

Verifiable Audit Trail

Detailed machine-by-machine logging of all backup jobs, restores, logins, and credential modifications, exportable for compliance reviews and security questionnaires.

DPDP Framework

Clear data roles and processing governance

India's Digital Personal Data Protection framework distinguishes between fiduciary control and processing execution.

You

Data Fiduciary

You decide what data is collected, define backup schedules, set retention policies, and choose where your storage repository resides.

Serverstock

Data Processor

We process backup instructions on your behalf. When you bring your own storage bucket or local drive, file contents never pass through or rest on our servers.

Role-Based Access Control (RBAC) & Team Governance

SSO & MFA Enforced
Secured by Serverstock|Satkosh Cloud Backup Console
User Management
Manage access, role designations, and SSO authentication for your organization
SA
Serverstock AdminSERVERSTOCK TENANT
Organization Members & Roles
+ Add User
NAMEEMAILDESIGNATIONROLEMFAACTIONS
Serverstock AdminDirector● TENANT ADMIN● ENABLED
Edit
IT Operations LeadInfrastructure Lead● OPERATOR● ENABLED
EditDelete
Compliance AuditorCompliance Officer● VIEWER● ENABLED
EditDelete
Disaster Recovery EngineerDR Specialist● OPERATOR● ENABLED
EditDelete

Our standard Data Processing Agreement (DPA) defines complete contractual terms. We can review custom enterprise procurement requirements during onboarding.

Security & Vendor Due Diligence

Frequently asked technical questions

Direct, plain-language answers for your infosec and compliance reviewers.

Can Satkosh / Serverstock staff view or decrypt our files?

No. Everything is encrypted on the machine before it moves. When using zero-knowledge encryption, you hold the key alone, and our systems have no mechanism to decrypt your content.

How does Satkosh help against ransomware?

We do not scan for it or block it on your machines. That is antivirus, a different product, and we will not pretend otherwise. What we do is make sure ransomware cannot destroy the copy you recover from. Once a backup is locked, no user, compromised credential or system process can delete or overwrite it until the retention window expires, and you restore from the last clean copy.

Where does our backup data physically reside?

Wherever you configure it. You can write directly to local on-premise storage, your own Indian cloud bucket (AWS S3, Azure Blob, Wasabi), or storage purchased from Satkosh hosted in India.

Do you provide a signed Data Processing Agreement (DPA)?

Yes. We offer a standard Data Processing Agreement aligned with the Digital Personal Data Protection (DPDP) Act to support your vendor compliance requirements.

How are agent updates managed and verified?

Updates are cryptographically signed and install only when an administrator triggers them from the console. Endpoints verify the digital signature before applying any update.

Do you hold SOC 2 or ISO 27001 certifications?

We are in our pilot stage and operate under strict documented security controls and DPDP-aligned technical standards. We provide complete architectural transparency and technical questionnaire responses for procurement reviews.

Book a demo

Need security documentation for procurement?

We can walk your IT and compliance team through our technical architecture, provide questionnaire responses, and conduct a live restore verification.

No spam, just a reply from our team. Managed backup by Serverstock. Made in India.