Security, Architecture & Cloud Compliance
Entity: Socio Engineer Pvt. Ltd.
Platform: Vistaar360 Manufacturing Cloud
1. Security Architecture Overview
The Vistaar360 multi-tenant manufacturing cloud is engineered to meet the rigorous data security requirements of automotive Tier-1 suppliers, aerospace precision manufacturers, and export-oriented industrial plants.
2. Infrastructure Security
- Hosting Environment: Hosted on Tier-3/Tier-4 cloud infrastructure located in Mumbai and Hyderabad, India. Data centers maintain physical access biometrics, 24/7 armed security, redundant power feeds, and advanced fire suppression systems.
- Certifications: Underlying infrastructure holds active certifications for ISO/IEC 27001:2013, ISO 27017, ISO 27018, and SOC 1 / SOC 2 Type II.
- Network Perimeter: Web Application Firewalls (WAF), distributed denial-of-service (DDoS) mitigation by Cloudflare, and automated anomaly detection on all incoming API requests.
3. Cryptographic Controls
- Data in Flight: TLS 1.3 enforced across all public endpoints with HSTS (HTTP Strict Transport Security) enabled. Legacy protocols (SSLv3, TLS 1.0, TLS 1.1) are permanently disabled.
- Data at Rest: All relational databases, blob object storage (drawings, PDFs, invoices), and automated daily backups are encrypted using AES-256 with cloud-managed hardware security module (HSM) keys.
4. Tenant Logical Isolation
Vistaar360 implements strict multi-tenancy controls:
- Partitioned Schema & Identity: Every API request is authenticated via signed JWT tokens cryptographically linked to a verified
tenant_id. - Database Row-Level Security (RLS): PostgreSQL query engines enforce tenant boundary isolation at the database layer, ensuring no cross-query execution across distinct manufacturing companies.
5. Security Incident Management
In compliance with CERT-In directives:
- 24/7 automated log telemetry monitoring unauthorized access attempts.
- Incident response team tasked with containment, remediation, and statutory notification within mandated timeframes in the unlikely event of a verified breach.
For vulnerability disclosure or security reports, please contact: security@vistaar360.com.
