Enterprise Security You Can
Present to Your Board
Multi-layer security architecture, company-level ISO certifications, and platform-specific India-sovereign hosting options — built for the most sensitive transactions.
Confiex Data Room Private Limited — ISO Certified
These certifications apply to Confiex as a company — our processes, people, and quality management — regardless of which platform you use. They are the foundation under every platform-specific claim below.
ISO 9001:2015
Certifies that Confiex's quality management processes meet international standards — ensuring consistent, reliable service delivery across all data room implementations, customer support operations, and deal management workflows.
ISO 27001:2022
Internationally recognised standard for information security management systems (ISMS). Covers risk assessment, asset management, access control, cryptography, and incident response — audited and certified at the company level.
Additional company credentials: NASSCOM Member · MSME Registered · Startup India (DPIIT Recognised)
DocullyVDR — MEITY-Approved India Sovereign
DocullyVDR holds a deeper, product-level government approval — not just infrastructure empanelment. This is the platform for government, PSU, and regulated-sector deals requiring India data sovereignty.
MEITY-Approved Azure Hosting
Hosted on Microsoft Azure India data centres with MEITY approval. Your data never leaves Indian borders — mandatory for government, PSU, and regulated transactions.
India-Based Backup Data Center
A secondary India-based backup data center at a separate location ensures business continuity and disaster recovery without data leaving the country.
CERT-In-Approved VAPT Audit
DocullyVDR undergoes CERT-In-approved Vulnerability Assessment and Penetration Testing (VAPT) conducted per OWASP standards. This audit is scoped to DocullyVDR only.
eDataRooms & FileLink — MeitY-Empaneled AWS India
These platforms run on AWS India infrastructure that is MeitY CSP-empaneled — a different tier of claim than DocullyVDR's product-level approval above. This is infrastructure empanelment, not a product-level government audit.
MeitY-Empaneled Infrastructure
Runs on AWS infrastructure empaneled by India's Ministry of Electronics and Information Technology (MeitY), built on globally certified data centers (ISO 9001, SOC 1/2/3).
Applies to: eDataRooms and FileLink
DPDP Act Alignment
Hosts data on Indian servers, aligning with the data localization principles of India's Digital Personal Data Protection (DPDP) Act.
Applies to: eDataRooms and FileLink
Important distinction: MeitY infrastructure empanelment (this section) is not the same as DocullyVDR's MEITY-approved product-level Azure hosting with CERT-In VAPT audit (above). If your procurement checklist requires product-level government approval, DocullyVDR is the correct platform. If India-based hosting on MeitY-empaneled infrastructure is sufficient, eDataRooms or FileLink may meet your requirements at a lower cost.
Confiex Data Room — AWS Global, Maximum DRM Control
Confiex Data Room runs on AWS US/global infrastructure — not India-empaneled regions. It offers the strongest DRM controls in our portfolio but does not carry India data residency or DPDP claims.
Post-Download DRM Revocation
Revoke access to already-downloaded files remotely — unique among Indian VDR providers. Once revoked, files become inaccessible even on the recipient's device.
AI-Powered Document Intelligence
AI analyses your entire document set to surface anomalies, inconsistencies, and key findings — accelerating due diligence.
Dynamic Watermarking
Auto-applied watermarks on every view and download embed IP address, timestamp, and user identity.
AWS Global Infrastructure
Multi-region AWS deployment on globally certified infrastructure (ISO 27001, SOC 1/2/3). 99.99% uptime SLA with automated failover.
AES-256 Encryption
AES-256 encryption at rest and TLS 1.3 in transit, in line with ISO 27001 requirements.
Cross-Border Deal Ready
Suitable for international transactions and cross-border deal teams requiring reliable global performance.
When to choose DocullyVDR instead: If your deal requires India-based data residency or DPDP Act alignment, Confiex Data Room is not the right platform. We recommend DocullyVDR for government, PSU, and regulated-sector deals where data must remain within Indian borders.
Technical Security Architecture
Multi-layer defence-in-depth architecture ensures your data is protected at every level — across all four platforms.
Security features are product-specific — Confiex Data Room runs on AWS global infrastructure, DocullyVDR runs on Microsoft Azure India, and eDataRooms & FileLink run on AWS India. Speak to our sales team or email sales@confiexdataroom.com to learn more about the best security configuration for your deal.
Encryption
Access Control
Digital Rights Management
Monitoring & Audit
Infrastructure
Incident Response
Data Hosting & Sovereignty Summary
Choose where your data lives. Each platform has a distinct hosting profile — we match you to the right one for your compliance requirements.
Confiex Data Room
Multi-region AWS deployment for global performance. No India data residency or DPDP claims. Best for cross-border deals requiring maximum DRM control.
DocullyVDR
Full MEITY-approved India-sovereign hosting with CERT-In VAPT audit. Product-level government approval. Best for government, PSU, and regulated deals.
eDataRooms
Runs on MeitY-empaneled AWS India infrastructure. Hosts data on Indian servers with DPDP Act alignment. Best for cost-sensitive deals needing India hosting.
FileLink
Runs on MeitY-empaneled AWS India infrastructure. Hosts data on Indian servers with DPDP Act alignment. Best for secure ad-hoc file sharing.
Security FAQ
What encryption standards does Confiex use?
We use AES-256 encryption for all data at rest and TLS 1.3 for all data in transit, in line with ISO 27001 requirements.
Can Confiex staff access my documents?
No. Documents are encrypted and access is strictly controlled. Our team operates on a need-to-know basis with comprehensive access logging and internal controls.
What happens in a security incident?
Affected customers are notified promptly per our breach notification policy, meeting GDPR and Indian IT Act requirements. Speak to our team for details on our incident response process.
How do I get security documentation for my compliance team?
Please contact sales@confiexdataroom.com or speak to your dedicated deal manager. We can provide relevant compliance documentation appropriate to your deal type and platform choice.
Which platform should I choose if my deal requires India data residency?
DocullyVDR (MEITY-approved Azure India, product-level government approval) is the strongest option for government, PSU, and regulated-sector deals. eDataRooms and FileLink run on MeitY-empaneled AWS India infrastructure and align with DPDP Act data localization principles. Confiex Data Room runs on AWS global infrastructure and does not carry India data residency claims — we recommend DocullyVDR instead when sovereignty is required.