01
Our approach
Trust is designed into the engagement
Kriyantha considers security, privacy, continuity and accountability from assessment through support. The exact controls depend on the information involved, the client environment, the solution architecture and the consequences of failure.
Every engagement should make responsibilities visible: what Kriyantha manages, what the client manages and what remains with a cloud, AI, hardware or communications provider.
02
Core safeguards
Practical controls, proportionate to risk
Data minimisation
Collect, use and retain only the information needed for an approved purpose.
Least-privilege access
Limit viewing, editing, exporting and administration to authorised roles.
Secure architecture
Document important data flows, integrations, storage locations and recovery dependencies.
Traceability
Use appropriate logs, review points and change records for important system activity.
Retention & deletion
Define how long information is needed and how deletion, return or archival is handled.
Vendor visibility
Identify material cloud, AI, hardware and communication providers used in the solution.
03
Responsible AI
Automation should support accountable decisions
AI features are scoped for a defined business purpose, tested against agreed use cases and placed behind human review where an error could materially affect a person, operation or decision.
Model limitations, data dependencies and material third-party providers should be visible. Kriyantha does not present probabilistic output as guaranteed fact or recommend unsupervised high-impact use without appropriate governance.
04
Connected systems
Hardware integrations need physical and digital safeguards
Device identity, network exposure, access controls, update paths, availability and safe fallback behaviour are considered alongside the software layer. Where cameras, attendance systems, access control or sensors involve people, the purpose, notices, retention and authorised access require explicit review.
Alternative methods should be considered when they can meet the operational need with less personal data or lower risk.
05
Operational readiness
Security continues after launch
Monitoring
Agree what is monitored, who receives alerts and what requires escalation.
Recovery
Define backup, restoration and continuity expectations for critical components.
Incidents
Document reporting routes, decision owners and coordination responsibilities.
Change control
Review material changes to integrations, permissions, models and devices.
Kriyantha does not claim that every solution is certified, compliant with every framework, or free from risk. Applicable controls and contractual responsibilities are confirmed for each engagement.
Primary sources
Official references
These links are provided for direct access to current Indian government sources. They do not turn this page into a certification or legal opinion.