Trust in this category is not a badge on a page. It is knowing exactly what the agent does, where the data sits, and what we will refuse to automate.
You are giving us an agent on production servers. Here is exactly what it does — and what it does not do.
All customer data is stored and processed in AWS Asia Pacific (Mumbai), ap-south-1. Nothing is replicated outside the region. Zurlux Technologies will not change this default without written notice to affected customers.
The PatchMortem agent is a code-signed binary deployed on managed endpoints. It collects patch state and servicing logs. Remediation capability is off by default and must be enabled explicitly, per policy, per host group. The agent initiates outbound TLS only — there is no inbound listener and no open port on your estate.
All data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. Per-tenant key isolation is enforced — no shared credentials between customer environments. Encryption keys are managed via AWS KMS with automatic rotation.
PatchMortem supports SAML and OIDC single sign-on. Role-based access control (RBAC) is enforced at the API level. An approval gate is required for any action that changes the state of a host. All access is logged to the audit chain.
Every detection, decision, approval, and rollback is written to an append-only, HMAC-SHA256 chained audit log. Records cannot be edited or deleted by any user, including Zurlux staff. Retention is configured by the customer and the chain is exportable on demand in formats accepted by RBI, PCI-DSS, SEBI, and IRDAI auditors.
PatchMortem uses a multi-tenant architecture with PostgreSQL row-level security. mTLS is enforced between all internal services. Secrets are managed via AWS Secrets Manager. GuardDuty threat detection runs across the AWS Organisation.
All container images are scanned on push via AWS Inspector. Dependencies are monitored via GitHub Dependabot with automated pull requests for security updates. An independent penetration test (VAPT) is scheduled prior to general availability and the report will be shared with customers on request under NDA.
Security incidents are acknowledged within 72 hours of report. Critical vulnerabilities affecting customer data are disclosed to affected customers within 48 hours of confirmation. Report issues to security@zurlux.com — PGP key on request.
| SOC 2 Type I | In progress — target Q4 2026 |
| ISO 27001 | Roadmap — 2027 |
| RBI IT Framework 2023 | Aligned — audit trail designed for Section 4.2 |
| SEBI Cyber Security Circular | Aligned |
| IRDAI Info Security Guidelines | Aligned |
| VAPT | Scheduled — pre-GA |
| Data residency | AWS ap-south-1 (Mumbai) — all data |
Zurlux Technologies acts as Data Processor and the customer as Data Fiduciary under the Digital Personal Data Protection Act 2023. A signed Data Processing Addendum governs every production engagement and covers scope of processing, sub-processors, security measures, data localisation, breach notification, and audit rights.
PatchMortem processes operational infrastructure telemetry — hostnames, patch state, servicing logs, and the identity of operators who approve actions. It does not require or request end-customer personal data.
| Role | Zurlux is Data Processor; customer is Data Fiduciary |
| Sub-processors | AWS (ap-south-1). Disclosed in the executed DPA; changes notified in advance. |
| Data localisation | All processing within India. No cross-border transfer. |
| Audit rights | Customer may audit compliance under the terms set out in the executed DPA |
| Obtaining a copy | Request from hello@zurlux.com |
PatchMortem's audit chain is built specifically against the evidence requirements of the RBI IT Framework 2023, Section 4.2. Rather than producing a general activity log, it records the specific artefacts an inspector asks for: what failed, why it was classified the way it was, who approved the remediation, what was executed, and proof that the record has not been altered since.
| RBI IT Framework 2023 | Audit chain designed for Section 4.2 evidence requirements; one-click export |
| Change control evidence | Four-eyes approval enforced and logged for every state-changing action |
| Tamper evidence | HMAC-SHA256 chaining with key versioning — altering one record breaks the chain |
| Data localisation | AWS ap-south-1 (Mumbai) — satisfies Indian data residency expectations |
| Adjacent frameworks | SEBI Cyber Security Circular, IRDAI Information Security Guidelines, PCI DSS 6.3 |
Alignment is not certification. PatchMortem is designed against these frameworks and produces evidence in the formats they require; it does not carry an accreditation on their behalf, and your own audit obligations remain yours.
We would rather answer the hard questions before a pilot than during one.