PatchMortem / Security

What runs on your servers. What leaves your network. What we cannot do.

Trust in this category is not a badge on a page. It is knowing exactly what the agent does, where the data sits, and what we will refuse to automate.

You are giving us an agent on production servers. Here is exactly what it does — and what it does not do.

Data residency in India

All customer data is stored and processed in AWS Asia Pacific (Mumbai), ap-south-1. Nothing is replicated outside the region. Zurlux Technologies will not change this default without written notice to affected customers.

Agent behaviour

The PatchMortem agent is a code-signed binary deployed on managed endpoints. It collects patch state and servicing logs. Remediation capability is off by default and must be enabled explicitly, per policy, per host group. The agent initiates outbound TLS only — there is no inbound listener and no open port on your estate.

Encryption

All data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. Per-tenant key isolation is enforced — no shared credentials between customer environments. Encryption keys are managed via AWS KMS with automatic rotation.

Access control

PatchMortem supports SAML and OIDC single sign-on. Role-based access control (RBAC) is enforced at the API level. An approval gate is required for any action that changes the state of a host. All access is logged to the audit chain.

Audit trail integrity

Every detection, decision, approval, and rollback is written to an append-only, HMAC-SHA256 chained audit log. Records cannot be edited or deleted by any user, including Zurlux staff. Retention is configured by the customer and the chain is exportable on demand in formats accepted by RBI, PCI-DSS, SEBI, and IRDAI auditors.

Multi-tenancy and isolation

PatchMortem uses a multi-tenant architecture with PostgreSQL row-level security. mTLS is enforced between all internal services. Secrets are managed via AWS Secrets Manager. GuardDuty threat detection runs across the AWS Organisation.

Vulnerability management

All container images are scanned on push via AWS Inspector. Dependencies are monitored via GitHub Dependabot with automated pull requests for security updates. An independent penetration test (VAPT) is scheduled prior to general availability and the report will be shared with customers on request under NDA.

Incident response

Security incidents are acknowledged within 72 hours of report. Critical vulnerabilities affecting customer data are disclosed to affected customers within 48 hours of confirmation. Report issues to security@zurlux.com — PGP key on request.

What we do not do

  • We do not patch anything on our own initiative. PatchMortem reacts to your schedule; it does not set one.
  • We do not claim agentless coverage. Real root cause needs the servicing logs, and those live on the host.
  • We do not roll back where the rollback is unsafe — a driver, firmware flash, or schema change gets flagged for a human.
  • We do not hold SOC 2 or ISO 27001 today. The controls above are built and running; the audits are on the roadmap and we will not imply otherwise.
  • We do not access customer systems without explicit authorisation documented in a signed Data Processing Addendum.

Certifications and compliance status

SOC 2 Type IIn progress — target Q4 2026
ISO 27001Roadmap — 2027
RBI IT Framework 2023Aligned — audit trail designed for Section 4.2
SEBI Cyber Security CircularAligned
IRDAI Info Security GuidelinesAligned
VAPTScheduled — pre-GA
Data residencyAWS ap-south-1 (Mumbai) — all data

Data Processing Addendum

Zurlux Technologies acts as Data Processor and the customer as Data Fiduciary under the Digital Personal Data Protection Act 2023. A signed Data Processing Addendum governs every production engagement and covers scope of processing, sub-processors, security measures, data localisation, breach notification, and audit rights.

PatchMortem processes operational infrastructure telemetry — hostnames, patch state, servicing logs, and the identity of operators who approve actions. It does not require or request end-customer personal data.

RoleZurlux is Data Processor; customer is Data Fiduciary
Sub-processorsAWS (ap-south-1). Disclosed in the executed DPA; changes notified in advance.
Data localisationAll processing within India. No cross-border transfer.
Audit rightsCustomer may audit compliance under the terms set out in the executed DPA
Obtaining a copyRequest from hello@zurlux.com

RBI compliance alignment

PatchMortem's audit chain is built specifically against the evidence requirements of the RBI IT Framework 2023, Section 4.2. Rather than producing a general activity log, it records the specific artefacts an inspector asks for: what failed, why it was classified the way it was, who approved the remediation, what was executed, and proof that the record has not been altered since.

RBI IT Framework 2023Audit chain designed for Section 4.2 evidence requirements; one-click export
Change control evidenceFour-eyes approval enforced and logged for every state-changing action
Tamper evidenceHMAC-SHA256 chaining with key versioning — altering one record breaks the chain
Data localisationAWS ap-south-1 (Mumbai) — satisfies Indian data residency expectations
Adjacent frameworksSEBI Cyber Security Circular, IRDAI Information Security Guidelines, PCI DSS 6.3

Alignment is not certification. PatchMortem is designed against these frameworks and produces evidence in the formats they require; it does not carry an accreditation on their behalf, and your own audit obligations remain yours.

Send it to your security team

We would rather answer the hard questions before a pilot than during one.