ArthaOps
PlatformTrustCase StudiesPricingDocs
Sign InStart Free
ZERO-AGENT READ-ONLY DEPLOYMENT // MULTI-CLOUD IAM & RBAC

Evaluate your multi-cloud environment in under 2 minutes.

Deploy the agentless read-only scanner with zero long-lived credentials stored. Real-time deterministic waste detection across 378 active multi-cloud rules.

Start Free ScanBook Demo
$curl -sSL https://arthaops.com/scan | sh
ArthaOps

Zero-Trust Multi-Cloud Cost Governance Platform. Continuous waste detection, deterministic math & automated remediation.

INSTITUTIONAL FINOPS // ZERO-TRUST ENGINE

01 PLATFORM

Platform OverviewControl RoomCloud TopologyDetector EngineAsset InventoryRemediation EngineSavings IntelligenceDetector CatalogPlatform ComparisonPricing

02 TRUST

Trust CenterSecurity ArchitectureCompliance MatrixSovereign Proxy Guarantee

03 RESOURCES

DocumentationChangelogCase StudiesCustomer GuaranteesROI CalculatorGitHub Repository

04 COMPANY

About UsContact UsEnterprise Sales
45.0°W:117.0mmR:14.0mmH:53.0mmCL:298.0GAP:15.045.0°O-DIAM:117.0P-LOOP:38.0S-END:957.0117.0117.0117.0117.0117.0117.0117.0117.03.03.03.03.03.03.03.0P1P2P3P4P5P6P7P8P9⊕ DATUM-A (0,53)⊕ DATUM-B (957,0)OVERALL WIDTH: 957.00 mm53.00 mmDESIGNED BY ARTHAOPSMISSION CONTROL // CLASS-ATECH SINGULARITYSECTION 9 // ISO-128CAD DWG NO: AO-2026-M290 // SCALE 1:1 // TOLS: ±0.005mm // SHADER: WGL-V2 // CERTIFIED MAXIMUM HIGH-DENSITY CAD SCHEMATIC
© 2026 ArthaOps. Inc. All rights reserved.
SOC2 TYPE II READY // READ-ONLY IAM
Privacy PolicyTerms of ServiceCookie PolicyRefund PolicySystem Status
/////DATA PROTECTION
[DPDPA 2023]

Data protection · DPDPA 2023, IT Act 2000 & GDPR compliance

Comprehensive Privacy Policy

Effective Date: March 31, 2026 · Last Updated: July 27, 2026 · ArthaOps. Inc.

1. Introduction & Corporate Identity & Commitment to Privacy

Welcome to the exhaustive Privacy Policy of ArthaOps. Inc. (hereinafter referred to interchangeably as "ArthaOps," "we," "us," or "our"). We recognize that in the modern enterprise software-as-a-service (SaaS) landscape, particularly concerning cloud cost optimization and infrastructure governance, data privacy is not merely a statutory obligation but a foundational pillar of trust, architectural integrity, and operational security.

This Privacy Policy sets forth our unwavering commitment to safeguarding the personal, technical, and metadata derived from our business-to-business (B2B) clientele. Our platform is designed with privacy-by-design and privacy-by-default architectures, strictly aligning with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000 (IT Act), the CERT-In Cyber Security Directions 2022, and maintaining rigorous sovereign alignment with the General Data Protection Regulation (GDPR) for our global stakeholders. We operate exclusively on a multi-tenant cloud cost management thesis, identifying waste and inefficiency across AWS environments, deploying our proprietary suite of 378 cloud cost waste detectors.

By executing an agreement, creating an account, authenticating via our Enterprise Single Sign-On (SSO) infrastructure, or otherwise utilizing the ArthaOps Control, Operator, or Command plans, you ("Customer," "User," "Enterprise," or "Data Principal") explicitly acknowledge, comprehend, and consent to the intricate data processing paradigms articulated in this multi-tiered policy document. We implore you to read this document with the utmost scrutiny, as it constitutes a binding legal framework governing the lifecycle, ingestion, processing, cryptology, and eventual purge of your data within our localized sovereign cloud environments in AP-SOUTH-1 (Mumbai).

2. Legal Definitions & Interpretation

To preclude ambiguity and establish a precise lexicon for this Privacy Policy and associated agreements, the following defined terms shall have the meanings ascribed to them hereunder, whether utilized in singular or plural form, and shall dictate the interpretative boundaries of our data processing undertakings:

  1. "ArthaOps Ecosystem" refers to the totality of our software applications, proprietary APIs, CLI tools, web consoles, Autopilot remediation engines, and underlying compute infrastructure deployed to deliver our SaaS capabilities.
  2. "Personal Data" signifies any data about an individual who is identifiable by or in relation to such data, explicitly conforming to the definition under Section 2(t) of the DPDPA 2023.
  3. "Data Principal" denotes the individual to whom the personal data relates, frequently manifesting as the authorized representatives, administrators, or IAM users of our enterprise customers.
  4. "Data Fiduciary" determines the purpose and means of processing personal data; ArthaOps acts as a Data Fiduciary concerning account registration and billing information.
  5. "Data Processor" refers to any person who processes personal data on behalf of a Data Fiduciary; ArthaOps acts as a Data Processor concerning the telemetry, logs, and metadata fetched from Customer AWS environments.
  6. "Processing" encapsulates any automated operation or set of operations performed on digital personal data, encompassing collection, recording, organization, structuring, storage, adaptation, retrieval, use, alignment, combination, restriction, erasure, or destruction.
  7. "Consent Manager" represents an entity registered under the DPDPA 2023 accountable for providing an accessible, transparent, and interoperable platform to give, manage, review, and withdraw consent.
  8. "Metadata" encompasses the structural, descriptive, and administrative data generated by AWS services (e.g., tags, resource IDs, provisioning states) that ArthaOps ingests, devoid of the underlying payload or content data stored within those resources.
  9. "Zero Static Credential Architecture" is our foundational security paradigm wherein no long-lived AWS Access Key IDs or Secret Access Keys are ever persisted, transmitted, or utilized within our databases.
  10. "AWS STS AssumeRole" refers to the ephemeral credential vending mechanism facilitated by the AWS Security Token Service, incorporating strict External ID validation to thwart confused deputy vulnerabilities.
  11. "Autopilot" designates our optional, autonomous remediation engine capable of executing non-destructive state changes via a dry-run validated dependency graph.
  12. "Sovereign Cloud Localization" mandates the exclusive provisioning, processing, and retention of all platform telemetry, databases, cache layers, and backups strictly within the geographical boundaries of the Republic of India (AP-SOUTH-1).
  13. "Audit Ledger" signifies our cryptographically immutable, SHA-256 linear hash-chained system of record, designed to establish a tamper-evident chronical of all platform mutations and IAM role assumptions.
  14. "Sub-processor" means any third-party entity engaged by ArthaOps to process Personal Data on our behalf, subjected to rigorous vendor risk assessments and equivalent contractual obligations.
  15. "Grievance Officer" denotes the statutory role mandated by the IT Act 2000 and DPDPA 2023, responsible for expeditiously addressing and resolving complaints from Data Principals.
  16. "Data Breach" implies a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
  17. "Anonymization" is the irreversible cryptographic and structural alteration of Personal Data such that the Data Principal can no longer be identified, directly or indirectly.
  18. "DSAR" refers to a Data Subject Access Request, an explicit statutory mechanism allowing Data Principals to exercise their rights to access, correction, erasure, and portability.
  19. "Cost Telemetry" includes aggregated, high-level metrics pertaining to AWS billing (e.g., Cost Explorer outputs, CUR reports) required for waste detection algorithms.
  20. "Service Level Agreement (SLA)" constitutes our operational commitment, explicitly targeting a 99.9% uptime metric for our SaaS interfaces and background worker pools.

3. Scope of Application & Platform Architecture

This Privacy Policy universally governs all interactions, data exchanges, and API payloads executed between ArthaOps and its authorized users across the entire spectrum of our offerings. This scope includes the public-facing marketing website, the authenticated web application (Control Plane), our programmatic interfaces (APIs), our documentation repositories, and the backend ingestion daemons that interface with your localized AWS infrastructure. The architectural blueprint of ArthaOps is explicitly engineered to decouple the control plane (hosted by us) from the data plane (residing within your AWS accounts), thereby minimizing our blast radius and dramatically reducing the volume of sensitive data traversing our network boundaries.

It is imperative to note that this Policy does not govern the privacy practices of third-party platforms, open-source dependencies deployed within your environments independently, or the underlying core infrastructure provided by Amazon Web Services, except to the extent that ArthaOps interacts with such services via explicitly granted IAM roles. We emphatically disclaim any liability for data exposures, misconfigurations, or privacy breaches originating from the inherent insecurity of the customer's proprietary applications, underlying network architecture, or failure to adhere to the principle of least privilege when provisioning the ArthaOps IAM Role. Our scope is strictly bounded by the permissions defined in our provided CloudFormation and Terraform templates.

If you do not agree with the extensive, uncompromising data handling practices delineated herein, your sole and exclusive remedy is to immediately cease all usage of the ArthaOps platform, revoke all IAM roles granted to our AWS Account IDs, and initiate an account deletion request via our primary support vector at support@arthaops.com. Continued utilization of the service unequivocally constitutes binding acceptance of these architectural constraints and privacy protocols.

4. Data Minimization & Exact Ingestion Scope

ArthaOps enforces an aggressive, unyielding stance on data minimization. We operate under the foundational premise that we cannot leak, lose, or expose data that we simply do not possess. Our ingestion daemons are mathematically constrained to invoke read-only AWS APIs (specifically List*, Describe*, and GetMetricData operations) to fetch the absolute minimum metadata required to fuel our 378 cloud cost waste detectors. We do not inspect payloads, we do not read object contents, and we do not query your relational or non-relational database rows. The ingestion scope is meticulously delineated across the following AWS services:

  • Amazon EC2 (Elastic Compute Cloud): We retrieve instance metadata including instance types, state transitions, associated security groups, IAM instance profiles, VPC affiliations, and high-level utilization metrics (CPU, Network In/Out) via CloudWatch to identify over-provisioned, idle, or unattached instances. We do not have SSH access, Systems Manager (SSM) access, or the ability to execute commands on your instances.
  • Amazon RDS (Relational Database Service): Our ingestion is limited to cluster/instance configuration metadata, engine versions, allocated storage, IOPS provisioning, multi-AZ deployment status, and CloudWatch performance metrics. We do NOT possess database credentials, we cannot connect to the database endpoints (port 3306, 5432, etc.), and we absolutely cannot execute SQL queries, inspect schemas, or view row-level data.
  • Amazon EBS (Elastic Block Store): We analyze volume metadata, attachment states, volume types (gp2, gp3, io1, io2), size parameters, and read/write byte metrics to flag unattached, orphaned, or severely underutilized block storage. We never take volume snapshots for our own use and cannot read the underlying file systems or data blocks formatted on the EBS volumes.
  • Amazon S3 (Simple Storage Service): Our visibility is rigidly restricted to bucket-level metadata, lifecycle configuration rules, versioning status, public access block configurations, and aggregate storage metrics (bucket size, object count). We categorically DO NOT possess s3:GetObject permissions. We cannot read, download, or index the files, images, documents, or data payloads stored within your S3 buckets.
  • Amazon ElastiCache: We examine Redis and Memcached cluster configurations, node types, engine versions, parameter groups, and CloudWatch utilization metrics (CPU, Swap Usage, Evictions) to determine sizing efficiency. We cannot execute Redis commands (e.g., GET, SET, KEYS) or access the cached data payloads in any capacity.
  • Amazon EKS (Elastic Kubernetes Service): We monitor cluster metadata, node group configurations, Fargate profiles, and control plane logging statuses. If granted optional permissions, we may analyze Prometheus metrics for pod-level resource utilization, but we never access Kubernetes Secrets, ConfigMaps containing sensitive data, or application logs inside the pods.
  • Amazon VPC (NAT Gateways): We scrutinize NAT Gateway configurations, active connections, and bytes processed metrics to identify inefficient routing, cross-AZ data transfer anomalies, and idle gateways. We do not perform deep packet inspection (DPI) or analyze the contents of the network traffic traversing the gateways.
  • Amazon CloudWatch: We extensively utilize GetMetricData to ingest time-series performance metrics for the aforementioned services. This data is purely numeric (timestamps and floating-point values) and contains no personally identifiable information (PII) or business logic.

5. What We NEVER Collect (Strict Exclusions)

To further cement our commitment to data minimization and to provide absolute clarity to our enterprise clientele, ArthaOps explicitly, categorically, and unconditionally prohibits the ingestion, processing, storage, or transmission of the following categories of data. Our technical architecture actively prevents the collection of this information, and our IAM bounds are mathematically incapable of accessing it:

  • Protected Health Information (PHI): We do not collect, process, or store any data governed by HIPAA, the HITECH Act, or equivalent global health privacy frameworks. Our systems will never touch medical records, patient histories, or biometric data.
  • Payment Card Industry (PCI) Data: While we accept payments for our SaaS subscriptions, all credit card processing is offloaded entirely to Razorpay (a PCI-DSS Level 1 compliant entity). ArthaOps never sees, processes, or stores your Primary Account Numbers (PAN), CVV codes, or expiration dates on our infrastructure.
  • Customer Application Payloads: As emphasized in our ingestion scope, we do not possess the APIs, network routes, or IAM permissions to read the actual data stored in your RDS rows, DynamoDB tables, S3 objects, or EBS volumes. Your proprietary business data remains cryptographically sealed within your AWS account.
  • Long-Lived AWS Credentials: We never ask for, accept, or store AWS Access Key IDs or Secret Access Keys. Any attempt to supply such credentials to our support staff will result in the immediate destruction of the message and a mandatory rotation request directed to your security team.
  • End-User PII: We do not monitor the individuals utilizing your software applications. We have zero visibility into your users' names, email addresses, IP addresses (unless accessing our Control Plane directly), physical locations, or behavioral patterns.
  • Source Code or Intellectual Property: We do not integrate with your version control systems (GitHub, GitLab, Bitbucket) for the purpose of source code analysis. We do not read, clone, or analyze your proprietary algorithms, application logic, or intellectual property.
  • Zero Third-Party AI Model Training: We categorically DO NOT use your AWS infrastructure metadata, telemetry, or configuration data to train public, third-party generative foundation models (such as OpenAI, Anthropic, or Google Gemini). All internal heuristic optimizations remain strictly confined to anonymized numeric metrics within our sovereign AP-SOUTH-1 infrastructure.

6. Legal Basis for Data Processing

In strict adherence to the fundamental principles of modern privacy legislation, including the Digital Personal Data Protection Act, 2023 (DPDPA) and the General Data Protection Regulation (GDPR), ArthaOps processes your minimal Personal Data and extensive infrastructure Metadata on precisely defined legal bases. We do not engage in arbitrary or legally ambiguous data processing activities. Our processing operations are grounded in the following justifications:

A. Contractual Necessity (Performance of a Contract): The overwhelming majority of our data processing—including user registration via Logto Cloud OIDC, billing operations via Razorpay, and the core ingestion of AWS metadata—is strictly necessary for the performance of the SaaS agreement (Terms of Service) executed between ArthaOps and the Customer. Without processing this telemetry, the provision of our 378 cloud cost waste detectors would be technically impossible. This basis covers the core functionality of the Discovery, Control, Operator, and Command plans.

B. Explicit Consent: Where mandated by law, or for activities that fall outside the strict purview of contractual necessity (such as the activation of the autonomous Autopilot remediation features, or opting into marketing communications), we rely on explicit, informed, and unambiguous consent. Under the DPDPA 2023, this consent is obtained via clear affirmative action, managed transparently, and can be withdrawn at any time without prejudice, subject to the technical limitations of reversing automated actions already executed.

C. Legitimate Interests: We may process certain metadata, anonymized telemetry, and platform usage analytics to fulfill our legitimate business interests, provided such interests are not overridden by the fundamental rights and freedoms of the Data Principal. This includes activities such as platform security enhancements, fraud detection, performance optimization of our infrastructure in AP-SOUTH-1, and the continuous refinement of our waste detection algorithms. We utilize post-processed, sanitized data via PostHog to fulfill these interests, ensuring individual privacy is maintained.

D. Legal Obligation: ArthaOps will process and, if necessary, disclose Personal Data and audit logs when strictly required to comply with a binding legal obligation imposed by the laws of India. This includes, but is not limited to, compliance with the Companies Act 2013 for financial auditing, the CGST Act 2017 for tax invoicing (generating B2B GSTIN credit notes), and responding to lawful, validly issued subpoenas or warrants from Indian judicial authorities or statutory bodies such as CERT-In.

7. India Sovereign Region Localization & DPDPA 2023 Compliance

ArthaOps operates under a rigid sovereign data mandate, purposefully engineered to exceed the localization requirements and privacy standards of the Indian regulatory landscape. We have centralized our entire primary production infrastructure, including all compute clusters, relational databases, distributed cache layers (Redis), event brokers, and persistent block storage, exclusively within the AWS AP-SOUTH-1 (Mumbai) region. This architectural decision guarantees absolute data residency within the Republic of India.

Our compliance posture is deeply integrated with the mandates of the Digital Personal Data Protection Act, 2023 (DPDPA). We operationalize compliance with key sections as follows:

  • Section 3 (Application of the Act): We acknowledge the application of the DPDPA to all digital personal data processed within the territory of India by our platform, treating all user records with the highest echelon of regulatory scrutiny.
  • Section 16 (Processing of Personal Data outside India): While our core infrastructure is localized in Mumbai, we strictly regulate any incidental cross-border transfers (e.g., to global sub-processors like Sentry for error tracking). Such transfers are governed by robust Standard Contractual Clauses (SCCs) and are restricted solely to permissible jurisdictions that offer an adequate level of data protection, ensuring no dilution of the Data Principal's rights.
  • Section 17 (Exemptions): We do not rely on broad exemptions under the DPDPA. We recognize that our B2B operations do not absolve us of the responsibility to protect the personal data of the administrators and operators utilizing our platform. However, we acknowledge statutory exemptions related to the processing of data necessary for enforcing legal rights, preventing fraud, or complying with judicial orders.

8. AWS STS AssumeRole Credential Architecture & Zero Key Storage

The cornerstone of ArthaOps' security and privacy framework is our uncompromising Zero Static Credential Architecture. Traditional SaaS platforms often request long-lived AWS Access Keys, creating a catastrophic vulnerability if the SaaS provider's database is compromised. ArthaOps categorically rejects this paradigm. We utilize the AWS Security Token Service (STS) to implement a dynamic, ephemeral credential vending machine.

When a Customer integrates their AWS environment with ArthaOps, they deploy an IAM Role via CloudFormation or Terraform. This role establishes a trust relationship exclusively with the ArthaOps AWS Account ID. Crucially, we mandate the use of a cryptographically secure, unique External ID generated during the onboarding process. This External ID acts as a cryptographic nonce, unequivocally mitigating the "Confused Deputy" vulnerability, ensuring that no other ArthaOps customer can maliciously assume your IAM role.

When our background worker pools require telemetry, they invoke the sts:AssumeRole API endpoint, supplying the target Role ARN and the specific External ID. AWS validates this request and issues ephemeral, short-lived session tokens (typically valid for 15 to 60 minutes). These temporary credentials are held only in the volatile memory of our worker nodes and are never written to persistent disk storage, databases, or cache layers. Once the ingestion task is complete, the session tokens evaporate. Even in the theoretical event of a database exfiltration, an attacker would yield absolutely zero actionable AWS credentials.

9. Autopilot Autonomous Remediation & Data Access Governance

ArthaOps offers an advanced, optional capability termed "Autopilot," designed to execute autonomous remediation actions against identified cloud cost waste. Given the inherent risks of programmatic infrastructure modification, the Autopilot feature operates under an exceptionally strict data access governance model, requiring explicit, multi-layered authorization.

Autopilot is strictly opt-in. The default IAM Role provisioned during onboarding contains only ReadOnlyAccess bounds. To enable Autopilot, the Customer must proactively deploy a supplementary IAM policy that grants narrowly scoped mutation permissions (e.g., ec2:StopInstances, rds:StopDBInstance, ebs:DeleteVolume). ArthaOps will never autonomously attempt to escalate privileges or brute-force mutation operations.

Furthermore, the Autopilot engine operates via a rigorous Dry-Run Dependency Graph. Before any destructive or state-altering API call is executed, our engine simulates the action to evaluate potential cascading failures or downstream dependencies. All Autopilot actions—both dry-runs and actual executions—are permanently etched into our SHA-256 Hash-Chained Audit Ledger. For high-risk operations, Autopilot enforces a 1-click snapshot rollback mechanism, ensuring that point-in-time recovery data is available prior to resource termination, thereby safeguarding business continuity and data integrity.

10. How We Use Your Information

ArthaOps processes the ingested metadata, telemetry, and personal data (such as authentication identifiers) for a meticulously defined set of purposes. We adhere to the principle of purpose limitation, ensuring that data is never repurposed for secondary, undisclosed activities such as data brokering or algorithmic surveillance. The explicit purposes for processing include:

  1. Service Delivery & Waste Detection: The primary utilization of your AWS metadata is to power our proprietary analytical engines. We process this data to identify cost inefficiencies, generate optimization recommendations, and project financial savings across your compute, storage, and networking primitives.
  2. Authentication & Authorization: We use identity data (provided via Logto Cloud OIDC) to authenticate users, manage session state, enforce multi-tenant workspace isolation, and validate Role-Based Access Control (RBAC) within the ArthaOps console.
  3. Financial Processing & Billing: Corporate billing details, GSTIN information, and subscription tier data are processed to calculate usage, generate tax-compliant invoices in sovereign INR (₹), and facilitate secure payment collection via Razorpay.
  4. Operational Telemetry & Performance Tuning: We aggregate anonymized system logs and performance metrics to monitor the health of our AP-SOUTH-1 infrastructure, trace API latencies, and dynamically scale our worker pools to meet our 99.9% SLA uptime targets.
  5. Security Auditing & Threat Mitigation: Log data, IP addresses, and user agent strings are analyzed continuously to detect anomalous access patterns, brute-force attempts, and unauthorized API invocations, ensuring the integrity of the platform.
  6. Customer Support & Grievance Resolution: Communication metadata, support tickets, and direct inquiries submitted to support@arthaops.com or grievance@arthaops.com are processed solely to troubleshoot issues, provide technical assistance, and fulfill our statutory grievance redressal obligations.
  7. Platform Evolution & Analytics: We utilize anonymized, sanitized interaction data via PostHog to understand feature adoption rates, optimize user interface workflows, and prioritize the development roadmap. This data is rigorously stripped of all PII and customer-specific infrastructure identifiers.

11. Information Sharing, Sub-processors & Third-Party Disclosures

ArthaOps operates as a modern cloud-native entity and, by necessity, leverages a curated selection of elite third-party service providers (Sub-processors) to deliver our SaaS capabilities. We do not sell, rent, or indiscriminately share your data. All sub-processors are subjected to intense security evaluations and are bound by stringent Data Processing Agreements (DPAs) that mandate security postures equivalent to or exceeding our own. Our primary sub-processors include:

  • Amazon Web Services (AWS): Serves as our foundational Infrastructure-as-a-Service (IaaS) provider. All core databases, compute nodes, and storage arrays reside within the AWS AP-SOUTH-1 (Mumbai) region. AWS physical security and hypervisor isolation are foundational to our security posture.
  • Logto Cloud Inc.: Facilitates our Enterprise Single Sign-On (SSO) and identity management. Logto Cloud handles user authentication, session tokens, and OAuth/Passkeys workflows, ensuring secure, isolated tenant access.
  • Razorpay: Functions as our exclusive payment gateway. Razorpay (PCI-DSS Level 1) processes all INR (₹) transactions, subscription renewals, and manages the secure tokenization of payment instruments. ArthaOps does not touch raw payment data.
  • Sentry: Utilized for real-time error tracking and exception monitoring in our application code. We employ aggressive data scrubbing configurations to ensure zero PII, AWS identifiers, or sensitive payload data is transmitted to Sentry's aggregation servers.
  • PostHog: Deployed for product analytics and usage telemetry. PostHog is configured to rely strictly on anonymized, internal workspace identifiers. No raw IP addresses, user names, or infrastructure metadata are sent to this service.

Mandatory Disclosures: Notwithstanding the above, ArthaOps reserves the unassailable right to disclose your data if legally compelled to do so by a valid court order, subpoena, or statutory directive from Indian law enforcement or regulatory authorities (e.g., CERT-In), or when we determine in good faith that disclosure is strictly necessary to protect the physical safety, property, or vital interests of ArthaOps, our users, or the public.

12. CERT-In Cyber Security Directions 2022 & IT Act 2000 Compliance

As a technology company operating within the Indian jurisdiction, ArthaOps is fully cognizant of and strictly complies with the Information Technology Act, 2000, and the sweeping Cyber Security Directions issued by the Indian Computer Emergency Response Team (CERT-In) in April 2022.

In absolute compliance with CERT-In mandates, we maintain synchronized Network Time Protocol (NTP) servers connected to authorized Stratum 1 time sources (NIC/NPL) for all infrastructure logging. We are legally bound to report any severe cyber security incidents (as classified in Annexure I of the Directions) to CERT-In within the mandatory 6-hour window. This aggressive reporting timeline is embedded directly into our incident response runbooks.

Furthermore, we strictly adhere to the data retention mandates stipulated by the IT Act and CERT-In. We securely retain specified system logs, firewall configurations, and access trails within our sovereign Indian infrastructure for a rolling period of 180 days, making them available to authorized government agencies solely upon the presentation of a valid, lawful requisition order.

13. Data Retention Schedules & Archival Policies

ArthaOps enforces precise, automated data retention and destruction lifecycles. We do not hoard data indefinitely. Our retention schedules are explicitly categorized and strictly enforced by automated background cron jobs:

  • Active AWS Telemetry & Cost Data: Metadata and aggregated cost metrics utilized by our detectors are retained for a maximum of 13 months to facilitate accurate year-over-year comparative analysis and predictive forecasting. Data exceeding this window is automatically purged.
  • Audit Ledger Logs: The SHA-256 hash-chained operational logs, critical for security investigations and compliance audits, are retained for 7 years to align with the statute of limitations under Indian corporate law and financial auditing requirements.
  • Account Deletion Purge: Upon explicit initiation of an account deletion request, or following the termination of a subscription with no subsequent renewal, all associated tenant data, IAM role configurations, historical telemetry, and user profiles are placed into a soft-delete state. We execute a hard, cryptographic purge of this data exactly 30 days post-deletion. This 30-day window is maintained solely to facilitate accidental deletion recovery.
  • Financial Invoicing Data: B2B GSTIN invoices, transaction IDs, and CGST/SGST/IGST credit notes are retained for a period of 8 years in strict compliance with the mandate of the Companies Act 2013 and the directives of the Central Board of Indirect Taxes and Customs (CBIC).

14. Encryption at Rest & In Transit

Cryptographic security is not an afterthought; it is woven into the very fabric of the ArthaOps architecture. We employ military-grade encryption protocols to ensure the confidentiality and integrity of all data moving through or resting within our sovereign infrastructure.

Encryption in Transit: Absolute transport layer security is enforced across all network boundaries. All communication between the Customer's browser, our API gateways, internal microservices, and external sub-processors is rigorously encrypted using TLS 1.3 (Transport Layer Security) with perfect forward secrecy (PFS). We utilize strictly configured cipher suites (e.g., TLS_AES_256_GCM_SHA384) and explicitly disable legacy protocols such as TLS 1.0, TLS 1.1, and all versions of SSL. Non-HTTPS traffic is aggressively rejected or immediately redirected to secure endpoints via HTTP Strict Transport Security (HSTS) directives.

Encryption at Rest: Every single byte of data resting within our AP-SOUTH-1 infrastructure—encompassing our relational databases (Amazon RDS PostgreSQL), persistent block storage (Amazon EBS), object storage (Amazon S3 backups), and distributed cache (Amazon ElastiCache Redis)—is encrypted at rest using the Advanced Encryption Standard with a 256-bit key (AES-256). We utilize the AWS Key Management Service (KMS) for robust, centralized cryptographic key generation, rotation, and access control, ensuring that underlying storage volumes remain entirely impenetrable even in the event of physical drive theft from an AWS data center.

15. SHA-256 Hash-Chained Audit Ledger Architecture

Transparency and operational accountability are paramount for enterprise trust. To provide unassailable proof of our platform's actions—particularly concerning IAM role assumptions and Autopilot mutations—ArthaOps has engineered a proprietary, cryptographically secure Audit Ledger.

This ledger operates on a linear, SHA-256 hash-chain architecture. Every significant state change, API invocation against a Customer's AWS account, and background synchronization event is recorded as a discrete, immutable block. Each block computes a cryptographic hash that inherently incorporates the hash of the immediately preceding block. This mechanism guarantees that the ledger is mathematically tamper-evident — any attempt to silently alter, delete, or rewrite historical logs would instantaneously invalidate the subsequent hash chain, triggering immediate internal security alarms and visibly corrupting the ledger's integrity. Note: this is a centrally managed, linear hash-chain ledger, distinct from decentralized blockchain architectures.

This Audit Ledger is fully accessible to the Customer via the Command plan interface, allowing security operations teams to continuously monitor exactly what ArthaOps is doing, when it did it, and under what authorization context.

16. Your Data Subject Rights

Under the robust framework of the DPDPA 2023, the GDPR, and other progressive privacy legislations, you, as a Data Principal, possess a suite of fundamental, inalienable rights concerning your personal data. ArthaOps is fully committed to facilitating the seamless exercise of these rights:

  1. Right to Access: You have the absolute right to request a comprehensive summary of the personal data we hold about you, the identities of all Data Fiduciaries/Processors with whom it has been shared, and the specific purposes of processing.
  2. Right to Correction: You maintain the right to mandate the immediate rectification of inaccurate, misleading, or incomplete personal data, and the right to demand the updating of obsolete information.
  3. Right to Erasure (Right to be Forgotten): Subject to our aforementioned statutory data retention mandates (e.g., financial records, audit logs), you have the right to demand the total erasure of your personal data when it is no longer necessary for the purpose for which it was collected.
  4. Right to Data Portability: You are entitled to receive your raw metadata and configuration telemetry in a structured, commonly used, and machine-readable format (e.g., JSON or CSV), facilitating the transfer of this data to alternative platforms or internal data lakes.
  5. Right to Withdraw Consent: Where processing is explicitly based on consent (e.g., marketing communications or optional feature toggles), you possess the right to withdraw that consent at any time, with effect for the future, without affecting the lawfulness of processing based on consent before its withdrawal.
  6. Right to Grievance Redressal: You possess the inalienable right to have any grievance related to the processing of your personal data resolved expeditiously by our designated Grievance Officer, and if unsatisfied, to escalate the matter to the Data Protection Board of India.

17. Data Subject Access Requests (DSAR) Process & Timelines

To exercise any of the rights enumerated above, Data Principals must submit a formal Data Subject Access Request (DSAR). ArthaOps has instituted a streamlined, highly responsive DSAR workflow to ensure compliance with statutory timelines.

All DSARs must be initiated via written communication directed to our dedicated privacy inbox at privacy@arthaops.com. Upon receipt, our compliance team will initiate a mandatory identity verification protocol to prevent fraudulent data extraction or unauthorized alterations. We will never fulfill a DSAR without absolute confirmation of the requester's identity.

Once identity is verified, ArthaOps guarantees the fulfillment of the DSAR within the strict 30-day statutory window prescribed by global privacy standards. In the exceptionally rare event that a request is mathematically complex or requires extensive data collation spanning multiple tenant silos, we reserve the right to extend this period by a maximum of 30 additional days, provided we proactively notify the Data Principal of the extension and the specific technical reasons necessitating the delay. All standard DSAR processing is conducted entirely free of charge.

18. Cross-Border Transfer Restrictions & Sovereign Data Lock

As emphasized in our localization commitments, ArthaOps operates under a strict Sovereign Data Lock paradigm. The overwhelming majority of your metadata, telemetry, and platform configurations remain physically and logically locked within the borders of India (AWS AP-SOUTH-1).

We vehemently reject the practice of indiscriminately replicating customer telemetry to international data centers for cost savings or operational convenience. Any incidental data transfers that cross international borders—such as transient API payloads sent to our global sub-processors (e.g., Logto Cloud for SSO, Sentry for error logging)—are subjected to extreme scrutiny. These specific data flows are governed by ironclad Standard Contractual Clauses (SCCs) and Data Processing Agreements (DPAs) that legally bind the recipient to uphold privacy standards that are completely isomorphic to the DPDPA 2023 and GDPR. Furthermore, all transmitted data is heavily sanitized, stripping out raw infrastructure identifiers, account numbers, and IP addresses prior to transmission across national borders.

19. Security Incident Response & Breach Notification Procedures

In the highly unlikely event of a catastrophic security failure, unauthorized data exfiltration, or cryptographic compromise (a "Data Breach"), ArthaOps maintains an aggressive, rehearsed Security Incident Response Plan. We do not engage in obfuscation or delay tactics.

Upon the verified detection of a breach, our incident response team initiates immediate containment protocols, including the emergency revocation of all active AWS STS tokens, the isolation of compromised infrastructure segments, and the potential suspension of the SaaS control plane to prevent further lateral movement.

Notification Timelines: We adhere to a rigid, transparent notification policy. If a breach poses a risk to your personal data or AWS infrastructure, we will notify the primary technical contact associated with your enterprise account without undue delay, and in absolutely no case later than 72 hours after becoming aware of the breach. Furthermore, in strict compliance with CERT-In directions, any severe incident will be formally reported to the Indian Computer Emergency Response Team within 6 hours of discovery. Our notifications will detail the nature of the breach, the specific data categories impacted, our immediate mitigation efforts, and actionable guidance on how to secure your AWS environment (e.g., rotating IAM external IDs).

20. B2B Enterprise-Only Scope & Children's Data Exclusions

The ArthaOps platform, including all associated software, documentation, and services, is engineered, marketed, and contractually restricted exclusively for Business-to-Business (B2B) utilization. We serve modern enterprises, cloud-native startups, and corporate entities. Our SaaS product is categorically not intended for consumer use, personal data management, or household applications.

Consequently, we strictly enforce a Children's Data Exclusion policy. ArthaOps does not knowingly solicit, collect, process, or store any personal data from individuals under the age of 18 (or the age of majority in their respective jurisdictions). Our Terms of Service explicitly prohibit the creation of accounts by minors. If we become aware, through internal audits or external notification, that we have inadvertently collected data belonging to a minor, we will execute an immediate, unrecoverable cryptographic purge of that data from all active systems and backup archives, overriding all standard retention schedules.

21. Changes to This Policy & Notice Obligations

The technology landscape, cloud computing paradigms, and global privacy legislations are in a state of continuous evolution. Consequently, ArthaOps reserves the absolute right to unilaterally modify, amend, or rewrite this Privacy Policy at our discretion to reflect architectural upgrades, regulatory shifts, or the introduction of new SaaS capabilities (such as additional detectors or Autopilot functions).

However, we recognize our profound obligation to maintain transparency. We will not silently alter fundamental privacy protections. In the event of material changes to this Policy—specifically alterations that expand our data ingestion scope, modify data sharing practices, or dilute Data Principal rights—we will provide explicit, proactive notification to all active Customers. This notification will be disseminated via an unmissable banner within the authenticated ArthaOps web console and a direct email communication sent to the registered primary billing and technical contacts at least 15 days prior to the enforcement of the revised policy. The "Effective Date" at the apex of this document will always reflect the most recent cryptographic commit of this policy text. Continued use of the platform following the effective date constitutes binding acceptance of the amended terms.

22. Statutory Grievance Officer & Data Protection Officer Contact

In absolute compliance with the mandates of the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, ArthaOps has designated a statutory Grievance Officer to oversee our privacy operations, manage DSARs, and resolve disputes. If you have any inquiries, concerns, complaints, or if you wish to exercise your fundamental data rights, you are instructed to contact our Grievance Officer utilizing the following vectors:

  • Name/Designation: Data Protection & Grievance Officer
  • Corporate Entity: ArthaOps. Inc.
  • Registered Office: 61, Laxmi Nagar Zone, Dheku Road, Amalner, Dist. Jalgaon, Maharashtra 425401, India
  • Secure Email: grievance@arthaops.com (Primary Vector)
  • General Legal Inquiries: legal@arthaops.com
  • Security/Breach Reports: security@arthaops.com
  • Corporate Phone: +91 8999401914 (Business hours: Monday–Friday, 9:00 AM – 6:00 PM IST)

We commit to acknowledging all formal grievances within 24 hours of receipt and resolving them within 15 days, or such shorter period as mandated by prevailing law. If your grievance remains unresolved or is addressed unsatisfactorily, you maintain the statutory right to escalate your complaint to the Data Protection Board of India or the relevant judicial authorities within the jurisdiction of Mumbai/Jalgaon, Maharashtra.