Security you can verify.
The certifications, the standards the architecture is built to, the compliance clauses it evidences, and the way to tell us when something is wrong. Every claim on this page is one you can ask us to prove.
Certified, aligned, and checkable.
the posture
Trust in an access platform has two halves. One is external: an auditor has examined how InstaSafe runs and issued a certificate or a report, and the standard the product is built to is a public one. The other is architectural: the design itself removes whole classes of risk, and you can verify that on your own network with a packet capture rather than a promise. This page carries both, and the certificates, reports and architecture documents are available to customers and evaluators on request.
- ISO 27001:2013 certified.The information-security management system that runs InstaSafe is certified. The certificate is available on request.
- SOC 2 compliant.Controls examined against the AICPA trust services criteria. The report is shared under NDA.
- Built to NIST SP 800-207.The Zero Trust architecture standard describes a policy decision point, a policy enforcement point and a continuous evaluation loop. InstaSafe implements that model, with CSA Software-Defined Perimeter alignment alongside it.
- Privacy by architecture.Split plane: the control plane decides, the data plane carries, and application traffic never transits InstaSafe's machines. That is what makes the residency and privacy claims properties of the design.
- ✓ISO 27001:2013certified · certificate on request
- ✓SOC 2compliant · report under NDA
- ✓NIST SP 800-207architecture built to the standard
- ✓CSA SDPsoftware-defined perimeter aligned
- ✓HIPAA · GDPRcontrols in place · GDPR ready
- ✕Data plane via InstaSafenever: split-plane by design
marks _
ISO 27001:2013Certified. The certificate is available on request.
SOC 2Compliant. Report under NDA.NIST SP 800-207Built to the Zero Trust architecture standard.
HIPAAControls for protected health information.
GDPRReady: data minimisation by architecture.
DSCIData Security Council of India recognition.
Compliance coverage, clause by clause.
The frameworks Indian and global buyers procure against, and what the platform evidences for each. The compliance solution page carries the mappings in full.
- DPDP Act (India)Access minimisation and purpose-scoped access as policy objects; application data stays on your own paths.
- RBI / SEBI / IRDAIAccess control, MFA, vendor-access oversight and audit trails; third-party session recording answers the outsourcing-oversight clauses directly.
- PCI DSSMFA, least privilege and access logging for the systems adjacent to cardholder data.
- HIPAA / GDPRAccess minimisation, plus an accounting of who reached what and when.
- ISO 27001 / SOXAccess-control and logging clauses evidenced from the console rather than reconstructed for the auditor.
- NIST SP 800-207The architecture itself, with CSA SDP alignment alongside it.
- CERT-InLog retention and incident-reporting expectations met from the same event store the platform already keeps.
Framework mappings are engineering statements, not legal advice. Your auditor decides what satisfies a clause; the platform's job is to make the evidence exportable.
What the architecture removes.
Six design decisions, each one closing a class of risk rather than detecting it.
- SPLIT PLANEControl plane and data plane are separate systems. Trust is established in one; data moves in the other, device to application, never through InstaSafe.More
- DROP-ALL GATEWAYThe gateway drops every packet it has not been told to expect. Nothing on the internet can learn the address exists, let alone fingerprint it.More
- SINGLE-PACKET AUTHORISATIONOne signed message tells the gateway to expect one authenticated device. The door opens for that device, for that session, and stays dark to everyone else.
- PER-APPLICATION SESSIONSAccess is to the one application requested, never to the segment it lives on. Lateral movement has no path to travel.More
- DEVICE TRUSTA device certificate binds the account to hardware you approved; posture checks decide whether that hardware is fit to open a session, and keep deciding during it.More
- THE RECORDEvery decision (grant, refusal, step-up, revocation) writes an event with the person, the device and the context. It exports to your SIEM in the formats you already ingest.More
Deployed where your data has to live.
On-premise and air-gapped
Controller and gateways inside your own boundary, including estates with no route to the internet. The whole platform, not a connector.
Cloud and hybrid
The same policy engine wherever workloads land, in a data centre or a private or public cloud, so nothing forks when something moves.
Sovereign procurement
Listed on the Government e-Marketplace for ministries and PSUs that procure through GeM, with the on-premise design as the default.
Documents on request
Certificates, the SOC 2 report, architecture documents and the pen-test summary are available to customers and evaluators under NDA.
responsible disclosure _
Found something? Tell us first.
Keeping InstaSafe secure is a community effort, and independent researchers are part of it. If you believe you have found a security issue in the InstaSafe website, the products or the agents, report it to us privately and we will work it with you. Reports that affect many users are recognised through our vulnerability rewards program, run on SafeHats.
- Report privately, through the portal or the address below, before any public disclosure.
- Do not access, alter or exfiltrate data that is not yours, and stop the moment a proof of concept exists.
- Scope, eligibility and rewards are on the SafeHats program page; that page is the policy.

security at InstaSafe, answered.
Tap a question. If yours is not here, a specialist can answer it.
Talk to a specialist//Ready when you are//
Ask for the certificates. Then ask for the packet capture.
A 30-minute walkthrough with the architecture on the table, plus the documents your security review needs, under NDA.
Regulated, air-gapped, or on-premise? See deployment options