VENDOR DILIGENCE

We are a material outsourcing
arrangement. We're built for it.

For a regulated lender, engaging ShieldX is outsourcing of information technology services under the RBI Master Direction of April 2023. That obligation sits with the institution — but it is only satisfiable if the provider is willing to hold the other end of it.

This page states the positions we hold contractually, so your vendor-risk team can assess them before a conversation rather than three months into one.

01

Right to audit

The institution, its internal and external auditors, and the Reserve Bank of India may audit ShieldX's books, records, and controls insofar as they relate to the services provided. This right is contractual, survives for the record-retention period, and is not contingent on notice periods that would frustrate a regulatory inspection.

02

Regulatory access and inspection

RBI and any other statutory authority with jurisdiction over the institution may access ShieldX's records, systems, and premises relating to the engagement, and may require information directly from us. We do not treat supervisory access as a confidentiality exception to be negotiated.

03

Data ownership and residency

Client and borrower data belongs to the institution at all times. It is hosted in India — AWS Mumbai (ap-south-1) — or within the institution's own boundary for on-premise deployments. ShieldX asserts no ownership, no licence for cross-client use, and no right to retain data beyond the term.

04

Exit management and data return

On termination, the institution receives its decision logs, outcome records, and derived features in a documented, machine-readable format — not a proprietary export that creates lock-in. Residual data is destroyed on a defined schedule with written confirmation. Transition assistance is available during the exit window.

05

Sub-contracting and fourth parties

Sub-processors are disclosed before engagement and listed publicly. Material changes are notified in advance, and the institution may object. No sub-processor receives access broader than the function it performs.

06

Business continuity

Backups and point-in-time recovery are in place, with restore drills performed. Recovery objectives are agreed per engagement against the institution's own BCP requirements rather than asserted as a single universal figure, and are documented in the MSA.

07

Incident reporting

Security incidents are reported to the institution without undue delay and within the timelines its own obligations require — including the six-hour reporting window under the CERT-In Directions, 2022, where applicable. ICT log retention is configured to the institution's requirement, including the 180-day CERT-In window, and logs are held in India.

08

Concentration risk

ShieldX is designed to be removable. The decision layer runs above execution, so an institution keeps its CPaaS contracts, dialer, and agency relationships throughout — see how we deploy. The system of record is exportable. Neither dependency is engineered to raise the cost of leaving.

Operational specifics — recovery objectives, notice periods, audit frequency, service levels — are agreed per engagement in the Master Services Agreement, against the institution's own policy. We publish positions here, not numbers we would have to hold identically across every institution regardless of its requirements.

Diligence pack

VAPT report, security documentation, DPA, and our standard MSA clauses covering the positions above are available to institutions under NDA. Request them through a walkthrough, or write to legal@queloai.online.