LAST UPDATED 2026 · FOR VENDOR DUE DILIGENCE
Security & compliance posture — written for your procurement team.
This page summarises our security architecture, compliance posture, contractual instruments, and answers to the common vendor due-diligence questions. If you’re evaluating us for a healthcare, fintech, or regulated-industry engagement and need a more detailed SIG-Lite questionnaire response, email us and we’ll send it within 48 hours.
Mutual NDA signed before discovery · BAA available for healthcare engagements · DPA on request for EU clients
- HIPAA-alignedarchitecture · BAA available with model providers
- 5+ yrscentral-bank-grade production (NRB)
- 0cross-tenant data incidents on DiNePa over 5+ years
- 4.8★on Capterra · 25 verified client reviews
DATA PROTECTION
How client data is encrypted, stored, and isolated.
- Encryption at rest — AES-256 across all client deployments. Database-level encryption on PostgreSQL and MySQL. File storage encrypted via AWS S3 server-side encryption or equivalent on other providers.
- Encryption in transit — TLS 1.2 minimum (TLS 1.3 where supported by the client stack). HSTS enforced. Certificate rotation automated via Let’s Encrypt or AWS Certificate Manager.
- Multi-tenant isolation — Schema-per-tenant database partitioning with middleware validation enforced before any business logic executes. Cross-tenant data exposure is architecturally impossible, not just policy-prevented. Zero cross-tenant incidents on DiNePa in 5+ years of EU enterprise production.
- Key management — AWS KMS, GCP KMS, or HashiCorp Vault depending on client cloud preference. Customer-managed keys (CMK) available for enterprise engagements.
- Backup & recovery — Automated daily backups with cross-region replication for production systems. Restore testing performed quarterly — backups we haven’t restored don’t count as backups. RPO and RTO defined per workload in the architecture phase.
- Data residency — US-region hosting for US healthcare and US enterprise clients. EU-region for European clients (GDPR-compliant). Sovereign / on-premise / isolated intranet for central-bank and government engagements (NRB runs on isolated intranet by regulatory requirement).
- Data retention & deletion — Per client SLA. Default 7-year retention for healthcare audit logs (HIPAA-aligned). Verifiable deletion on contract termination, with written attestation if required.
ACCESS CONTROL
Authentication, authorisation, and role isolation.
- Authentication — OAuth2 / JWT with refresh-token rotation. Biometric login (Face ID / Touch ID) on mobile apps where the use case requires it. Account lockout after repeated failures. Session timeout configurable per deployment.
- Multi-factor authentication (MFA) — Mandatory for super-admin and platform-owner roles across all our multi-tenant SaaS deployments. TOTP-based (Google Authenticator, Authy) standard; SMS fallback available; hardware key (YubiKey) supported on request.
- Role-based access control (RBAC) — Backend-enforced role partitioning at the routing layer (not the UI). Granular role definitions per project (e.g. 8 distinct roles on the Adult Home Care SaaS, 4 isolated portals on DiNePa). Cross-role escalation requires explicit privilege grant.
- SSO / SAML / OIDC — Okta, Azure AD, generic SAML, and OIDC integrations shipped to production. Enterprise customers typically ask for SSO inside the first sales conversation; we plan for it from discovery onwards.
- Device fingerprinting — Captured on every authentication event for fraud detection. Anomaly alerts on suspicious patterns (impossible-travel, unusual device, repeated failure spikes).
AUDIT & OBSERVABILITY
Immutable audit logs, structured logging, regulator-ready evidence.
- Immutable audit logs — Every privileged action logged with caregiver/user ID, timestamp, IP address, device fingerprint, action type, and affected resource. Logs are write-once, append-only, and tamper-evident. NRB’s litigation system runs on this pattern; the immutable log is the reason the system has maintained 100% audit readiness for 5+ years.
- Per-tenant log isolation — Audit logs are partitioned per tenant in multi-tenant SaaS. Tenant administrators can export their own audit log; cross-tenant visibility is restricted to platform super-admins.
- Structured application logging — JSON-formatted logs with correlation IDs across every service boundary. Sensitive fields (PHI, PCI, PII) automatically redacted at log emission — never written to disk in plaintext.
- Metrics & alerting — Prometheus + Grafana, CloudWatch, Datadog, or Sentry depending on client stack. Alerts tied to user-impact metrics (failed transactions, request error rates) rather than infrastructure metrics (CPU spikes). Every alert has a documented runbook.
- Incident response — On-call rotation with PagerDuty or Opsgenie integration. Blameless post-incident reviews on every Sev-1 / Sev-2 event. Written incident reports provided to the client within 5 business days of resolution.
COMPLIANCE FRAMEWORKS
Regulatory environments we have shipped to production.
We are architected to these frameworks — not certified as a corporate vendor. HIPAA and similar laws do not certify companies; they certify practices. We build the practices, and we sign the contractual instruments (BAA, DPA, MSA) that codify them.
HIPAA (US healthcare)
HIPAA Privacy & Security Rules — architecture, encryption, access control, audit logging, and BAA-signed third-party services. Currently shipping the AI Home Care SaaS to a US healthcare operator under NDA. Read deep-dive →
GDPR (EU)
EU data residency, lawful basis documentation, data-subject request handling, DPA available on request. Currently operating DiNePa SaaS for European enterprise procurement with EU-region hosting.
Central-bank-grade compliance
Maker-checker 4-Eye Principle, immutable audit logs, isolated intranet deployment, bilingual Unicode rendering, role-segregated access. Live for 5+ years at Nepal Rastra Bank. Read case study →
21st Century Cures Act EVV
Federally-mandated Electronic Visit Verification with biometric authentication, GPS verification, face-detection anti-fraud. State-by-state EVV adopter/aggregator integration ready. Engineered into the AI Home Care SaaS Caregiver mobile app.
CMS Medicaid/Medicare & EDI 837/835
Medicaid and Medicare claims integration, payer-specific billing rule engines, EDI 837 submission, EDI 835 remittance ingestion, claims-status tracking. Built into the data model from day one.
NIST & SOC 2–aligned controls
NIST Cybersecurity Framework alignment across identification, protection, detection, response, recovery. SOC 2-aligned controls implemented; formal SOC 2 Type 1 audit planned for 2026 in support of enterprise procurement requirements.
CONTRACTUAL INSTRUMENTS
The legal infrastructure we sign before discovery.
- Mutual NDA — Standard before any discovery call where confidential project material will be shared. We can use your NDA template or ours; both have been used across US, UK, EU, and APAC engagements.
- Master Services Agreement (MSA) + Statements of Work (SOW) — Standard contract structure for engagements. MSA governs the overall relationship; per-project SOWs scope specific deliverables, timelines, and pricing. Templates available on request.
- Business Associate Agreement (BAA) — Signed for any engagement where we touch Protected Health Information (PHI) during build, staging, or production. We can use your BAA template or our mutual template refined across healthcare engagements.
- Data Processing Agreement (DPA) — Available on request for European clients to satisfy GDPR Article 28 requirements. Includes Standard Contractual Clauses (SCCs) for international data transfers where required.
- Source code escrow — Available for enterprise engagements where you want assurance that the codebase remains accessible if the engagement ends abruptly. Third-party escrow providers (Iron Mountain, etc.) supported.
- Intellectual property assignment — All work product, source code, designs, and documentation transfer to the client on final payment. We retain no residual rights to project-specific IP. We may retain rights to internal tools or templates developed prior to or independently of the engagement.
INSURANCE & LIABILITY
Risk infrastructure for the engagement.
Professional Indemnity Insurance: [Coverage and provider to be filled in by the client team before publication.] Certificate of insurance available on request for procurement teams that require it as part of vendor onboarding.
Cyber Liability Insurance: [Coverage and provider to be filled in by the client team before publication.] Includes breach response and notification cover for engagements where we are designated as a Business Associate or Data Processor.
Limitation of liability: Standard mutual limitation negotiated per SOW, typically capped at fees paid for the SOW in the preceding 12 months. Higher caps available for engagements where the client’s risk profile requires them.
Indemnification: Mutual indemnification for IP infringement, gross negligence, and wilful misconduct. Negotiated per engagement based on the regulatory environment.
This page is a summary, not a legal instrument. The exact terms of any engagement are governed by the executed MSA, SOW, and any associated BAA / DPA. For a copy of our standard templates or a redlined version of yours, contact the engagement lead during discovery.
VENDOR DUE DILIGENCE
Answers to the questions your procurement team will ask.
Can you complete a SIG-Lite (Shared Assessments) questionnaire?
Yes. We maintain a pre-filled SIG-Lite response for healthcare and enterprise engagements. Email contact@emultitechsolution.com with your procurement contact and we’ll send the current version within 48 hours, then update it for your specific scope after the discovery call.
Can you complete a CAIQ (Cloud Security Alliance Consensus Assessment) questionnaire?
Yes for engagements where we’re deploying SaaS infrastructure on the client’s behalf. Pre-filled responses available for AWS and DigitalOcean deployment patterns; we’ll customise for your specific cloud environment during discovery.
What background checks do your engineers undergo?
Standard background checks for all in-house engineering staff before they touch client production code. Additional checks (drug screening, fingerprint, US Department of Justice clearance) available on request for healthcare and government engagements at the client’s cost. We never subcontract or use external freelancer pools for engagements that touch PHI or central-bank-grade data.
How do you handle security incidents involving our data?
Defined incident response runbook with severity classification (Sev-1 / Sev-2 / Sev-3), client notification SLAs (within 24 hours for Sev-1 involving client data, written report within 5 business days), and post-incident review with documented remediation. For healthcare engagements covered by a BAA, breach notification follows the timelines and content requirements of 45 CFR 164.410.
Do you carry insurance and can you provide a certificate?
Yes — Professional Indemnity and Cyber Liability insurance both in place. Certificate of insurance available on request for procurement onboarding. Exact coverage limits depend on the engagement scope and are negotiated per SOW.
Where is your engineering team located?
In-house engineering team is based in Kathmandu, Nepal (UTC+5:45). Local presence in Melbourne, Australia (UTC+10/+11) for Asia-Pacific client coverage. We do not subcontract. The engineer you meet in discovery is the engineer who ships your code.
What happens to our data when the engagement ends?
Per your written instruction in the SOW termination clause. Default options: (a) full export of all client data in a documented format and verifiable deletion from our systems within 30 days, with written attestation; (b) retention for the agreed legal-hold period (typically 7 years for healthcare); or (c) handover to a successor vendor under a transition SOW.
Are you SOC 2 certified?
We are SOC 2–aligned in our controls today and have planned a SOC 2 Type 1 audit for 2026 in support of US enterprise procurement requirements. If your procurement process requires an active SOC 2 report at vendor onboarding, please flag this on the discovery call so we can discuss the timeline. For non-SOC-2 engagements, we provide a written controls summary that procurement teams typically accept as part of vendor due diligence.

Need the full security questionnaire?
- BAA
- Available for healthcare
engagements that touch PHI - DPA
- Available for EU clients
with GDPR Article 28 compliance - SOC 2
- Type 1 audit planned
for 2026 - NDA
- Signed before
any discovery call
If your procurement team needs SIG-Lite, CAIQ, or a custom security questionnaire response, email us and we’ll send the current pre-filled version within 48 hours.
Procurement-team contact contact@emultitechsolution.com — Roshan Subedi, Founder & MD · vendor due-diligence reviewed directly