Security & Trust Center

Security Questions Your
CISO Will Ask. Answered.

ISO 27001 certified. This page documents how Upcore handles your code, which AI providers process it, and the contractual protections available before you sign anything.

ISO 27001 Certified CMMI Level 3 ISO 9001 Certified
Quick reference

Six Questions From Every CISO

Short answers first. Each question links to the full detail below.

Yes
Is Upcore ISO 27001 certified?
Yes. Upcore Technologies Pvt. Ltd. holds ISO 27001:2022 certification at the organisational level, covering information security management across all delivery functions.
Yes
Does my code leave my environment?
Only with your explicit permission. Code review under the FAO engagement happens in your repository environment (via OAuth-scoped access). No code is copied to Upcore servers. Snippets shared for analysis are not retained after the session.
Disclosed on request
Which LLM providers process my data?
Disclosed in your Statement of Work and DPA before engagement starts. We work with enterprise-tier API agreements (data processing agreements, no training on customer data). The specific provider(s) are named in your contract.
Yes
Can Upcore sign a BAA for HIPAA engagements?
Yes. A Business Associate Agreement is available for engagements where PHI is in scope. Contact us during the discovery call to include the BAA in your contract package.
On request
Is Upcore SOC 2 Type II audited?
SOC 2 Type II audit documentation is available to enterprise clients under NDA during procurement review. Contact gaurav@upcoretechnologies.com to request our Security Review Pack.
Yes
Can we use our own LLM (on-premise or private cloud)?
Yes. Upcore supports on-premise and private cloud LLM deployments for clients with air-gap requirements. This is scoped in the Done-For-You engagement model and adds approximately 2 weeks to the initial deployment timeline.
Data handling

How Your Code and Data Are Handled

Specifics for your procurement team. If you need this in a formal document, request our Data Processing Appendix.

🔒
Repository Access
Upcore accesses your repository via OAuth integration with minimum required permissions: read access to the branches specified in your SOW. We do not request write access unless you opt into automated PR commenting in the Done-For-You model.
Access is revoked immediately on engagement end or at your request at any time.
Code Retention
No code is copied to Upcore's systems. When code snippets are shared for AI-assisted review during a session, they are processed in-context and not persisted to any Upcore storage beyond the active session window.
Audit log entries (which files were reviewed, risk classifications assigned) are retained for the duration of the engagement and handed to you on exit.
🌍
Data Residency
By default, analysis occurs via the LLM provider's regional endpoint nearest your primary data location. For EU clients, EU-region endpoints are used by default. For clients with US-only data residency requirements, US-region endpoints are configured at onboarding.
Data residency specifics are documented in your DPA.
👥
Access Controls
Access to your environment is restricted to the named FAO assigned to your engagement. No other Upcore employee or subcontractor has access unless you explicitly approve it. Access credentials are stored in an ISO 27001-compliant credential management system.
📊
Subprocessors
The complete list of Upcore's subprocessors — including the LLM API providers, credential management platform, and communication tools — is available in your DPA. You will be notified of any new subprocessors added during your engagement, with 30 days' notice and the right to object.
Security Incident Notification
In the event of a security incident affecting your data, Upcore will notify you within 72 hours of becoming aware, consistent with ISO 27001 incident management requirements and GDPR Article 33 obligations.
Certifications

Upcore's Active Certifications

Certificates are available to enterprise clients during procurement review. Request via the Security Review Pack email below.

🛡
ISO 27001:2022
Information Security Management System. Covers all Upcore delivery functions including client data handling, access controls, and incident response. Organisation-level certification.
Certified — Active
🏗
CMMI Level 3
Capability Maturity Model Integration. Level 3 (Defined) — Upcore's delivery processes are documented, standardised, and consistently applied across all engagements.
Certified — Active
ISO 9001:2015
Quality Management System. Documents Upcore's quality planning, monitoring, and continual improvement processes across client delivery.
Certified — Active
Compliance support

Regulatory Frameworks Your FAO Governs

Upcore does not provide legal or audit opinions. Your FAO generates the evidence and audit trail your compliance team needs to demonstrate adherence to these frameworks.

EU AI Act
EU AI Act — High-Risk Classification
Your FAO maps your AI systems to the EU AI Act's high-risk categories, generates the required conformity documentation, and maintains an AI system register aligned to Annex III requirements. Effective 2 August 2026.
HIPAA
HIPAA — AI Code in PHI Environments
Governance of AI-generated code that touches PHI-adjacent systems. FAO reviews ensure AI code does not introduce access control or encryption gaps under HIPAA §164.312. BAA available.
SOX
SOX — Financial System AI Audit Trails
For public companies, FAO governance generates the AI code audit trail your external auditors need under PCAOB AS 2201. Attestation gaps closed proactively before audit cycles.
GDPR
GDPR — AI Processing & Data Flows
AI code that processes personal data is reviewed for DPIA triggers, data minimisation, and purpose limitation. Upcore processes EU client data under Standard Contractual Clauses (SCCs).
ISO 42001
ISO 42001 — AI Management System
The emerging international standard for AI management systems. Your FAO aligns your governance posture to ISO 42001 as part of the L1 Align layer — useful for clients preparing for formal AI management certification.
OWASP LLM
OWASP LLM Top 10 — Code-Level Controls
Every AI code review checks against the OWASP LLM Top 10 (prompt injection, insecure output handling, supply chain vulnerabilities). Controls are documented per-PR in your governance log.
AI provider disclosure

How AI Is Used in Upcore's Delivery

Your CISO needs to know which AI systems process your code. Here's what we can tell you before the discovery call, and what's disclosed in your contract.

Upcore's Fractional AI Officers use enterprise-tier LLM APIs for assisted code review — the same way your engineers use Copilot or Cursor, but under a formal governance framework with documented access controls and data processing agreements.

We do not use LLM providers that train on customer data. The specific provider(s) used in your engagement are named in your Statement of Work and Data Processing Agreement before you sign.

For clients who cannot send code to any external API, Upcore supports on-premise deployment of open-weight models on your infrastructure. This option is available in the Done-For-You engagement model.

AI Provider Controls Summary
Provider training on customer data No
Data Processing Agreement available Yes
Provider named in SOW Yes — before signing
On-premise LLM option Available
Code sent to Upcore servers No
EU-region API endpoints (EU clients) Default
Prompt audit logging Included in L1 Align layer
Contracts & protections

What's Available Before You Sign

All documents are provided during the discovery call stage, before any engagement starts. Nothing is hidden in procurement.

Master Services Agreement (MSA)
Standard MSA covering liability, indemnification, IP ownership, confidentiality, and termination rights. Your legal team can redline it; we use a reasonable review process.
Standard contract
Data Processing Agreement (DPA)
Covers all data flows between your environment and Upcore's systems, including subprocessor list, retention periods, deletion process, and breach notification obligations. Required for all engagements.
Included with MSA
Business Associate Agreement (BAA)
Required for any engagement where PHI may be in scope. Covers Upcore's obligations as a Business Associate under HIPAA and includes the safeguards your compliance team requires.
On request — healthcare clients
Non-Disclosure Agreement (NDA)
Mutual NDA covering both directions — your code and business information, and Upcore's proprietary methodologies. Executed before any discovery call where sensitive details are shared.
Signed before discovery call
Standard Contractual Clauses (SCCs)
For EU-based clients, Upcore processes personal data under the EU's approved SCCs, addressing the cross-border data transfer question for India-based processing entities.
EU clients — standard
Security Review Pack
Full pack including ISO 27001 certificate, CMMI attestation, subprocessor list, and security questionnaire responses. Available to enterprise procurement teams under NDA.
On request — email us
Entity & jurisdiction

Upcore Technologies Pvt. Ltd. — Procurement Questions Answered

Upcore is an Indian private limited company. Enterprise procurement teams in the US, EU, and UK regularly ask jurisdiction-specific questions. Here are the factual answers.

Addressed
GDPR: India is not an EU adequacy country. How does data transfer work?
EU personal data transferred to Upcore is governed by Standard Contractual Clauses (SCCs) — the EU Commission's approved mechanism for transfers to non-adequacy countries. Our DPA (included with every MSA) specifies the applicable SCC module, subprocessor list, and breach notification timeline. No EU personal data is processed outside the scope of the executed SCC.
Addressed
HIPAA: Can an Indian Pvt. Ltd. sign a Business Associate Agreement?
Yes. HIPAA's Business Associate requirements apply based on what data is handled, not where the vendor is incorporated. If PHI may be in scope, Upcore executes a BAA that meets the 45 CFR §164.308–314 safeguard requirements. The BAA is reviewed by your compliance team before any engagement starts.
Addressed
SOX: How does an Indian vendor fit into a SOX-scoped audit chain?
SOX Section 404 requires controls over financial reporting to be documented and tested — including third-party vendors with access to financial data or systems. Upcore's FAO engagement delivers audit-ready AI governance documentation (control inventories, change logs, risk assessments) that your internal audit team can present to your external auditor. Upcore is treated as a third-party vendor under your vendor management controls.
Addressed
EU AI Act: Does the Act apply to an Indian provider serving EU clients?
Yes — under the EU AI Act's extraterritorial scope (Article 2), providers placing AI systems on the EU market or whose outputs are used in the EU are covered regardless of where they are established. Upcore's FAO engagement includes EU AI Act compliance mapping: risk classification, transparency obligations, and conformity assessment documentation for AI systems within the Act's scope.

Ready for Your Security Review?

Request our Security Review Pack or schedule a discovery call. We'll answer your CISO's questions before you commit to anything.

Request Security Review Pack Book a Discovery Call →

Security questions? Email gaurav@upcoretechnologies.com directly. We respond within 24 hours.