ISO 27001 certified. This page documents how Upcore handles your code, which AI providers process it, and the contractual protections available before you sign anything.
Short answers first. Each question links to the full detail below.
Specifics for your procurement team. If you need this in a formal document, request our Data Processing Appendix.
Certificates are available to enterprise clients during procurement review. Request via the Security Review Pack email below.
Upcore does not provide legal or audit opinions. Your FAO generates the evidence and audit trail your compliance team needs to demonstrate adherence to these frameworks.
Your CISO needs to know which AI systems process your code. Here's what we can tell you before the discovery call, and what's disclosed in your contract.
Upcore's Fractional AI Officers use enterprise-tier LLM APIs for assisted code review — the same way your engineers use Copilot or Cursor, but under a formal governance framework with documented access controls and data processing agreements.
We do not use LLM providers that train on customer data. The specific provider(s) used in your engagement are named in your Statement of Work and Data Processing Agreement before you sign.
For clients who cannot send code to any external API, Upcore supports on-premise deployment of open-weight models on your infrastructure. This option is available in the Done-For-You engagement model.
All documents are provided during the discovery call stage, before any engagement starts. Nothing is hidden in procurement.
Upcore is an Indian private limited company. Enterprise procurement teams in the US, EU, and UK regularly ask jurisdiction-specific questions. Here are the factual answers.
Request our Security Review Pack or schedule a discovery call. We'll answer your CISO's questions before you commit to anything.
Security questions? Email gaurav@upcoretechnologies.com directly. We respond within 24 hours.