Skip to main content
Security

Security built for multi-tenant agent operations

Clear authority surface for reviewers: tenant isolation, auditability, and data handling — without inflated certification claims.

Trust

Trust Center

Assurance pack entry and enterprise evaluation links.

Trust Center

Tenant isolation

PUVINoise is designed for multi-tenant fleet operations. Tenant boundaries govern how operational data and configuration are scoped. Website copy describes isolation at the architectural level; detailed assurance artifacts are provided through your sales and security review process—not invented on the marketing site.

Tenant-scoped operational data paths
Clear blast-radius boundaries for fleet onboarding
Architecture narratives for security assessment

Audit and access

Operator actions in the control plane should be traceable for accountability. Describe audit-oriented workflows without promising specific compliance regimes unless formally certified and approved for public claim.

Traceable operator actions in the control plane
Role-appropriate access patterns
Audit trails for accountability workflows

Data handling

Categories of data processed include operational telemetry, behaviour signals, and configuration metadata. We do not claim SOC 2 Type II, ISO 27001, HIPAA, or FedRAMP readiness unless legal and leadership have approved exact wording.

Operational telemetry from instrumented agents
Behaviour signals on governed surfaces
Configuration metadata for fleet operations

Data residency

Default PUVINoise production infrastructure is hosted in India on Amazon Web Services (AWS). Customer-specific residency or regional constraints are documented in the customer agreement. The marketing website does not host PUVINoise tenant data.

Default production hosting: India on AWS
Customer-specific residency: customer agreement
Marketing site does not host tenant operational data

AI training stance

We do not use customer tenant data — including operational telemetry, behaviour signals, prompts, or content — to train general-purpose foundation models, or to improve models for other customers. Processing required to operate, secure, and support the contracted PUVINoise service is governed by the customer agreement and DPA.

No training of general-purpose foundation models on customer tenant data
No cross-customer model improvement from your tenant data
Service operation / security processing under agreement + DPA

DPA and subprocessors

A Data Processing Addendum (DPA) is available for enterprise customers as part of the MSA / contracting process. The marketing-site Privacy Policy does not replace a product DPA. We use carefully selected subprocessors to host and operate PUVINoise and the marketing website. The public list below is indicative; the current schedule is provided with the DPA / assurance pack and may change with notice under the customer agreement.

Amazon Web Services (AWS) — Cloud infrastructure and hosting
MongoDB Atlas — Managed database platform
Request via Contact — note “DPA” or “assurance pack”, and include your tenancy model and timeline.

Responsible disclosure

Report security issues to kalaiselvan@puvilabs.com or via the contact form (note “security”). We aim to acknowledge good-faith reports promptly.

kalaiselvan@puvilabs.com — security and vulnerability reports
Contact form — security review / assurance pack / DPA requests

Start a security review conversation

We provide honest architecture narratives for engineering and security reviewers—without inflated certification claims.