Security
Tenant isolation, auditability, data-handling narratives for engineering and security reviewers.
Open Security →Security, Privacy, OpenTelemetry, Roadmap, Documentation, Company, and Support — clear entry points, not buried footer-only links.
What we state publicly: tenant-scoped data and access, TLS for data in transit, governed recovery with audit trails and human overrides, and a DPA available on request. What we do not currently hold: SOC 2, ISO 27001, HIPAA, or FedRAMP certification. Detailed security documentation is shared during security review under NDA.
Tenant isolation, auditability, data-handling narratives for engineering and security reviewers.
Open Security →Privacy overview plus full Privacy Policy for the marketing site.
Open Privacy →OTLP-aligned instrumentation and SDK paths — portable telemetry into Behaviour Runtime Intelligence.
OpenTelemetry / SDK →Directional product themes — not a binding commitment. Pair with Changelog for what shipped.
Open Roadmap →Technical docs, guides, and SDK reference.
Open Documentation →Who we are, how to reach us, and status for public surfaces.
Company →Illustrative composite scenarios — no invented metrics.
Case studies →Evaluation rubric linked from Product and Pricing paths.
Benchmarks →A high-level architecture and tenancy overview.
Architecture →Command Centre and behaviour intelligence on the Product page.
Product overview →Step-by-step instrumentation and pillar guides.
Tutorials →Live product walkthrough paths and media hub.
Videos →PUVI Labs Private Limited is incorporated in India (CIN: U62011TN2026PTC188238) and holds DPIIT Startup Recognition (DIPP245046). GST registration is deferred and not yet available. Use these identifiers for vendor onboarding, KYC, and procurement forms. Primary contact: Kalaiselvan Palani, Founder and CEO (kalaiselvan@puvilabs.com).
Patent pending in India for Behaviour Runtime Intelligence — the core innovation embodied in PUVINOISE™. A provisional patent application has been filed by PUVI Labs Private Limited. This reflects filing status only and does not imply that a patent has been granted. This is the primary innovation we intend to protect as intellectual property. Additional details are available under NDA.
A Data Processing Addendum (DPA) is available for enterprise customers as part of the MSA / contracting process. The marketing-site Privacy Policy does not replace a product DPA. Request via Contact — note “DPA” or “assurance pack”, and include your tenancy model and timeline.
Request DPA →Default PUVINOISE™ production infrastructure is hosted in India on Amazon Web Services (AWS). Customer-specific residency or regional constraints are documented in the customer agreement. The marketing website does not host PUVINOISE™ tenant data.
Open Security →We use carefully selected subprocessors to host and operate PUVINOISE™ and the marketing website. The public list below is indicative; the current schedule is provided with the DPA / assurance pack and may change with notice under the customer agreement. Indicative: Amazon Web Services (AWS); MongoDB Atlas.
Request schedule →We do not use customer tenant data — including operational telemetry, behaviour signals, prompts, or content — to train general-purpose foundation models, or to improve models for other customers. Processing required to operate, secure, and support the contracted PUVINOISE™ service is governed by the customer agreement and DPA.
Privacy overview →We use carefully selected subprocessors to host and operate PUVINOISE™ and the marketing website. The public list below is indicative; the current schedule is provided with the DPA / assurance pack and may change with notice under the customer agreement.
Enterprise reviewers can request architecture narrative, data-handling summary, DPA, and current subprocessor schedule under NDA / sales process.
No. PUVI Labs does not currently claim SOC 2, ISO 27001, HIPAA, or FedRAMP certification. Security documentation is available through security review.
A Data Processing Addendum (DPA) is available for enterprise customers as part of the MSA / contracting process. The marketing-site Privacy Policy does not replace a product DPA. Request via Contact — note “DPA” or “assurance pack”, and include your tenancy model and timeline.
Default PUVINOISE™ production infrastructure is hosted in India on Amazon Web Services (AWS). Customer-specific residency or regional constraints are documented in the customer agreement. The marketing website does not host PUVINOISE™ tenant data.
We do not use customer tenant data — including operational telemetry, behaviour signals, prompts, or content — to train general-purpose foundation models, or to improve models for other customers. Processing required to operate, secure, and support the contracted PUVINOISE™ service is governed by the customer agreement and DPA.
We use carefully selected subprocessors to host and operate PUVINOISE™ and the marketing website. The public list below is indicative; the current schedule is provided with the DPA / assurance pack and may change with notice under the customer agreement. Request the current subprocessor schedule via Contact (note “subprocessors” or “DPA”).
Patent pending in India for Behaviour Runtime Intelligence — the core innovation embodied in PUVINOISE™. A provisional patent application has been filed by PUVI Labs Private Limited. This reflects filing status only and does not imply that a patent has been granted. Behaviour Runtime Intelligence is the innovation we intend to protect as IP. We do not describe products as “patented” until a patent is granted.
PUVI Labs Private Limited is incorporated in India (CIN: U62011TN2026PTC188238) and holds DPIIT Startup Recognition (DIPP245046). GST registration is deferred and not yet available. Both identifiers also appear in the site footer. Founder contact: kalaiselvan@puvilabs.com.
/privacy is the overview. /legal/privacy is the full policy for the marketing website. Product app privacy is under customer agreements and the DPA.
Start free on app.puvilabs.com, use Contact for guided help, and Status for public incident communication.
Open Security and Privacy first, then prove Behaviour Runtime Intelligence on your agents.