Datavrn
Security

Security & data handling

Last updated: 11 August 2026

Datavrn handles financial and operational reporting data. These are the control boundaries built into the product and the way we operate it.

Data boundary

Reporting data is stored in India. The database and application run in Mumbai (AWS ap-south-1), each organisation's data is isolated from every other's, and data is encrypted in transit and at rest. Connector credentials are encrypted separately. A customer-connected enterprise AI receives only the data requested through its scoped credential, under the customer's agreement with that provider. Datavrn-operated Help receives only a user-submitted question and allow-listed guidance; Datavrn does not attach reporting data. Prepare receives the question the user submits plus bounded, allow-listed reporting context and facts from one selected frozen statement version, only for a user-initiated request after Organization enablement and explicit Entity consent. These Datavrn-operated requests may be processed outside India by the providers named on our sub-processors page.

Access control

Access follows roles and the Entity scope assigned to the user or credential. Group access is available only when that principal may access every member Entity. Sign-in is passwordless — a one-time code to your email, or your Google account — with optional two-factor authentication. Connected assistants act only through the permissions granted to their credential.

Reporting integrity

Every action that changes data is recorded in an append-only audit log: who, when and what changed. Audit records cannot be edited or deleted. Reporting methodology and run context are preserved so a reported result can be understood and reproduced.

AI governance

AI is not required. No released reporting capability is reserved for AI users, and no AI provider is required to use any available Datavrn workflow. If your team prefers a conversational way of working, connect your enterprise AI through scoped access or use optional Datavrn AI. In every mode, deterministic engines compute each reported figure; AI never generates, estimates or adjusts one.

Portability and recovery

Datavrn preserves source provenance and the source fields permitted for each format; people-data formats intentionally exclude personal fields. Supported ingestions can be rolled back, but rollback removes that upload and does not always restore rows replaced by an earlier upload. Available mappings export and round-trip as standard files; report output includes linked Excel. Deleted Entities are hidden and recoverable, and the action is audited.

Security questions, or anything this page should answer and doesn't: hello@datavrn.com. See also the privacy policy, sub-processors, and the FAQ.