Built on trust.
Audited for compliance.

For 15+ years, Atidiv has handled finance & accounting, customer experience, and operations for 70+ clients across 20+ industries. Independent auditors and recognised standards bodies regularly verify the controls behind that work.

WHY THIS MATTERS

When you outsource finance, customer data, or platform operations to Atidiv, you’re trusting us with information that matters to your business and to the people you serve. The certifications, audits, and operational controls below exist so that trust is earned — not assumed.

Certifications & Independent Audits

Each of these is verified by an external auditor or standards body. Full reports available on request under NDA.

Information Security

ISO 27001

The international standard for Information Security Management Systems. Covers governance, risk management, access control, and continuous improvement of how we protect data — yours and ours.


Standard

ISO/IEC 27001

Standard

Active

Request certificate
Financial Reporting

SOC 1 Type 1 (SSAE 18)

Independent service auditor's opinion on the design of our finance & accounting controls — the controls our user entities rely on for their own financial reporting.


Auditor

Accorp Partners CPA LLC

Report Date

Sep 12, 2025

Request full report under NDA
Data Privacy

CCPA / CPRA Compliance Review

Independent review of our privacy program against California Consumer Privacy Act and California Privacy Rights Act requirements — covering consumer rights, notices, vendor controls, and breach response.


Reviewed by

Riskpro India

Report Date

Dec 2, 2025

View privacy policy
Penetration Testing

VAPT — Annual

External Vulnerability Assessment and Penetration Testing performed annually — and whenever there's a material change to our environment — by an independent security firm.


Cadence

Annual + on change

Report Date

Aug 29, 2025

Request executive summary

Security Controls

Each of these is verified by an external auditor or standards body. Full reports available on request under NDA.

Trusted cloud partners

Data hosting and processing on Google Cloud and AWS — certified, geo-redundant, encrypted by default.

Endpoint protection

Sophos firewall and antivirus across all workstations and laptops, with real-time threat detection.

Access Control

Role-Based Access Control (RBAC), multi-factor authentication, and least-privilege defaults.

Secure remote work

Sophos VPN with encrypted tunnels for all remote access. Removable media restricted at the endpoint.

Patch management

Rigorous patching cadence for operating systems, applications, and firmware — with documented review.

Backup & recovery

Scheduled differential and full backups protected at the same security level as live data.

Encryption

Encryption in transit and at rest. Client work performed on client networks via RDP / VPN.

Monthly security review

Monthly security audits and risk register reviews with the CEO and senior management.

Privacy & governance

The people and processes that make compliance an everyday discipline, not a once-a-year checkbox.

01

Data Protection Officer appointed

A named DPO oversees Atidiv's privacy program, monitors regulatory change, and is the single point of contact for privacy queries from clients, employees, and regulators.

02

Records of Processing maintained

A documented Data Inventory and Records of Processing Activities (ROPA) tracks what personal data we hold, why we hold it, where it's stored, and who it's shared with — kept current as our business evolves.

03

Documented breach response

A formal incident response plan covers detection, containment, root-cause analysis, notification, and remediation — tested through tabletop exercises.

04

Privacy training, every year

All employees handling personal information complete information security and privacy awareness training at induction, with annual refreshers and acknowledgement.

05

Vendor due diligence

Every third-party processor goes through a privacy and security risk assessment before onboarding, with periodic reassessment thereafter. Data Processing Addendums in place where required.

06

Data subject rights honoured

Documented procedures to handle access, deletion, correction, portability, and opt-out requests within the timelines required by applicable law.

DATA PROTECTION OFFICER

Anand Krishnan Ramani

Senior Manager — IT & Data Protection Officer, Atidiv (India) Pvt Ltd

Privacy Queries

anand.krishnan@atidiv.com

General Contact

contact@atidiv.com

Phone

+91 020 67486141