KavachIQ is built for security-aware and regulated teams. Tenant-scoped access, encryption, immutability, auditability, and compliance-mapped controls from day one.
Jump to: Data handling · Procurement FAQ
A small set of principles drives how the product handles customer data and recovery actions.
KavachIQ uses Microsoft Entra OAuth admin consent. Your Global Admin approves scoped access. No passwords are stored, only tenant-scoped API tokens.
Every backup, snapshot, restore job, and audit record is scoped to a tenant. Cross-tenant access is not a path in the product.
Identity and workload state are captured and restored together. Recovery actions are logged, attributable, and reversible per object.
Encryption, per-tenant keys, immutable storage, SSO, MFA, audit trail, and compliance mapping are built in from the first deployment.
Encryption, immutability, access, and logging are enforced from the first tenant onboarded. Not a later upgrade.
AES-256-GCM for all stored data. Keys are rotated and managed per tenant.
Each tenant has its own data encryption key, wrapped by a master key. A tenant key compromise cannot expose another tenant.
Snapshots under a WORM-enabled SLA are locked for the retention window. Deletion is blocked at the storage and API layers until the lock expires.
Sign in via Microsoft Entra OIDC. MFA enforcement is inherited from the tenant.
Every privileged action is logged with timestamp, user, tenant, and result. Audit records are exportable for security and compliance review.
Platform admin, MSP admin, tenant admin, and viewer roles. Least-privilege by default. Viewer accounts cannot take destructive actions.
Every API call and UI action is scoped to an explicit tenant. Cross-tenant operations require platform-admin privileges and produce audit records.
Checksum validation, policy-active checks, and sign-in tests confirm a recovery actually restored the expected state.
Six stages that describe the practical lifecycle of tenant data and recovery workflows in KavachIQ. Each stage states what is accessed, what is stored or computed, and how it is protected or controlled.
Tenant-scoped access through Microsoft Graph.
Identity and workload state are snapshotted on a schedule.
Snapshots are protected by encryption and immutability.
Restore and rollback actions run through guided, controlled workflows.
Recovery ends with evidence, not just a completed job.
Every privileged action is logged and reviewable.
For environment-specific retention, residency, or data-processing questions, route requests through [email protected].
KavachIQ controls are mapped to common compliance frameworks. Mapping is an internal evidence exercise and not a substitute for a formal audit report. For audit artifacts, contact the security and procurement path below.
16 controls mapped: access control, encryption, audit, change management, incident response, and monitoring.
8 articles mapped: right to erasure, data portability export, breach notification, and processor obligations.
14 safeguards mapped: administrative, physical, and technical safeguards for ePHI in Microsoft 365.
Digital Operational Resilience Act controls for financial-sector operational recovery mapped against KavachIQ capabilities.
Mapping terminology: "mapped" means KavachIQ controls are cross-referenced to each framework's control IDs with supporting evidence in internal documentation. If your review process requires a SOC 2 report, a DPA, or other formal artifacts, route your request through the security and procurement path.
The deployment model is built for Microsoft-native operations and enterprise review.
Primary deployment is on Microsoft Azure Container Apps with Azure Storage and Azure Database for PostgreSQL.
Control plane (API, scheduler, UI) is separate from the data plane (snapshot storage). Snapshots live in tenant-scoped, per-tenant-encrypted storage.
Built on Microsoft Graph for Entra, Exchange, OneDrive, SharePoint, and Teams. Permissions use least-privilege scopes per workload.
Documented API for tenant onboarding, workload enablement, and restore operations. OAuth admin consent handles permission grants.
Short, specific answers to the questions that come up during vendor evaluation. For formal artifacts and questionnaire responses, use the security contact path below.
If a question specific to your environment is not covered here, reach out at [email protected].
Security reviewers, procurement teams, and risk owners can route requests through the paths below.
Vendor-risk questionnaires, SOC 2 requests, DPA, and review artifacts.
[email protected]Security architecture, compliance mapping, tenant security, and API reference.
Review documentationRequest a walkthrough of KavachIQ security controls, tenant isolation, and compliance-mapped evidence. Or send a procurement questionnaire directly to the security path.