Security
Built for enterprise relocation. Documented like one.
ikan handles relocation data for procurement, HR, and mobility teams who answer to auditors. Our security posture is built around least-privilege access, encrypted data at rest and in transit, defined retention windows, and a vendor list you can actually inspect.
Last updated: 22 July 2026
Data handling
- Encryption at rest — managed database and object-storage providers encrypt persisted data under their platform controls; sensitive documents use private storage or an authenticated database fallback.
- Encryption in transit — public traffic uses HTTPS. Production responses include HSTS, anti-framing, referrer, and permissions-policy headers.
- Retention — standard voice calls are not intentionally recorded; persisted transcripts are kept for up to 30 days. Optional contracted recordings are disclosed before use and kept for no more than 90 days. Booking and audit records follow the legal and contractual periods in our privacy policy.
- Deletion on request — verified requests sent to privacy@ikan-residences.com are processed subject to legal, tax, fraud-prevention, and contractual retention requirements.
- AI data use — ikan does not use customer prompts or transcripts to train its own models. External model providers process requests under the applicable API or enterprise terms and account-level data controls.
Vendors and sub-processors
Core infrastructure is always used. Feature-dependent vendors receive data only when the corresponding integration is configured and used. The links point to each vendor’s own privacy, trust, or sub-processor information; processing locations follow the contracted account and vendor terms rather than an assumed region.
| Vendor | Role | Use | Policy |
|---|---|---|---|
| Vercel | Application hosting, edge delivery, and file storage | Core | View policy |
| Supabase | Managed Postgres database | Core | View policy |
| Resend | Transactional email and email webhooks | Feature-dependent | View policy |
| Render | Aira voice-worker compute | Feature-dependent | View policy |
| LiveKit | Real-time voice transport and voice inference gateway | Feature-dependent | View policy |
| Cartesia | Text-to-speech through LiveKit Inference | Feature-dependent | View policy |
| Groq | Aira language, speech-to-text, vision, and fallback speech synthesis | Feature-dependent | View policy |
| Gemini language and vision fallback | Feature-dependent | View policy | |
| Anthropic | Claude language-model fallback | Feature-dependent | View policy |
| OpenAI | Language-model fallback | Feature-dependent | View policy |
| Upstash | Distributed abuse and rate-limit counters | Feature-dependent | View policy |
| Mapbox | Explicit office-address geocoding with permanent-storage rights | Feature-dependent | View policy |
| Twilio | SMS delivery and messaging webhooks | Feature-dependent | View policy |
| Meta | WhatsApp Business messaging | Feature-dependent | View policy |
| Telegram | Internal operations alerts | Feature-dependent | View policy |
| Razorpay | India payment processing | Feature-dependent | View policy |
| Stripe | International payment processing | Feature-dependent | View policy |
| Sentry | Error monitoring | Feature-dependent | View policy |
| PostHog | Consent-gated product analytics | Feature-dependent | View policy |
Compliance posture
- Parent-company certifications — our parent, ikan Talent Mobility Pvt. Ltd., holds the EuRA Global Quality Seal+ and ISO 9001 / 27001 / 14001 certifications. Every certification, membership and award is listed with its source at /trust.
- Platform certifications — ikan Residences does not currently claim its own SOC 2 Type II or platform-level ISO 27001 certification.
- Independent testing — a platform VAPT is not represented as complete until an independent report is available. Customer security reviews can use this page and the current technical questionnaire.
- GDPR — EEA/UK processing obligations, transfer mechanisms, and audit terms are set in the executed customer agreement and DPA; the published DPA is the standard form.
- DPDP (India) — ikan operates as a Data Fiduciary or processor according to the relationship and follows applicable obligations under the Digital Personal Data Protection Act, 2023.
- DPA — a Data Processing Addendum is available for every customer at /dpa or on request.
Access control
- Role-based access — five distinct roles: Relocation Manager (RMC), Operations, Admin, Supplier, Traveler. Each sees only the data their role requires.
- Audit trail — consequential booking, pricing, payment, access, and document actions record their actor and timestamp.
- Controlled recovery — supported actions expose explicit undo or state-safe reversal; financial records use dedicated refund and adjustment workflows.
- SSO & SCIM — Google Workspace / Microsoft Entra ID single sign-on and SCIM provisioning are on the enterprise roadmap; talk to us about timing for your rollout.
Incident response
- Configured observability providers capture application failures; the status page also exposes current service checks.
- Customer-facing impact is reflected on ikan-residences.com/status shortly after detection.
- Affected customers are notified in accordance with applicable law and contractual incident terms.
- Material incidents receive a written follow-up with root cause and remediation when the investigation is complete.
Reporting a vulnerability
Email security@ikan-residences.com with as much detail as you can share. We aim to acknowledge complete reports within one business day, but investigation and remediation time depends on severity and reproducibility. Our security contact and policy are published at /.well-known/security.txt per RFC 9116. Please allow reasonable remediation time before public disclosure; we coordinate disclosure timing with the reporter.
Contact
Security questions: security@ikan-residences.com. Privacy and data-subject requests: privacy@ikan-residences.com.