Skip to Content
Trust

How we handle infrastructure, data, access, and incidents

Entrivis Tech operates client systems, custom code, and data flows that businesses depend on. This page is written for the security, IT, and procurement reviewers who vet us before a project starts. Where we have a formal program, we say so. Where we don't, we say so.

Last updated July 2026. Questions: hello@entrivistech.com

01 / Company information

Company information

A factual block for procurement records.

Legal entity
Entrivis Tech Private Limited
Country of registration
India
Year founded
2020
Founders' Odoo experience
14 years, since the Odoo v6 era, predating the company
Team size
30
Offices
Vadodara (HQ), Mehsana, Gandhinagar, all in Gujarat, India
Active client geographies
India, UAE, Saudi Arabia, USA, Canada, UK, Norway, Oman, Sudan, Philippines, South Africa, Zambia, and others. These are client and project locations: our only offices are the three in Gujarat above.
02 / Hosting & infrastructure

Hosting and infrastructure

We deliver on the hosting model a client's requirements call for, decided jointly at engagement start and recorded in the project's architecture record.

  • Self-hosted on cloud infrastructure (DigitalOcean, AWS, Hostinger). For clients who want full control of their environment, predictable cost, or specific data-residency requirements. We work across all three and recommend the fit based on scale, region, and compliance needs.
  • Odoo Online and Odoo.sh (managed by Odoo SA). For clients who prefer Odoo's official cloud. Hosting, backup, and infrastructure security are managed by Odoo SA under their published security documentation.
  • Client-managed AWS / Azure / GCP. When a client's architecture or compliance requires major cloud infrastructure, we provision and configure inside accounts the client owns.

For our own internal infrastructure (build systems and internal tooling) DigitalOcean is our default.

03 / Data handling

Data handling

During delivery, Entrivis personnel may access client production data, staging environments, source code, and integration credentials.

Our standing rules

  • Every engagement begins under a signed NDA, or under the NDA terms specified in the master services agreement.
  • We handle data on the terms agreed with each client, as documented in their contract or DPA.
  • To debug a production issue we may take a backup of the client's production database into a controlled environment. This is done with the client's awareness, and the backup is removed once the issue is resolved.
  • Integration credentials (API keys, database passwords) are held in a managed secrets approach per engagement and are never committed to public repositories.

Where a client has stricter requirements: HIPAA-context engagements, PCI-aware environments, GDPR data flows, we adapt our handling to meet what the client defines.

04 / Access controls

Access controls

For Entrivis-managed infrastructure

(our internal tooling, build systems, and development environments)

  • Access is restricted to team members by role and engagement.
  • Multi-factor authentication is required for sensitive systems.
  • Access is reviewed when a team member changes role or leaves.

For client-managed infrastructure

  • We follow the client's access policies in full.
  • We don't bypass or work around client security controls. If a task needs elevated access, we request it formally.

For coordination

We work in the client's preferred channel: Microsoft Teams, Slack, Google Chat / Meet, or WhatsApp, based on what they use internally. Sensitive material (credentials, exports, screenshots of production data) is shared only through the secure channel the client's policy requires.

05 / Backups & recovery

Backups and recovery

For our own systems

  • Code repositories: GitHub, with branch protection on production branches.
  • Internal documentation and operational records: backed up via the platforms we use.
  • Email and collaboration: enterprise plans with vendor-managed backup.

For client systems we operate

  • The backup approach is agreed at project start and documented per engagement.
  • For Odoo-managed environments (Odoo Online, Odoo.sh), we rely on Odoo SA's published backup procedures.
  • For self-hosted clients (DigitalOcean / AWS / Hostinger), we configure automated daily backups with retention appropriate to the client's needs.
  • Where the client runs their own backup infrastructure or policy, we follow it.

Recovery procedures are documented per engagement and tested when the client requests verification.

06 / Incident response

Incident response

Production incidents on client systems are handled in three phases:

  1. Detection and communication. When an incident is detected by us or reported by the client, an Entrivis engineer is on it promptly during business hours, with escalation paths defined per engagement for urgent off-hours issues. The client is notified in writing immediately, even when the fix will take longer than the initial response.
  2. Containment and resolution. We work the issue continuously until the system is stable. Depending on severity, that can mean overnight or weekend work.
  3. Post-incident review. For significant incidents we give the client a written review: what happened, why, what we did, and what we're changing to prevent a recurrence.

Specific response windows and severity definitions are set per engagement in the contract, and vary by engagement type. See Engagement Models.

07 / Compliance & certifications

Compliance and certifications

What we currently hold formally

None. Entrivis holds no third-party security certifications today. We don't advertise certifications we haven't completed.

Regulatory frameworks we operate under

  • GDPR (EU). GDPR is a regulation, not a certification. We follow GDPR principles for EU-resident data, sign Data Processing Addendums with clients who require them, and operate as a Data Processor on behalf of clients who are Data Controllers. DPAs are available on request.
  • India DPDP Act 2023. The Indian equivalent of GDPR. We follow DPDP principles for our India-based engagements and our own internal data handling.
  • HIPAA (US healthcare). For clients in US healthcare contexts we work to client-defined HIPAA requirements when the client provides the framework - Business Associate Agreement, technical safeguard requirements, breach-notification procedures. We don't run an independent HIPAA program; we operate within a client's HIPAA program when contracted to do so.
  • PCI-DSS. For payment-integration clients we minimize PCI scope by routing card data through PCI-compliant gateways (PhonePe, Cashfree, Paystack, Peach Payments, PayTabs, and others). We don't store cardholder data in any system we build, which keeps the client's PCI scope minimal.
08 / Available on request

Available on request

The following are available to enterprise clients and prospects under NDA:

  • Standard Master Services Agreement (MSA)
  • Data Processing Addendum (DPA), GDPR-aligned
  • Non-Disclosure Agreement (NDA), mutual or one-way
  • Standard security questionnaire response (CAIQ-aligned, partial)
  • Sample architecture decision record from a delivered project
  • References from current and past clients in similar industries or geographies

Email hello@entrivistech.com to request any of these.

09 / Reporting a security concern

Reporting a security concern

If you believe you've found a security issue with an Entrivis-built or Entrivis-operated system, email hello@entrivistech.com.

We respond to security reports within two business days. We don't run a public bug bounty program, but we recognize and credit researchers who report responsibly.

This page is a living record. For anything it doesn't answer, email hello@entrivistech.com - we reply within two business days.

Last updated July 2026.

Talk to us