01 · BYOC Your AWS, GCP, or Azure account — always.
Workloads run on your cloud. We never host them.
ZopDay is a control plane over the cloud account you already own. If you leave, the workloads stay where they are — standard Helm releases on your clusters.
02 · CLOUD-NATIVE SECRETS Sensitive env vars stay in your cloud’s secret store.
AWS Secrets Manager, Google Secret Manager, Azure Key Vault.
Sensitive values are masked in the UI and land in your cloud-native secret manager, never ours. ZopDay reads from them at deploy time.
03 · NO DATA PATH Control plane, not a proxy.
Your application traffic never hits our infra.
Helm rollouts, Live K8s view, audit events — everything ZopDay does is orchestration on your cluster. Application requests stay between your users and your services.
04 · ISO 27001 · SOC 2 ISO 27001:2022 · SOC 2 Type II.
Annually re-audited.
Independent third-party audit, end-to-end. Letter of attestation on request.
05 · IRDAI ICS · DPDP IRDAI ICS 2023 · DPDP Act 2023.
India regulatory mapping, ready for review.
IRDAI Information & Cyber Security controls mapped end-to-end. DPDP Act 2023 DPA available on request — signed before kickoff.
06 · INDIA-RESIDENT GCP India (Mumbai) · MeitY-empaneled.
Empaneled across AWS, Azure, GCP, OCI.
India-resident data plane for regulated workloads. Sovereign providers buildable on customer contract.
07 · OPEN-SOURCE ROOTS Built on GoFr. Apache 2.0.
21.5k+ stars on GitHub.
ZopDay’s control plane is built on GoFr, the open-source Go framework created by our CTO. The same framework McAfee, FairPrice, and Fortune 500 retail teams run in production.