← Zarvix AI

Trust & Security

Every line below is a live control with a real reference — no “bank-level security” badges that mean nothing.

What Zarvix AI is, and what it is not

Zarvix AI is a software-technology provider — a no-code algo building, research, backtesting, and execution-assistance platform for Indian markets (NSE / BSE).

Zarvix AI is NOT a broker, an investment adviser (RIA), a portfolio manager (PMS), or a research analyst (RA). We do not give specific buy/sell recommendations; we do not hold or touch client funds; every order is initiated by you, executed by your own SEBI-registered broker, and routed under your broker authentication.

Who can do what today:

  • All users — build strategies in plain English (or Hindi, Hinglish, Tamil), research across 6 years of NSE / BSE data, backtest with the Rust engine, and refine via AI chat.
  • Proprietary traders and trading desks — additionally, deploy strategies live through a connected Symphony XTS broker account, with your explicit approval on every order.
  • Retail traders — live deployment via retail brokers (Zerodha, Upstox, and others) is on the roadmap, gated on NSE algo-vendorship empanelment. Coming soon.

Founder: Akshay Bagade — former proprietary trader. NISM-certified for AIF Category III (Alternative Investment Fund managers). Built Zarvix AI to compress the build → research → backtest → refine → deploy pipeline he wished existed when he was trading professionally.

Compliance & registration

CIN — Corporate Identification Number

Live

U62011PN2025PTC248729 — Zarvix AI Private Limited, Pune, MH.

GSTIN

Live

27AACCZ8146M1ZN

DPIIT Recognition — Startup India

Live

DIPP233049 — Zarvix AI Private Limited is recognized as an eligible startup by the Department for Promotion of Industry and Internal Trade (DPIIT), Ministry of Commerce and Industry, Government of India, under the Startup India initiative. Verify the certificate number on the official portal at https://www.startupindia.gov.in/content/sih/en/startupgov/validate-startup-recognition.html (Certificate Type: "Certificate of Recognition" → enter DIPP233049).

Backed by Microsoft for Startups

Live

Zarvix AI is admitted to the Microsoft for Startups Founders Hub program. Production infrastructure runs on the program's Azure subscription (Central India region) with Azure OpenAI, PostgreSQL Flexible Server, Container Apps, and Key Vault. This is a benefits + technical-support program, not equity investment — Microsoft has no ownership stake in Zarvix AI Private Limited.

Why we are not SEBI-registered (and do not need to be)

Live

Zarvix AI is a software technology provider. We are NOT a broker, an investment adviser (RIA), a portfolio manager (PMS), or a research analyst (RA) — and we do not perform any of those activities. We never hold or touch client funds. We do not give specific buy/sell recommendations — the AI drafts strategies you author and approve. Every order is initiated by you through your own SEBI-registered broker. The activities that require SEBI registration are not in our product surface.

SEBI algo-ID framework (April 2026)

Live

Every live order routes through a SEBI-registered broker API that handles exchange-assigned Algo-ID issuance. Symphony XTS is wired end-to-end today; additional brokers follow the same pattern.

DPDP Act (Digital Personal Data Protection)

Live

Privacy policy describes lawful bases (consent + legitimate use). Data minimisation — we only store what we need to operate. Your DPDP rights (access, correction, deletion, withdrawal of consent) — invoke them at privacy@zarvixai.com. See /privacy for the full policy.

IT Act 2000 + IT Rules 2021

Live

We operate as an intermediary under the IT Act 2000. A grievance contact and published response SLA are listed below, per Rule 3(2) of the IT (Intermediary Guidelines) Rules 2021.

AI governance

The AI is a co-pilot, not an autopilot. Every guarantee below is enforced in code, not in policy alone.

AI never executes trades

Live

The LLM only drafts strategies and explanations. Every order flows through your broker login with explicit confirmation. There is no AI-initiated trading path anywhere in the codebase.

AI never invents market data

Live

All quote / option-chain / OHLC data comes from your broker feed or our binary historical archive (NSE/BSE). The frontend has NO synthetic-quote rendering paths. The AI cannot fabricate prices.

AI never bypasses confirmation

Live

Confirmation is a hard rule in code, not a configurable flag. Drafts → review → approve → execute. There is no path that skips a step.

Your data is not used to train AI models

Live

Your strategies, conversations, trade history, and account data are never used as training data. The LLM provider operates under contractual no-training terms.

AI model and region

Live

Azure OpenAI deployed in the centralindia region (Pune). No prompts or completions leave India. Content-safety filters are active on all model calls.

Process disclosure on every AI reply

Live

Each assistant message ships with the tool calls it ran, their arguments and durations, plus a compute receipt (model + token count + wall-clock). You can audit exactly what the AI touched.

Platform security

Auth tokens never reach JavaScript

Live

All API auth uses HttpOnly + Secure + SameSite cookies. The frontend never sees the bearer token; a server-side proxy at /api/v1 injects it. An XSS hole would not yield session tokens.

HSTS + strict CSP + frame-ancestors deny

Live

Strict-Transport-Security max-age=63072000 with includeSubDomains and preload. Content-Security-Policy locks script + style + connect sources. X-Frame-Options: DENY. Cross-Origin-Opener-Policy: same-origin.

Microphone / camera / geolocation off by default

Live

Permissions-Policy disables camera, geolocation, and gates microphone access behind explicit user action. Payment scope limited to self.

Secrets in Azure Key Vault

Live

Database passwords, broker API keys, and LLM provider keys live in Azure Key Vault, not in code or container env. Rotation handled per-quarter.

TLS 1.2+ end-to-end

Live

Azure Front Door + managed certificates. No HTTP listener; HTTPS-only with HSTS preload.

Data & privacy

We do not sell your data. Ever.

Live

No user data — personal, strategy, trade, or behavioural — is sold, rented, licensed, or syndicated to any third party. No advertising trackers, no behavioural profiling, no data marketplaces. The only third parties that touch your data are the sub-processors listed below, each strictly to operate the platform for you.

Your strategies are your IP

Live

Strategies you build on Zarvix are yours. Multi-tenant isolation is enforced in every database query — only your account can read your strategies; another user's session cannot return them. We do not share your strategies with other users, sell them, or use them to train AI models (Azure OpenAI operates under contractual no-training terms on customer data). Internal database access is application-only via Azure managed identity; humans at Zarvix do not browse user strategies in normal operations, and any access for support / debugging requires your explicit request. You can export your strategies and run them on any other platform — no lock-in.

What we collect

Live

Email and one-time password for waitlist + login. Broker API keys (encrypted via Azure Key Vault) only if you connect a broker. Strategy definitions, backtest results, AI conversations. That is the entire surface — no advertising trackers, no behavioural profiling.

What we do not collect

Live

No trading PIN, no 2FA token, no banking credentials. The broker login flow runs in your browser direct to the broker — those secrets never touch our servers.

Data residency

Live

All compute and storage in the Azure centralindia region. No data leaves India for primary operations. The Azure OpenAI deployment serving the chat is also in India.

Data retention

Live

Active accounts: retained while the account is in use. Closed accounts: hard-deleted within 30 days of closure (with the exception of records we must retain for tax, anti-fraud, or regulatory compliance). Backups purge on a 30-day rolling cycle.

Sub-processors

Third parties that may touch user data, each under a data-processing agreement. No others.

Microsoft Azure (compute, storage, Key Vault)

Live

All hosting, databases, caches, secret storage, and binary data archives run on Azure, in the centralindia region.

Azure OpenAI (LLM)

Live

AI model serving for the chat and strategy assistant. Centralindia deployment. Contractual no-training-on-customer-data terms.

Symphony XTS (broker)

Live

Live order routing — only invoked when you explicitly connect your XTS broker account. We never see your broker password; only the API keys you provision.

Microsoft 365 (transactional email)

Live

Welcome emails, OTP delivery, security notifications. Routed via outlook.com.

GoDaddy (DNS hosting)

Live

Domain DNS only. No application traffic.

Microsoft Clarity (marketing-site analytics)

Live

Privacy-friendly web analytics — session counts, heatmaps, and anonymized session recordings for the public marketing site (zarvixai.com). No personally-identifiable profiling, no advertising trackers, no cross-site identifiers. Used only on the public marketing surface; not loaded on authenticated dashboards or trade-data screens. Operated by Microsoft.

Acceptable use

What our users must not do on the platform. Enforced at the risk-gate layer where possible.

No market manipulation

Live

Spoofing, layering, quote-stuffing, wash trading, and other forms of market manipulation are prohibited. Strategies that pattern-match to these behaviours will be blocked at the risk-gate layer before they reach the exchange.

Only your own broker account

Live

Only connect broker accounts you legally own. We log every order against the authenticated user; impersonation or shared-account abuse is a hard-stop.

No reverse-engineering or scraping

Live

Our APIs are for use through our products. Automated scraping, model-extraction, and reverse-engineering of the platform are prohibited per the Terms.

Grievance Officer (required under IT Rules 2021)

Email grievance@zarvixai.com. Acknowledgement within 24 hours, resolution within 15 working days, per Rule 3(2) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Report a vulnerability

Email security@zarvixai.com with reproduction steps. We acknowledge within 48 hours, fix critical issues within 7 days, and credit responsible disclosure on this page. Out of scope: DoS, social engineering, physical attacks, third-party dependencies we don't control.

Operator contact

For compliance / institutional onboarding / data-processing questions, email operations@zarvixai.com. We respond within one business day.