Nootus.CA
Security Architecture
Technical deep dive

A zero-trust platform, built on Microsoft Azure.

Nootus.CA is engineered as a secure, multi-layered, zero-trust platform hosted entirely on Microsoft Azure India regions. This is a technical deep dive into the infrastructure, network security, encryption, failover and operational safeguards that protect CA firms and client financial data.

01 · Overview

Defense-in-depth, by design.

Nootus.CA follows a defense-in-depth security model that meets the expectations of CTOs, CIOs and enterprise compliance teams.

Multi-layer protection
Zero-trust access
Full encryption
Network isolation
Azure-native security
High availability
Disaster recovery
DPDP compliance
02–04 · Edge & perimeter

Edge security to secrets management.

Every request passes through Azure Front Door and Application Gateway before it ever reaches the application, with all secrets held in Azure Key Vault.

Azure Front DoorGlobal edge security
  • DDoS protection
  • Global load balancing
  • TLS termination
  • Bot filtering
  • Edge caching
  • High-speed routing

Faster access across India and a secure global entry point for all traffic.

Application GatewayWeb Application Firewall (WAF)
  • SQL injection protection
  • Cross-site scripting protection
  • Path traversal protection
  • OWASP Top 10 coverage
  • SSL/TLS inspection
  • Rate limiting

The primary shield for the application layer.

Azure Key VaultSecrets, keys & certificates
  • Database connection strings
  • Encryption keys
  • API secrets
  • Certificates
  • Hardware-backed security modules
  • Automatic key rotation

No secret ever resides in the codebase or environment variables.

05 · Encryption layers

Multi-layer encryption, in transit and at rest.

Data in transit

  • TLS 1.2+
  • Enforced HTTPS
  • HSTS enabled
  • Secure cipher suites

Data at rest

  • AES-256 encryption
  • Encrypted storage accounts
  • Encrypted SQL databases
  • Encrypted backups

Document encryption

  • Encrypted on upload
  • Version-controlled
  • Access-restricted
06 · Network isolation

Complete isolation from the public internet.

Azure Virtual Networks keep every service off the open internet, reachable only through Front Door and Application Gateway.

Virtual network

  • Private subnets
  • Network security groups (NSGs)
  • Restricted inbound/outbound rules
  • No public database endpoints
  • Service endpoints for Azure-internal traffic

Database isolation

  • SQL database accessible only from VNet
  • No public IP exposure
  • Firewall rules enforced

API isolation

  • Internal microservices over private networks
  • No cross-tenant exposure
07 · Zero-trust access model

No implicit trust, ever.

Identity-first security

  • Every request authenticated
  • Every action authorized
  • No implicit trust

Role-based access control

  • Firm-level roles
  • Staff-level roles
  • Client-level isolation
  • Module-specific permissions

Least privilege

  • Users only see what they are allowed to see.

Session security

  • Short-lived tokens
  • Automatic session expiry
  • Device fingerprinting (roadmap)
08–09 · Resilience

No data loss, minimal downtime.

Geo-redundant backups and multi-region failover across Azure India regions ensure high availability, even during regional outages.

Backups

  • Automated daily backups
  • Point-in-time restore
  • Encrypted backup storage
  • 30–90 day retention (configurable)

Disaster recovery

  • Azure Site Recovery
  • Automated failover
  • Recovery time objective (RTO): minutes
  • Recovery point objective (RPO): near-zero

Multi-region failover

  • Primary: Central India
  • Secondary: South India
  • Automatic failover
  • Region-level redundancy
  • Load balancing across regions
10 · Operational security

Every action logged, every change traceable.

Audit trails

Every action logged, every change traceable, and all AI agent activity logged.

Monitoring

Azure Security Center, Azure Monitor, Log Analytics, and threat detection alerts.

Compliance

Aligned with the DPDP Act, CERT-In guidelines and industry best practices.

11 · Summary

The level of security expected from a national-scale compliance platform.

Multi-layer protectionZero-trust accessFull encryptionNetwork isolationAzure-native securityHigh availabilityDisaster recoveryDPDP compliance

Enterprise-grade security, built for CA firms.

Engineered for the firms that demand reliability, protection and trust, every layer of the stack, secured.

Hosted entirely on Microsoft Azure India regions