In transit: TLS 1.2+
At rest: AES-256
Cloud & Integration Security
We only work with certified vendors (e.g., AWS, Azure) who meet ISO 27001 and SOC 2 standards.
We align our practices to the data privacy laws of the countries we operate in:
Consent-driven data handling
Appointed Data Protection Officer
Breach notifications within 3 days
Clear legal basis for data processing
Data access, correction, and erasure rights
UK-based DPO & Standard Contractual Clauses for transfers
Consent and purpose limitation
Data localization for sensitive information
Grievance redressal and breach notifications
ERP + AI logs for audit trails
Region-specific data storage (Singapore, UK, India)
Retention policies based on client and regulatory needs
No use of client data for generic AI training
Optional human-in-loop oversight for AI workflows
Detection & response within 4 hours
Client notification within 24 hours
Root-cause analysis and fix in 5 business days
We offer custom Data Processing Agreements (DPAs) and full visibility into how your data is accessed and processed—by humans or AI agents.