Skip to content
Brihat InfotechBrihat Infotech

Security & compliance

Access, data handling, certifications, and how each is reviewed.

Access model, data residency and handling, source ownership, and current certifications.

Information security management
ISO 27001Information security management
Quality management
ISO 9001Quality management
Source, from the first commit
YoursSource, from the first commit

Posture

How we work inside your systems.

Four commitments that shape every engagement, and that a security reviewer can check against what actually happens.

Access is least-privilege and time-boxed

Engineers request access per environment and it is revoked at phase end. Where your policy requires it we work inside your network on your devices, and production data is never copied to a developer machine.

Your accounts, your billing

Cloud infrastructure runs in accounts you own under your billing relationship, with our access granted rather than held. Revoking it is a permission change, not a migration.

Source is yours from the first commit

In your repository, under your organisation, with no runtime licence back to us on custom work. Source escrow with a third-party agent is available where your risk function asks for it.

Security review is a delivery phase

The Prove phase covers penetration testing, dependency audit and a security walkthrough before go-live — not a remediation project discovered afterwards.

Data

Where it lives, how long, and who can reach it.

Residency

Data stays where your policy and your regulator require. For payment data under RBI rules that means India, and the region is decided before anything else about the architecture is.

DPDP Act 2023

Consent capture, purpose limitation, retention and erasure are designed into the data model rather than retrofitted. The grievance officer requirement is on the launch checklist for every platform that holds personal data.

Retention and deletion

Agreed per engagement and implemented as a scheduled job rather than a policy document nobody runs. Deletion means deletion, including from backups on their own cycle.

Encryption

TLS 1.2 or better in transit and provider-managed encryption at rest as the floor, with field-level encryption where the data class warrants it.

Sub-processors

The list depends on your architecture — cloud provider, and any managed service the design calls for. It is supplied in writing before contract rather than published here, because a partial list is worse than none.

Incident response

Defined severities, a named escalation path and a notification commitment in the SLA. Post-incident there is a written review covering timeline, cause and what changed.

Certifications

What we hold, and what the certificate says.

Brihat Infotech is certified to ISO/IEC 27001 and ISO 9001. We are not SOC 2 attested and do not display a badge suggesting otherwise.

ISO does not issue a logo to certified organisations — what a certified company may display is its certification body's mark. Ours, with the certificate number, is in the posture pack.

6 documents, available on request

  • Security posture pack — controls, access model, and data handling
  • ISO certificates and the certification body's details
  • Penetration test summary for platforms we operate
  • Sub-processor list for your proposed architecture
  • Professional indemnity certificate
  • Standard MSA, DPA and NDA templates

Ask at hello@brihatinfotech.com. These go out under NDA where the document warrants one, usually within a working day.

Asked in security review
More in the FAQ

No, and we will not imply otherwise. We hold ISO/IEC 27001 and ISO 9001. If your procurement process requires a SOC 2 Type II report specifically, that is a genuine constraint and worth raising in the first conversation rather than at contract stage.

Next step

Bring us the problem. We will bring the architecture.

A discovery call takes forty-five minutes. You leave with our read on the problem, the shape of the system we would propose, and a straight answer on whether we are the right team for it.

  • No sales deck
  • An engineer on the call, not an account manager
  • NDA before you share anything