Security & compliance
Access, data handling, certifications, and how each is reviewed.
Access model, data residency and handling, source ownership, and current certifications.
- Information security management
- ISO 27001Information security management
- Quality management
- ISO 9001Quality management
- Source, from the first commit
- YoursSource, from the first commit
Posture
How we work inside your systems.
Four commitments that shape every engagement, and that a security reviewer can check against what actually happens.
Access is least-privilege and time-boxed
Engineers request access per environment and it is revoked at phase end. Where your policy requires it we work inside your network on your devices, and production data is never copied to a developer machine.
Your accounts, your billing
Cloud infrastructure runs in accounts you own under your billing relationship, with our access granted rather than held. Revoking it is a permission change, not a migration.
Source is yours from the first commit
In your repository, under your organisation, with no runtime licence back to us on custom work. Source escrow with a third-party agent is available where your risk function asks for it.
Security review is a delivery phase
The Prove phase covers penetration testing, dependency audit and a security walkthrough before go-live — not a remediation project discovered afterwards.
Data
Where it lives, how long, and who can reach it.
Residency
Data stays where your policy and your regulator require. For payment data under RBI rules that means India, and the region is decided before anything else about the architecture is.
DPDP Act 2023
Consent capture, purpose limitation, retention and erasure are designed into the data model rather than retrofitted. The grievance officer requirement is on the launch checklist for every platform that holds personal data.
Retention and deletion
Agreed per engagement and implemented as a scheduled job rather than a policy document nobody runs. Deletion means deletion, including from backups on their own cycle.
Encryption
TLS 1.2 or better in transit and provider-managed encryption at rest as the floor, with field-level encryption where the data class warrants it.
Sub-processors
The list depends on your architecture — cloud provider, and any managed service the design calls for. It is supplied in writing before contract rather than published here, because a partial list is worse than none.
Incident response
Defined severities, a named escalation path and a notification commitment in the SLA. Post-incident there is a written review covering timeline, cause and what changed.
What we hold, and what the certificate says.
Brihat Infotech is certified to ISO/IEC 27001 and ISO 9001. We are not SOC 2 attested and do not display a badge suggesting otherwise.
ISO does not issue a logo to certified organisations — what a certified company may display is its certification body's mark. Ours, with the certificate number, is in the posture pack.
6 documents, available on request
- Security posture pack — controls, access model, and data handling
- ISO certificates and the certification body's details
- Penetration test summary for platforms we operate
- Sub-processor list for your proposed architecture
- Professional indemnity certificate
- Standard MSA, DPA and NDA templates
Ask at hello@brihatinfotech.com. These go out under NDA where the document warrants one, usually within a working day.
Next step
Bring us the problem. We will bring the architecture.
A discovery call takes forty-five minutes. You leave with our read on the problem, the shape of the system we would propose, and a straight answer on whether we are the right team for it.
- No sales deck
- An engineer on the call, not an account manager
- NDA before you share anything

