SECURITY & COMPLIANCE
What we publish. And what we have not.
Enterprise buyers ask the same handful of questions before a contract moves forward: where the data lives, who else touches it, what happens when something breaks. This page answers what we can prove today. Anything we cannot yet prove is marked as exactly that, never implied otherwise.
How we handle client data
Our privacy policy covers what data we collect and how we use it. The technical specifics a security review asks for next are not yet written down publicly.
Full detail lives in our privacy policy. The one operational figure we do publish today: a 99.9% uptime SLA on the infrastructure we operate.
Encryption in transit and at rest
Access control and least-privilege policy
Backup and disaster recovery plan
Employee security training and background checks
Certification and audit status
What independent verification we publish today. An item listed here without a status has not been published either way, not implied.
ISO/IEC 27001 (information security management)
SOC 2 Type II
Independent third-party penetration test
Cyber liability insurance
Data residency and sub-processors
Where client data actually lives, and who else touches it, is not yet documented as a public list.
Primary hosting region for client data
Named sub-processor list
Data retention and deletion schedule
DPDP Act and GDPR stance
YIB Global Technology Services LLP is registered in Kerala, India (GSTIN 32AADFY6703B1ZM). A registered address is not a compliance stance, so the specifics below are marked as what they are.
Digital Personal Data Protection Act, 2023 (India): documented compliance stance
EU General Data Protection Regulation: documented compliance stance
Named Data Protection Officer or grievance officer
Incident response and escalation
Every inbound message reaches us through the channels below. A dedicated security desk, with its own response-time commitment, does not exist yet.
Until a dedicated channel exists, report anything through our published contact details: contact@webxlr8.com or +91 8075247569.
Documented incident response plan
Client notification window after a confirmed incident
Dedicated security contact, separate from general inquiries
What we sign
Whether these are standing templates or drafted per engagement isn't published yet, so each is listed rather than assumed.
Mutual Non-Disclosure Agreement (NDA)
Master Services Agreement (MSA)
Data Processing Agreement (DPA)
Ask what's missing. We'll tell you straight.
A security review usually starts with a question this page cannot yet answer with a document. Ask anyway. We'll say honestly where each item stands, and when it's likely to change.



