Skip to content

SECURITY & COMPLIANCE

What we publish. And what we have not.

Enterprise buyers ask the same handful of questions before a contract moves forward: where the data lives, who else touches it, what happens when something breaks. This page answers what we can prove today. Anything we cannot yet prove is marked as exactly that, never implied otherwise.

How we handle client data

Our privacy policy covers what data we collect and how we use it. The technical specifics a security review asks for next are not yet written down publicly.

Full detail lives in our privacy policy. The one operational figure we do publish today: a 99.9% uptime SLA on the infrastructure we operate.

NOT YET PUBLISHED

Encryption in transit and at rest

NOT YET PUBLISHED

Access control and least-privilege policy

NOT YET PUBLISHED

Backup and disaster recovery plan

NOT YET PUBLISHED

Employee security training and background checks

Certification and audit status

What independent verification we publish today. An item listed here without a status has not been published either way, not implied.

NOT PUBLISHED

ISO/IEC 27001 (information security management)

NOT PUBLISHED

SOC 2 Type II

NOT PUBLISHED

Independent third-party penetration test

NOT PUBLISHED

Cyber liability insurance

Data residency and sub-processors

Where client data actually lives, and who else touches it, is not yet documented as a public list.

NOT YET PUBLISHED

Primary hosting region for client data

NOT YET PUBLISHED

Named sub-processor list

NOT YET PUBLISHED

Data retention and deletion schedule

DPDP Act and GDPR stance

YIB Global Technology Services LLP is registered in Kerala, India (GSTIN 32AADFY6703B1ZM). A registered address is not a compliance stance, so the specifics below are marked as what they are.

NOT YET PUBLISHED

Digital Personal Data Protection Act, 2023 (India): documented compliance stance

NOT YET PUBLISHED

EU General Data Protection Regulation: documented compliance stance

NOT YET PUBLISHED

Named Data Protection Officer or grievance officer

Incident response and escalation

Every inbound message reaches us through the channels below. A dedicated security desk, with its own response-time commitment, does not exist yet.

Until a dedicated channel exists, report anything through our published contact details: contact@webxlr8.com or +91 8075247569.

NOT YET PUBLISHED

Documented incident response plan

NOT YET PUBLISHED

Client notification window after a confirmed incident

NOT YET PUBLISHED

Dedicated security contact, separate from general inquiries

What we sign

Whether these are standing templates or drafted per engagement isn't published yet, so each is listed rather than assumed.

NOT YET PUBLISHED

Mutual Non-Disclosure Agreement (NDA)

NOT YET PUBLISHED

Master Services Agreement (MSA)

NOT YET PUBLISHED

Data Processing Agreement (DPA)

Ask what's missing. We'll tell you straight.

A security review usually starts with a question this page cannot yet answer with a document. Ask anyway. We'll say honestly where each item stands, and when it's likely to change.