Visotonics designs, builds and operates its platform with a defence-in-depth security posture. This Security Policy summarises the administrative, technical and physical controls implemented to protect the confidentiality, integrity and availability of the Services and the data processed on them. It is intended for information purposes and does not modify the contractual commitments contained in a signed order form or master services agreement.
Section 01
Governance
- Documented information-security programme owned by the leadership team and reviewed at least annually.
- Policies aligned with recognised frameworks including ISO/IEC 27001 and SOC 2 principles.
- Security responsibilities assigned across the organisation with defined incident escalation.
Section 02
People & personnel
- Background verification for all employees prior to access provisioning.
- Annual mandatory security and privacy training for staff.
- Confidentiality obligations enforced through employment and contractor agreements.
Section 03
Access control
- Role-based access control (RBAC) with least-privilege by default.
- Multi-factor authentication (MFA) required for all administrative access.
- Passwords stored using industry-standard salted, one-way hashing (bcrypt).
- Access reviews conducted on a periodic basis and on role change or termination.
Section 04
Data protection
- Encryption in transit using TLS 1.2 or higher for all external and administrative traffic.
- Encryption at rest for production databases and backups using AES-256 (or equivalent).
- Key management performed via managed cloud key services with restricted operator access.
- Data segregation between customer tenants enforced at the application and infrastructure layers.
Section 05
Application security
- Secure software development lifecycle (SSDLC) with code review and static analysis on every change.
- Dependency and container-image scanning on the build pipeline.
- Regular vulnerability scanning and periodic third-party penetration testing.
- Defence-in-depth against the OWASP Top 10 including input validation, output encoding and CSRF/XSS mitigations.
Section 06
Infrastructure & network
- Deployment in hardened, network-isolated environments with default-deny firewall policies.
- Managed VPCs with dedicated subnets and security groups per service tier.
- DDoS protection at the ingress layer.
- Segregation of production from development and staging environments.
Section 07
Logging & monitoring
- Centralised, tamper-evident logging of authentication, administrative and application events.
- Continuous monitoring with automated alerting on anomalous behaviour.
- Log retention aligned to legal and contractual obligations.
Section 08
Incident response
- Documented incident-response plan with defined severity, triage and communication procedures.
- Customer notification of confirmed security incidents in accordance with the applicable contract and law.
- Post-incident review and remediation tracking.
Section 09
Business continuity & backups
- Automated encrypted backups of critical data with defined retention.
- Documented recovery-time and recovery-point objectives (RTO / RPO).
- Periodic testing of restore procedures.
Section 10
Vendor management
- Due diligence performed on all sub-processors and critical vendors.
- Written data-processing agreements imposing equivalent security obligations.
- Ongoing monitoring of vendor security posture.
Section 11
Physical security
All production infrastructure runs on facilities operated by leading cloud providers, which maintain ISO 27001, SOC 2 and equivalent certifications for physical, environmental and personnel controls.
Section 12
Responsible disclosure
We welcome reports from independent security researchers. If you believe you have identified a vulnerability affecting the Services, please contact us via the contact page. We will acknowledge the report, investigate promptly and coordinate any disclosure.
Section 13
Governing law & jurisdiction
This Security Policy is governed by the laws of India. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts in Lucknow, India.