Trust & Security

We hold ourselves to the standard we sell.

How Sadhyata secures its own systems, handles client data, and responds when something is reported — with the evidence available on request.

ISO 27001

Certified

SOC 2

Type II

< 1 day

Report acknowledgement

100%

Staff security training

Our controls

Eight areas, evidenced continuously

Control evidence is generated by our pipelines rather than assembled by hand before an audit.

Identity and access

Single sign-on with phishing-resistant multi-factor authentication for every employee. Access is least-privilege, time-bound where possible, and recertified quarterly.

Encryption

Data encrypted in transit with modern TLS and at rest with managed keys. Key rotation is scheduled and documented, not incidental.

Secure development

Dependency, secret, container, and static analysis scanning in every pipeline. A failing security gate blocks the release rather than raising a ticket.

Backup and recovery

Immutable backup copies with restoration tested on a schedule. A backup that has never been restored is not a backup.

Monitoring and response

Centralised logging with detections maintained against current techniques, and an incident response plan exercised with the executives who would run it.

Physical and personnel

Background checks proportionate to role, mandatory security training on joining and annually, and controlled access to delivery facilities.

Client data handling

Client data is segregated per engagement, accessed only by the named team, and returned or destroyed on completion against a written confirmation.

Subprocessors

A maintained subprocessor register available to clients on request, with notice given before a new subprocessor handles client data.

Documentation

What we can share

Available to clients and prospective clients under a mutual NDA where the document requires it.

Certification reports

ISO 27001 certificate and statement of applicability, plus the current SOC 2 Type II report under NDA.

Security questionnaires

We complete client questionnaires directly. Most are returned within five business days from a maintained answer library.

Penetration test summaries

Executive summaries of our most recent independent tests, with remediation status for each finding.

Certifications

Where we stand against each framework

Including the ones assessed per engagement rather than held as a certificate. Evidence is available for all of them.

ISO 27001

Certified
Status
Certified, annual surveillance audit
What it covers
Information security management system
Evidence available
Certificate and statement of applicability on request

SOC 2 Type II

Status
Report issued annually
What it covers
Security, availability and confidentiality
Evidence available
Full report under mutual NDA

GDPR

Status
Compliant, DPO appointed
What it covers
EU personal data processing
Evidence available
Processing register and DPA template

DPDPA

Status
Compliant, consent framework live
What it covers
Indian personal data processing
Evidence available
Consent and fiduciary obligations register

PCI DSS

Status
Scope-minimising design, assessed per engagement
What it covers
Cardholder data environments we build
Evidence available
Scope boundary documentation per engagement

HIPAA

Status
Business associate agreements in place
What it covers
Protected health information we process
Evidence available
BAA and safeguards documentation

How we operate

Three commitments about how we handle your estate

Access

Nobody holds standing access to your systems

Access to a client environment is requested, approved, time-boxed and logged, and expires automatically. That is occasionally inconvenient for us during an incident, which is the correct trade — a supplier with permanent credentials is an extension of your attack surface.

  • Just-in-time access with automatic expiry
  • Phishing-resistant multi-factor on every path
  • Session recording where the client requires it
  • Access reviewed quarterly and on every role change

Supply chain

We can tell you what is in what we shipped

Every release generates a software bill of materials, dependencies are scanned continuously rather than at release, and we run a licence audit before launch. When the next widely-exploited library lands, the question of whether you are affected takes minutes rather than weeks.

  • SBOM generated per release and retained
  • Continuous dependency and container scanning
  • Licence audit before any production launch
  • Notification to affected clients when an advisory lands

Incident response

A path agreed before it is needed

Contacts, decision rights and notification timelines are agreed in writing at contract, precisely so nobody is working out who to call while the clock is running. We rehearse it, and the rehearsal findings change the plan.

  • Named contacts and escalation agreed at contract
  • Notification timelines committed contractually
  • Response rehearsed in exercises, not just documented
  • Post-incident review shared in full, not summarised

Questions

What procurement and security teams ask

These are the questions on most security questionnaires, answered up front.

Our posture

Can we see your SOC 2 report?

Yes, under mutual NDA — the ISO 27001 certificate and statement of applicability are available without one. If your procurement process needs a completed security questionnaire, send it over; we maintain the answers against live control evidence rather than reconstructing them each time, so turnaround is usually a few days.

How do you handle our data in your environments?

Production data does not enter our development or test environments. Where realistic data is needed we generate synthetic data matching the statistical shape, or work with irreversibly de-identified extracts under a documented agreement. Where we must handle production data for an incident, it happens in your environment under your logging.

What happens to our access when the engagement ends?

Credentials are revoked as part of the closing checklist and we ask you to verify the revocation from your side rather than take our word for it. Any client data held for the engagement is destroyed or returned on the schedule set in the contract, with confirmation in writing.

Assurance

Are you independently tested?

Annually, by a third party we rotate rather than retain indefinitely, plus continuous automated scanning of our own estate. Summary findings and remediation status are available to clients under NDA. We have had findings, we have fixed them, and we would be suspicious of a supplier claiming otherwise.

Do you carry professional indemnity and cyber cover?

Yes, and certificates are provided as standard during contracting. Cover levels are stated in the master services agreement rather than negotiated per engagement, and we are happy to discuss whether the levels suit the risk profile of the specific work.

Reporting a vulnerability?

Go straight to security@sadhyata.com. We acknowledge within one business day and credit reporters who want it.