Trust & Security
We hold ourselves to the standard we sell.
How Sadhyata secures its own systems, handles client data, and responds when something is reported — with the evidence available on request.
ISO 27001
Certified
SOC 2
Type II
< 1 day
Report acknowledgement
100%
Staff security training
Our controls
Eight areas, evidenced continuously
Control evidence is generated by our pipelines rather than assembled by hand before an audit.
Identity and access
Single sign-on with phishing-resistant multi-factor authentication for every employee. Access is least-privilege, time-bound where possible, and recertified quarterly.
Encryption
Data encrypted in transit with modern TLS and at rest with managed keys. Key rotation is scheduled and documented, not incidental.
Secure development
Dependency, secret, container, and static analysis scanning in every pipeline. A failing security gate blocks the release rather than raising a ticket.
Backup and recovery
Immutable backup copies with restoration tested on a schedule. A backup that has never been restored is not a backup.
Monitoring and response
Centralised logging with detections maintained against current techniques, and an incident response plan exercised with the executives who would run it.
Physical and personnel
Background checks proportionate to role, mandatory security training on joining and annually, and controlled access to delivery facilities.
Client data handling
Client data is segregated per engagement, accessed only by the named team, and returned or destroyed on completion against a written confirmation.
Subprocessors
A maintained subprocessor register available to clients on request, with notice given before a new subprocessor handles client data.
Documentation
What we can share
Available to clients and prospective clients under a mutual NDA where the document requires it.
Certification reports
ISO 27001 certificate and statement of applicability, plus the current SOC 2 Type II report under NDA.
Security questionnaires
We complete client questionnaires directly. Most are returned within five business days from a maintained answer library.
Penetration test summaries
Executive summaries of our most recent independent tests, with remediation status for each finding.
Certifications
Where we stand against each framework
Including the ones assessed per engagement rather than held as a certificate. Evidence is available for all of them.
| Framework | Status | What it covers | Evidence available |
|---|---|---|---|
| ISO 27001Certified | Certified, annual surveillance audit | Information security management system | Certificate and statement of applicability on request |
| SOC 2 Type II | Report issued annually | Security, availability and confidentiality | Full report under mutual NDA |
| GDPR | Compliant, DPO appointed | EU personal data processing | Processing register and DPA template |
| DPDPA | Compliant, consent framework live | Indian personal data processing | Consent and fiduciary obligations register |
| PCI DSS | Scope-minimising design, assessed per engagement | Cardholder data environments we build | Scope boundary documentation per engagement |
| HIPAA | Business associate agreements in place | Protected health information we process | BAA and safeguards documentation |
ISO 27001
Certified- Status
- Certified, annual surveillance audit
- What it covers
- Information security management system
- Evidence available
- Certificate and statement of applicability on request
SOC 2 Type II
- Status
- Report issued annually
- What it covers
- Security, availability and confidentiality
- Evidence available
- Full report under mutual NDA
GDPR
- Status
- Compliant, DPO appointed
- What it covers
- EU personal data processing
- Evidence available
- Processing register and DPA template
DPDPA
- Status
- Compliant, consent framework live
- What it covers
- Indian personal data processing
- Evidence available
- Consent and fiduciary obligations register
PCI DSS
- Status
- Scope-minimising design, assessed per engagement
- What it covers
- Cardholder data environments we build
- Evidence available
- Scope boundary documentation per engagement
HIPAA
- Status
- Business associate agreements in place
- What it covers
- Protected health information we process
- Evidence available
- BAA and safeguards documentation
How we operate
Three commitments about how we handle your estate
Access
Nobody holds standing access to your systems
Access to a client environment is requested, approved, time-boxed and logged, and expires automatically. That is occasionally inconvenient for us during an incident, which is the correct trade — a supplier with permanent credentials is an extension of your attack surface.
- Just-in-time access with automatic expiry
- Phishing-resistant multi-factor on every path
- Session recording where the client requires it
- Access reviewed quarterly and on every role change
Supply chain
We can tell you what is in what we shipped
Every release generates a software bill of materials, dependencies are scanned continuously rather than at release, and we run a licence audit before launch. When the next widely-exploited library lands, the question of whether you are affected takes minutes rather than weeks.
- SBOM generated per release and retained
- Continuous dependency and container scanning
- Licence audit before any production launch
- Notification to affected clients when an advisory lands
Incident response
A path agreed before it is needed
Contacts, decision rights and notification timelines are agreed in writing at contract, precisely so nobody is working out who to call while the clock is running. We rehearse it, and the rehearsal findings change the plan.
- Named contacts and escalation agreed at contract
- Notification timelines committed contractually
- Response rehearsed in exercises, not just documented
- Post-incident review shared in full, not summarised
Questions
What procurement and security teams ask
These are the questions on most security questionnaires, answered up front.
Our posture
Can we see your SOC 2 report?
Yes, under mutual NDA — the ISO 27001 certificate and statement of applicability are available without one. If your procurement process needs a completed security questionnaire, send it over; we maintain the answers against live control evidence rather than reconstructing them each time, so turnaround is usually a few days.
How do you handle our data in your environments?
Production data does not enter our development or test environments. Where realistic data is needed we generate synthetic data matching the statistical shape, or work with irreversibly de-identified extracts under a documented agreement. Where we must handle production data for an incident, it happens in your environment under your logging.
What happens to our access when the engagement ends?
Credentials are revoked as part of the closing checklist and we ask you to verify the revocation from your side rather than take our word for it. Any client data held for the engagement is destroyed or returned on the schedule set in the contract, with confirmation in writing.
Assurance
Are you independently tested?
Annually, by a third party we rotate rather than retain indefinitely, plus continuous automated scanning of our own estate. Summary findings and remediation status are available to clients under NDA. We have had findings, we have fixed them, and we would be suspicious of a supplier claiming otherwise.
Do you carry professional indemnity and cyber cover?
Yes, and certificates are provided as standard during contracting. Cover levels are stated in the master services agreement rather than negotiated per engagement, and we are happy to discuss whether the levels suit the risk profile of the specific work.
Reporting a vulnerability?
Go straight to security@sadhyata.com. We acknowledge within one business day and credit reporters who want it.