Intellisoft is committed to safeguarding the confidentiality, integrity, and availability of information assets belonging to our organization, our clients, and our partners.
This page describes our public information security commitment. It is intended to provide assurance at a governance level — not to disclose sensitive operational or technical security details.
Important disclosure limitation
For legitimate security reasons, Intellisoft does not publicly disclose specific details about our security program, including but not limited to:
- Internal security policies, standards, procedures, and playbooks
- Technical architecture diagrams, network topology, or infrastructure configurations
- Security tooling, monitoring rules, alerting thresholds, or control implementations
- Access control matrices, privileged account management, or credential handling methods
- Vulnerability assessments, penetration test results, or remediation specifics
- Incident response timelines, forensic findings, or breach notification details
- Vendor security arrangements beyond general references
- Business continuity and disaster recovery runbooks or recovery point objectives
Detailed security documentation — including responses to security questionnaires, SOC reports, or control evidence — may be shared with prospective and existing clients only under a mutual non-disclosure agreement (NDA) or equivalent contractual confidentiality terms, and only with authorized personnel on a need-to-know basis.
To request security information under NDA, contact contact@intellisoft.in with your organization name and the nature of your inquiry.
1. Our commitment
We align our security practices with recognized industry principles and integrate security considerations into:
- Software development and delivery lifecycle
- Cloud and infrastructure operations
- Client data handling and service delivery
- Employee onboarding, training, and offboarding
- Third-party and vendor risk management
2. Governance and accountability
Information security is overseen at the management level with defined roles and responsibilities. We maintain policies that address acceptable use, access management, data classification, incident reporting, and secure development practices. Internal reviews are conducted periodically to improve our control environment.
3. Data protection
We apply measures designed to protect data at rest and in transit, including encryption where appropriate, secure development practices, and least-privilege access. Client data is handled in accordance with contractual obligations and applicable regulations.
For how we collect and use personal information on our website, see our Privacy Policy.
4. Access control
Access to systems and information is granted on a need-to-know basis, reviewed periodically, and revoked promptly when no longer required. We enforce authentication requirements and monitor for unauthorized access attempts using industry-standard practices.
5. Secure development and operations
Our engineering teams follow secure coding guidelines, code review practices, environment separation, and change management appropriate to project risk. Production deployments use controlled pipelines with logging and rollback capabilities.
6. Incident management
We maintain an incident response process to detect, contain, investigate, and remediate security events. Affected clients and regulators are notified when required by contract or law. Specific incident details are not published publicly.
7. Business continuity
We maintain business continuity and backup practices designed to support service resilience. Specific recovery procedures and targets are shared with clients under appropriate confidentiality agreements where relevant to contracted services.
8. Compliance and standards
Intellisoft operates under a quality management framework aligned with ISO 9001:2015 certification principles. We comply with applicable Indian laws and contractual security requirements for the industries and regions we serve.
9. Personnel and awareness
Employees and contractors with access to sensitive information undergo background checks where appropriate and receive security awareness guidance. Confidentiality obligations are included in employment and vendor agreements.
10. Shared responsibility
Security is a shared responsibility. Clients are expected to:
- Protect their account credentials and access tokens
- Provide accurate requirements and timely security-related information
- Report suspected security issues promptly
- Comply with applicable laws regarding data they provide to us
11. Reporting security concerns
If you discover a potential vulnerability or security issue related to Intellisoft systems or services, please report it responsibly to contact@intellisoft.in. Include sufficient detail for us to investigate. Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.
12. Updates to this page
We may update this public statement to reflect improvements in our program or changes in regulatory expectations. The effective date at the top indicates the latest revision. This page does not create contractual obligations beyond those in signed agreements.
13. Contact
Security and privacy inquiries: contact@intellisoft.in