Security & compliance

Security & compliance, transparently.

How Hipla protects your data — our certifications, security controls, subprocessors and policies, all in one place.

Last updated 5 October 2026

Compliance & certifications

SOC 2 Type II

Certified

Independently audited controls for security, availability and confidentiality.

ISO 27001 : 2022

Certified

ISMS certified to ISO/IEC 27001:2022 by OSS Certification Services (ASCB accredited). Certificate MS-A:9419920923-1, recertified 30 Sep 2026, valid to 29 Sep 2027 subject to annual surveillance.

GDPR

Compliant

Compliant with EU General Data Protection Regulation.

DPDPA India

Compliant

Safeguards for data protection as per DPDPA

Security controls

Data Protection8/8 operational▾
Encryption in transitOperational

All traffic secured with TLS 1.2+.

Encryption at restOperational

Data encrypted at rest with AES-256.

Key management (AWS KMS)Operational

Encryption keys are managed in AWS Key Management Service, access-controlled through IAM and rotated on a defined schedule.

Secrets managementOperational

API keys and application secrets are stored in AWS Secrets Manager and are never placed in source code, configuration or logs.

Data classificationOperational

Information is classified across four tiers (Public, Internal, Confidential, Restricted) with handling rules for each.

Data retention & disposalOperational

Retention periods are defined per data type; visitor data defaults to 3 years and is customer-configurable.

Secure data deletion & returnOperational

Customer data is securely deleted within 30 days of contract termination, with confirmation on request.

Data residency (India)Operational

All Indian-deployment data is hosted in the AWS Asia Pacific (Mumbai) region, keeping data in India.

Access Control7/7 operational▾
Single sign-on (SSO)Operational

SAML/OIDC SSO for enterprise customers.

MFA enforcementOperational

Multi-factor authentication required for all staff.

Role-based access control (RBAC)Operational

Access follows role-based least-privilege; users receive only the access their role requires.

Periodic access reviewsOperational

Cloud (IAM) and application access is formally reviewed every six months and findings tracked to closure.

Password policyOperational

Enforced minimum length, complexity, history, rotation and lockout across all accounts.

Privileged access managementOperational

Privileged access is restricted to named individuals, protected by MFA, via bastion hosts, and logged.

Joiner / mover / leaver processOperational

Access is provisioned, adjusted and revoked promptly as people join, change role or leave.

Infrastructure7/7 operational▾
Continuous monitoringOperational

24/7 monitoring and alerting across systems.

Network segmentation & isolationOperational

Production is isolated from non-production; databases and internal services are not exposed to the internet.

Threat detection (GuardDuty)Operational

AWS GuardDuty provides continuous, intelligent threat detection across the environment.

Audit logging (CloudTrail)Operational

AWS CloudTrail maintains a tamper-evident audit trail of API and account activity.

Patch managementOperational

Security patches are applied on severity-based SLAs, tested before release, with rollback.

Endpoint detection & response (EDR)Operational

CrowdStrike endpoint protection is deployed on company devices and kept current.

Mobile device management (MDM)Operational

Company devices are enrolled in Esper MDM with encryption, lock and remote-wipe.

Governance7/7 operational▾
Annual penetration testingOperational

Third-party pen tests performed annually.

Information security management systemOperational

An ISO/IEC 27001:2022-aligned ISMS governs the security programme, under Group CISO oversight.

Risk management programmeOperational

Formal risk assessment and treatment is run at least annually and on significant change.

Security awareness trainingOperational

All staff complete security-awareness training at induction and at least annually.

Vendor / sub-processor managementOperational

Suppliers are risk-assessed and bound by data-protection agreements; sub-processors are published.

Change managementOperational

Changes are assessed, approved by a change board and implemented with rollback.

Incident response & breach notificationOperational

A defined IR process applies; customers are notified within 24h and regulators within 72h of a confirmed breach.

Application Security6/6 operational▾
Secure development lifecycle (SDLC)Operational

Security is built into every phase of development, with threat modelling and quality gates.

Static application security testing (SAST)Operational

SonarQube runs on every code change and blocks merges with high or critical findings.

Software composition analysis (SCA)Operational

Third-party dependencies are continuously scanned against CVE data and remediated to SLA.

Mandatory code reviewOperational

Every change is peer-reviewed before merge; direct pushes to protected branches are blocked.

Vulnerability managementOperational

Findings are scored on CVSS and remediated within severity-based SLAs, then retested.

Web application firewall (WAF)Operational

Internet-facing endpoints are protected by AWS WAF against common web attacks.

Resilience4/4 operational▾
High availability (Multi-AZ)Operational

The database and compute tiers run Multi-AZ on AWS with automatic failover.

Business continuity planOperational

A documented BCP covers critical services with defined recovery objectives, tested regularly.

Disaster recovery (tested)Operational

A DR plan defines RTO/RPO and is validated through an annual failover drill.

Encrypted backups & restore testingOperational

Automated encrypted backups with point-in-time recovery; restores are tested annually.

Privacy4/4 operational▾
DPDP & GDPR alignmentOperational

Personal data is processed in line with India's DPDP Act 2023 and the GDPR where applicable.

Data subject rights (DSR)Operational

A documented process handles access, correction, erasure and portability requests within 30 days.

Records of processing (RoPA)Operational

A lawful-basis / data-processing register documents each processing activity and its basis.

Background verification & NDAOperational

Staff are background-verified before joining and bound by confidentiality agreements.

Documents & reports

Policy Pack - Control Register

Registers

Business Continuity Plan (HBI-PLN-01 v5.0)

Plans

Data Processing Agreement

Legal

Standard DPA for customers.

Disaster Recovery Plan (HBI-PLN-02 v1.0)

Plans

Incident Management Plan (HBI-PLN-03 v6.0)

Plans

Information Security Policy (HBI-POL-01 v5.0)

Policies

Data Privacy Policy (HBI-POL-02 v6.0)

Policies

Access Control Policy (HBI-POL-03 v1.0)

Policies

Subprocessors

ProviderPurposeLocation
Amazon Web ServicesCloud infrastructure hostingUSA / EU
CloudflareCDN and DDoS protectionGlobal

Frequently asked questions

Where is my data stored?▾

All data is hosted in the AWS Asia Pacific (Mumbai) region, keeping your data resident in India. Backups also remain in India.

Do you support SSO?▾

Yes, SAML and OIDC SSO are available on enterprise plans.

How do I report a vulnerability?▾

Email support@hipla.io with details. We aim to respond within 24 hours.

Is my data encrypted?▾

Yes. All data is encrypted in transit with TLS 1.2+ and at rest with AES-256, using keys managed in AWS KMS.

What certifications and compliance standards do you meet?▾

Hipla operates an ISO/IEC 27001:2022-aligned information security management system and complies with India's DPDP Act and with GDPR where EU personal data is processed.

Do you perform independent penetration testing?▾

Yes. Independent third-party testing of our web, mobile and API surfaces is performed at least annually and before major releases, with findings tracked to closure.

How quickly will you notify me of a data breach?▾

We notify affected customers without undue delay, within 24 hours of confirming a personal-data breach.

What is your disaster recovery capability?▾

We maintain a documented business-continuity and disaster-recovery plan with defined recovery objectives, encrypted backups, Multi-AZ replication, and point-in-time recovery.