Compliance
Information Security Policy
This policy describes eNeoteric's commitments to information security — covering how we protect data, manage access, respond to incidents, and maintain the security posture of our own systems. Effective date: 1 January 2026. Last reviewed: July 2026.
Policy statement
eNeoteric Consultancy Services Pvt. Ltd. is committed to protecting the confidentiality, integrity, and availability of all information assets — including customer data, proprietary information, and the systems through which we deliver our services. This commitment extends to our employees, contractors, partners, and supply chain.
Our Information Security Management System (ISMS) is aligned to ISO 27001:2022 principles and CERT-In guidelines. The following sections summarise our key security controls and commitments.
Key security controls
Access control
All access to eNeoteric systems and customer data is governed by role-based access control (RBAC) on a need-to-know basis. Multi-factor authentication (MFA) is mandatory for all remote access and privileged accounts. Access rights are reviewed quarterly and revoked within 24 hours of staff departure.
Data encryption
All data in transit is encrypted using TLS 1.3 or higher. All data at rest on eNeoteric systems is encrypted using AES-256. Encryption keys are managed using dedicated key management systems with annual rotation.
Vulnerability management
eNeoteric conducts monthly vulnerability scans of its external and internal systems and performs annual penetration tests conducted by an independent third party. Critical vulnerabilities are remediated within 7 days; high within 30 days.
Incident response
eNeoteric maintains a documented incident response plan aligned to NIST SP 800-61. Security incidents are triaged within 2 hours, escalated to senior management within 4 hours for critical events, and reported to relevant authorities (CERT-In, DPDPA) within regulatory timeframes.
Business continuity
eNeoteric maintains a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) with tested RTO of 4 hours and RPO of 1 hour for critical systems. BCP/DRP tests are conducted annually. See our Business Continuity page for details.
Third-party risk
All third-party vendors with access to eNeoteric systems or customer data are subject to security assessment before onboarding and annual review. Vendors must meet minimum security requirements and are bound by confidentiality agreements.
Employee security
All employees and contractors complete security awareness training annually, with role-specific training for those handling customer data or accessing privileged systems. Background verification is conducted for all new hires in security-sensitive roles.
Frequently asked questions
- Who is responsible for information security at eNeoteric?
- The Head of Security Operations is responsible for eNeoteric's information security programme, reporting to the Managing Director. A Security Committee including senior leadership meets quarterly to review the security posture, risk register, and policy compliance.
- How do you handle security incidents affecting customer data?
- In the event of a security incident affecting customer data, we notify affected customers within 24 hours of confirmation, provide a situation report within 72 hours, and file mandatory notifications with CERT-In and (where applicable) the Data Protection Board of India within regulatory timeframes.
- Is this policy audited independently?
- Yes. Our security controls are assessed annually by an independent penetration testing team, and our security programme is reviewed by an external auditor. We are in the process of obtaining ISO 27001 certification for our own operations.
- How can I request a copy of this policy for vendor assessment?
- The public version of this policy is available on this page. For more detailed security documentation including our full ISMS controls list, risk assessment methodology, and evidence of key controls, contact [email protected] with subject 'Vendor Security Assessment'.
Questions about our security practices?
Contact UsGet in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us on +91 91080 15170.