Compliance
Trust Centre
eNeoteric is a cybersecurity company. Our customers trust us with their most sensitive environments. This Trust Centre documents the security, privacy, and operational practices we hold ourselves to — so you can make an informed decision about entrusting your organisation's security to us.
Trust Centre
How we protect customer data and operate our internal security controls.
Read Security Policy →How we collect, use, and protect personal data under DPDPA and GDPR.
Read Privacy Policy →How to report security vulnerabilities in eNeoteric systems.
Report a Vulnerability →Our data handling practices and DPDPA alignment.
Read Data Protection →Our RTO/RPO commitments and service resilience practices.
Read BCP Policy →How security is embedded in our software delivery process.
Read SDL →Our security commitments
- We encrypt everything in transit and at rest — All customer data is encrypted using TLS 1.3 in transit and AES-256 at rest. We do not transmit customer data over unencrypted channels.
- We operate least-privilege access — Access to customer environments is granted on a need-to-know basis, reviewed quarterly, and revoked immediately upon engagement closure or staff departure.
- We are CERT-In empanelled — Our security practice is authorised to conduct mandatory information security audits for Indian regulated organisations.
- We undergo independent security assessments — Our own infrastructure and systems are assessed annually by an independent penetration testing team — we practise what we preach.
- We maintain a responsible disclosure programme — Security researchers who discover vulnerabilities in our systems can report them safely and receive a timely, professional response.
- We carry professional indemnity insurance — Our cybersecurity consulting and audit services are covered by professional indemnity insurance, details available upon request.
Frequently asked questions
- How do I report a security concern about eNeoteric's systems?
- Use our Responsible Disclosure page at encse.com/responsible-disclosure or email [email protected]. We acknowledge all reports within 24 hours and aim to resolve confirmed vulnerabilities within 30 days.
- Does eNeoteric have an ISO 27001 certificate for its own operations?
- We are in active pursuit of ISO 27001 certification for our own operations and are currently in the implementation phase. In the meantime, our security programme is aligned to ISO 27001 controls and we undergo annual independent security assessments. We will publish our certificate here upon issuance.
- How does eNeoteric handle data from client engagements?
- Data from client engagements is handled under strict confidentiality. We process only the minimum data necessary for each engagement, store it in isolated, access-controlled environments, and delete or return it per the terms of our engagement agreement. We never use client data for secondary purposes.
- Can I request a copy of eNeoteric's security documentation for due diligence?
- Yes. Enterprise customers and prospects can request our security questionnaire responses, NDA-protected security documentation, and evidence of key controls as part of vendor due diligence. Contact [email protected] with subject 'Vendor Due Diligence Request'.
Have a security question about eNeoteric?
Contact UsGet in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us on +91 91080 15170.