Security Policy
1. Infrastructure Security
Our infrastructure is hosted on world-class, Tier-IV data centers provided by Amazon Web Services (AWS) and Google Cloud Platform (GCP). These facilities employ advanced physical security measures, including biometric access controls, 24/7 security guards, and rigorous environmental controls.
At the network layer, we employ:
- DDoS Mitigation: Enterprise-grade web application firewalls (WAF) and DDoS protection to ensure continuous availability.
- Network Isolation: Strict Virtual Private Cloud (VPC) segmentation separating public-facing applications from internal databases.
- Intrusion Detection: 24/7 automated monitoring for anomalous network activity.
2. Data Encryption
Protecting client data is our highest priority. We use industry-standard encryption protocols to protect data both in transit and at rest.
- In Transit: All communications with SoftGen servers are encrypted using Transport Layer Security (TLS) 1.2 or higher, with strong cipher suites and Perfect Forward Secrecy (PFS).
- At Rest: All databases, backups, and file storage are encrypted using AES-256 encryption. We utilize Key Management Services (KMS) to securely rotate and manage encryption keys.
3. Identity & Access Management
Access to SoftGen's production environments and customer data is strictly controlled following the Principle of Least Privilege (PoLP).
- Multi-Factor Authentication (MFA): Mandatory for all employees accessing internal systems and code repositories.
- Role-Based Access Control (RBAC): Granular permissions ensure employees only have access to the resources necessary for their specific role.
- Audit Logs: Comprehensive logging of all access and administrative actions, securely stored in immutable log servers.
4. Compliance & Certifications
SoftGen is committed to maintaining the highest standards of regulatory compliance and operational security.
- SOC 2 Type II: We undergo annual audits by independent third parties to verify our security, availability, and confidentiality controls.
- ISO 27001: Our Information Security Management System (ISMS) is certified against the ISO 27001 standard.
- GDPR & CCPA: We provide full support for global privacy regulations, including data subject access requests and data portability.
5. Vulnerability Management
We proactively identify and remediate security vulnerabilities across our software stack.
- Penetration Testing: We commission independent cybersecurity firms to conduct thorough penetration tests at least annually.
- Continuous Scanning: Automated static (SAST) and dynamic (DAST) analysis tools are integrated directly into our CI/CD pipelines.
- Bug Bounty Program: We maintain a private bug bounty program to incentivize responsible disclosure from the security research community.
6. Incident Response
SoftGen maintains a comprehensive Incident Response Plan (IRP) that is tested and updated regularly. In the event of a security incident, our dedicated Security Operations Center (SOC) team acts immediately to contain, investigate, and remediate the issue.
We are committed to transparent communication and will notify affected customers within 48 hours of discovering a confirmed data breach, as required by applicable laws and SLAs.