|Trust CentreSecurity & compliance, transparently.
How Hipla protects your data — our certifications, security controls, subprocessors and policies, all in one place.
Last updated 5 October 2026
Compliance & certifications
SOC 2 Type II
CertifiedIndependently audited controls for security, availability and confidentiality.
ISO 27001 : 2022
CertifiedISMS certified to ISO/IEC 27001:2022 by OSS Certification Services (ASCB accredited). Certificate MS-A:9419920923-1, recertified 30 Sep 2026, valid to 29 Sep 2027 subject to annual surveillance.
GDPR
CompliantCompliant with EU General Data Protection Regulation.
DPDPA India
CompliantSafeguards for data protection as per DPDPA
Security controls
Data Protection8/8 operational▾
All traffic secured with TLS 1.2+.
Data encrypted at rest with AES-256.
Encryption keys are managed in AWS Key Management Service, access-controlled through IAM and rotated on a defined schedule.
API keys and application secrets are stored in AWS Secrets Manager and are never placed in source code, configuration or logs.
Information is classified across four tiers (Public, Internal, Confidential, Restricted) with handling rules for each.
Retention periods are defined per data type; visitor data defaults to 3 years and is customer-configurable.
Customer data is securely deleted within 30 days of contract termination, with confirmation on request.
All Indian-deployment data is hosted in the AWS Asia Pacific (Mumbai) region, keeping data in India.
Access Control7/7 operational▾
SAML/OIDC SSO for enterprise customers.
Multi-factor authentication required for all staff.
Access follows role-based least-privilege; users receive only the access their role requires.
Cloud (IAM) and application access is formally reviewed every six months and findings tracked to closure.
Enforced minimum length, complexity, history, rotation and lockout across all accounts.
Privileged access is restricted to named individuals, protected by MFA, via bastion hosts, and logged.
Access is provisioned, adjusted and revoked promptly as people join, change role or leave.
Infrastructure7/7 operational▾
24/7 monitoring and alerting across systems.
Production is isolated from non-production; databases and internal services are not exposed to the internet.
AWS GuardDuty provides continuous, intelligent threat detection across the environment.
AWS CloudTrail maintains a tamper-evident audit trail of API and account activity.
Security patches are applied on severity-based SLAs, tested before release, with rollback.
CrowdStrike endpoint protection is deployed on company devices and kept current.
Company devices are enrolled in Esper MDM with encryption, lock and remote-wipe.
Governance7/7 operational▾
Third-party pen tests performed annually.
An ISO/IEC 27001:2022-aligned ISMS governs the security programme, under Group CISO oversight.
Formal risk assessment and treatment is run at least annually and on significant change.
All staff complete security-awareness training at induction and at least annually.
Suppliers are risk-assessed and bound by data-protection agreements; sub-processors are published.
Changes are assessed, approved by a change board and implemented with rollback.
A defined IR process applies; customers are notified within 24h and regulators within 72h of a confirmed breach.
Application Security6/6 operational▾
Security is built into every phase of development, with threat modelling and quality gates.
SonarQube runs on every code change and blocks merges with high or critical findings.
Third-party dependencies are continuously scanned against CVE data and remediated to SLA.
Every change is peer-reviewed before merge; direct pushes to protected branches are blocked.
Findings are scored on CVSS and remediated within severity-based SLAs, then retested.
Internet-facing endpoints are protected by AWS WAF against common web attacks.
Resilience4/4 operational▾
The database and compute tiers run Multi-AZ on AWS with automatic failover.
A documented BCP covers critical services with defined recovery objectives, tested regularly.
A DR plan defines RTO/RPO and is validated through an annual failover drill.
Automated encrypted backups with point-in-time recovery; restores are tested annually.
Privacy4/4 operational▾
Personal data is processed in line with India's DPDP Act 2023 and the GDPR where applicable.
A documented process handles access, correction, erasure and portability requests within 30 days.
A lawful-basis / data-processing register documents each processing activity and its basis.
Staff are background-verified before joining and bound by confidentiality agreements.
Documents & reports
Policy Pack - Control Register
RegistersBusiness Continuity Plan (HBI-PLN-01 v5.0)
PlansData Processing Agreement
LegalStandard DPA for customers.
Disaster Recovery Plan (HBI-PLN-02 v1.0)
PlansIncident Management Plan (HBI-PLN-03 v6.0)
PlansInformation Security Policy (HBI-POL-01 v5.0)
PoliciesData Privacy Policy (HBI-POL-02 v6.0)
PoliciesAccess Control Policy (HBI-POL-03 v1.0)
PoliciesSubprocessors
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure hosting | USA / EU |
| Cloudflare | CDN and DDoS protection | Global |
Frequently asked questions
Where is my data stored?▾
All data is hosted in the AWS Asia Pacific (Mumbai) region, keeping your data resident in India. Backups also remain in India.
Do you support SSO?▾
Yes, SAML and OIDC SSO are available on enterprise plans.
How do I report a vulnerability?▾
Email support@hipla.io with details. We aim to respond within 24 hours.
Is my data encrypted?▾
Yes. All data is encrypted in transit with TLS 1.2+ and at rest with AES-256, using keys managed in AWS KMS.
What certifications and compliance standards do you meet?▾
Hipla operates an ISO/IEC 27001:2022-aligned information security management system and complies with India's DPDP Act and with GDPR where EU personal data is processed.
Do you perform independent penetration testing?▾
Yes. Independent third-party testing of our web, mobile and API surfaces is performed at least annually and before major releases, with findings tracked to closure.
How quickly will you notify me of a data breach?▾
We notify affected customers without undue delay, within 24 hours of confirming a personal-data breach.
What is your disaster recovery capability?▾
We maintain a documented business-continuity and disaster-recovery plan with defined recovery objectives, encrypted backups, Multi-AZ replication, and point-in-time recovery.