Security
Our commitment to protecting your data and systems.
LAST UPDATED: January 2025
01 Security Approach
Security is integrated into every phase of our development lifecycle — from architecture design to deployment and maintenance.
We follow the principle of least privilege, defense in depth, and zero-trust architecture across all systems we build and operate.
02 Data Protection
All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 industry-standard encryption.
Access to client data is restricted to authorized personnel only, with multi-factor authentication and role-based access controls.
03 Compliance & Certifications
We maintain ISO 27001 certification and comply with GDPR, CCPA, and other applicable data protection regulations.
Our infrastructure partners (AWS, Google Cloud) are SOC 2 Type II certified, ensuring enterprise-grade security.
04 Vulnerability Management
We conduct regular security audits, penetration testing, and code reviews to identify and remediate vulnerabilities.
We use automated dependency scanning and SAST/DAST tools in our CI/CD pipelines to catch security issues early.
05 Incident Response
We have a documented incident response plan with defined roles, escalation paths, and communication protocols.
In the event of a security incident, we notify affected clients within 72 hours and provide regular updates until resolution.
06 Reporting a Vulnerability
If you discover a security vulnerability in our systems, please report it responsibly to info@dicetechnosoft.cloud. We acknowledge all reports within 48 hours.