[{"_id":"6a3b968d5b5032995b11006a","widgetName":"Controls","isVisible":true,"isEditable":true,"config":{"categories":[{"title":"Infrastructure","blurb":"Hardened, redundant cloud infrastructure across regions.","icon":"🔒","bg":"#EBF2FF","items":[{"label":"Data hosted on AWS & Azure","description":"Production workloads run on Amazon Web Services and Microsoft Azure in data centres, with logical multi-tenant isolation between customers."},{"label":"Encryption at rest","description":"All customer data encrypted at rest using AES-256."},{"label":"Encryption in transit","description":"TLS 1.2 (strong ciphers) and TLS 1.3 enforced on every connection."},{"label":"Redundancy & high availability","description":"Redundant information processing facilities and multi-AZ deployment ensure continuity of service in the event of system failure."}]},{"title":"Product Security","blurb":"Controls that protect the application and customer data in use.","icon":"🔒","bg":"#EBF2FF","items":[{"label":"Audit logging","description":"User and system activity is logged and retained to support traceability and investigation."},{"label":"Strong authentication","description":"SSO and Multi-Factor Authentication (MFA) enforced for access to applications and resources; passwords governed by group policy."},{"label":"Service-level commitment","description":"Availability and recovery commitments backed by an RTO of 4 hours and RPO of 1 hour."},{"label":"Secure coding","description":"Application code is developed in line with a formal Secure Coding Policy and OWASP best practices, with code review and vulnerability scanning across the development lifecycle."}]},{"title":"Data Security","blurb":"How customer data is stored, segregated, and protected.","icon":"🔒","bg":"#EBF2FF","items":[{"label":"Multi-tenant isolation","description":"Logical tenant separation using unique identifiers ensures one customer's data is never shared with another within our SaaS environment."},{"label":"Data masking","description":"Sensitive PII such as identifiers is masked at the code level, with masking offered as a configurable feature for customers based on their requirements."},{"label":"Information deletion","description":"Data no longer required is securely and permanently deleted from all storage media and backups are performed as contractually agreed."},{"label":"Workstation encryption","description":"Workstation hard drives are encrypted using BitLocker, FileVault and LUKS."}]},{"title":"Network & Application Security","blurb":"Defences that guard against external and internal threats.","icon":"🔒","bg":"#EBF2FF","items":[{"label":"Web application firewall","description":"Cloudflare WAF monitors and restricts network traffic to applications operating in our cloud infrastructure."},{"label":"Threat detection & monitoring","description":"Prisma Cloud continuously monitors network activity for security anomalies, integrated with PagerDuty for automated alerting."},{"label":"Vulnerability & penetration testing","description":"A CERT-IN empaneled third party conducts external vulnerability assessment and penetration testing semi-annually, with findings tracked to closure."},{"label":"Secure remote access","description":"Remote access to network infrastructure is secured through an encrypted VPN tunnel (GlobalProtect)."},{"label":"Data leakage prevention","description":"DLP measures, endpoint protection (Cortex XDR), and disabled USB ports prevent unauthorized disclosure or transfer of sensitive data."}]},{"title":"Identity & Access","blurb":"Controls governing who can access what, and how.","icon":"🔒","bg":"#EBF2FF","items":[{"label":"Multi-factor authentication","description":"SSO and MFA are enforced for access to applications, resources, and cloud infrastructure."},{"label":"Privileged access management","description":"Production, database, and OS access is granted only through Teleport (PAM), with one-hour access windows, session logging, and screen recording."},{"label":"Role-based access & least privilege","description":"Access is provisioned on a least-privilege, role-based basis, authorized by department heads, with permissions denied by default."},{"label":"Periodic access reviews","description":"Periodic user access reviews and cloud-infrastructure access reviews validate that access remains appropriate to role."}]},{"title":"Resilience & Recovery","blurb":"How service and data are protected against disruption.","icon":"🔒","bg":"#EBF2FF","items":[{"label":"Data backup","description":"Database backups are taken regularly and retained on a tiered schedule, with point-in-time recovery enabled for 48 hours."},{"label":"Recovery objectives","description":"Darwinbox maintains a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour."},{"label":"Business continuity & disaster recovery","description":"A formal BCP/DR plan is maintained, with BCP/DR drills and data restoration tests conducted semi-annually and reviewed by senior management."}]},{"title":"Secure Development","blurb":"How the application is built and changed safely.","icon":"🔒","bg":"#EBF2FF","items":[{"label":"Secure development lifecycle","description":"Our SDLC incorporates threat modelling, code review, vulnerability scanning, and penetration testing across development stages, with development, testing, and production environments separated."},{"label":"Change management","description":"A formal change management process governs planning, development, testing, and implementation, with all change requests registered, assigned, and tracked in Jira."},{"label":"Incident management","description":"Security incidents are logged, triaged, and resolved, with resolution comments documented and status tracked to closure."}]}]},"created_on":"2026-06-24T08:34:21.907Z","updated_on":"2026-06-26T12:14:20.544Z","__v":0},{"_id":"6a3b968d5b5032995b110072","widgetName":"Hero","isVisible":true,"isEditable":true,"config":{"orbitNodes":[],"showOrbit":true},"created_on":"2026-06-24T08:34:21.968Z","updated_on":"2026-06-28T07:48:45.883Z","__v":0},{"_id":"6a3b968e5b5032995b110079","widgetName":"Compliances","isVisible":true,"isEditable":true,"config":{"items":[{"id":"cert-1782457441944","short":"ISO 27001:2022","name":"ISO 27001:2022","body":"BSI","desc":"Information Security Management System (ISMS)","icon":"ribbon-star","url":"","logoUrl":"/trustapi/widgets/logo/1782464911228-ISO_27001V1.png","svg":"","group":"Certification","status":"active"},{"id":"cert-1782457473223","short":"ISO 27701:2019","name":"ISO 27701:2019","body":"BSI","desc":"Privacy Information Management System (PIMS)","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782457575745","short":"ISO 9001:2015","name":"ISO 9001:2015","body":"BSI","desc":"Quality Management System","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782457621777","short":"ISO 27017:2015","name":"ISO 27017:2015","body":"BSI","desc":"Cloud Security","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782457645273","short":"ISO 27018:2019","name":"ISO 27018:2019","body":"BSI","desc":"PII on Cloud","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782457801070","short":"SOC 2 Type II","name":"SOC 2 Type II","body":"KPMG","desc":"SOC 2 Type II  independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782457810626","short":"SOC 1 Type II","name":"SOC 1 Type II","body":"KPMG","desc":"SOC 1 Type II  independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782457904300","short":"GDPR - General Data Protection Regulation, Regulation (EU)","name":"GDPR - General Data Protection Regulation, Regulation (EU)","body":"EY","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477289542","short":"Thailand - Personal Data Protection Act, B.E. 2562 (2019)","name":"Thailand - Personal Data Protection Act, B.E. 2562 (2019)","body":"","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477404465","short":"Philippines - Data Privacy Act of 2012 - Republic Act No. 10173","name":"Philippines - Data Privacy Act of 2012 - Republic Act No. 10173","body":"","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477495298","short":"Indonesia - Personal Data Protection Law, Law No. 27 of 2022","name":"Indonesia - Personal Data Protection Law, Law No. 27 of 2022","body":"","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477525896","short":"Singapore - Personal Data Protection Act 2012","name":"Singapore - Personal Data Protection Act 2012","body":"","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477546305","short":"Malaysia - Personal Data Protection Act 2010","name":"Malaysia - Personal Data Protection Act 2010","body":"","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477586385","short":"Dubai - DIFC Data Protection Law","name":"Dubai - DIFC Data Protection Law","body":"","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477615157","short":"China - Personal Information Protection Law","name":"China - Personal Information Protection Law","body":"","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477732319","short":"CCPA/CPRA - California Consumer Privacy Act of 2018 and California Privacy Rights Act of 2020","name":"CCPA/CPRA - California Consumer Privacy Act of 2018 and California Privacy Rights Act of 2020","body":"","desc":"Independent assurance report","icon":"ribbon-star-2","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"},{"id":"cert-1782477924243","short":"ISO/IEC 42001:2023","name":"ISO/IEC 42001:2023","body":"TUV","desc":"Artificial Intelligence Management System standard","icon":"ribbon-star","url":"","logoUrl":"","svg":"","group":"Certification","status":"active"}]},"created_on":"2026-06-24T08:34:22.128Z","updated_on":"2026-08-17T10:08:18.068Z","__v":0},{"_id":"6a3b968e5b5032995b11007c","widgetName":"TrustedBy","isVisible":true,"isEditable":false,"created_on":"2026-06-24T08:34:22.150Z","updated_on":"2026-06-24T08:34:22.150Z","__v":0},{"_id":"6a3b968e5b5032995b11007f","widgetName":"Resources","isVisible":true,"isEditable":false,"created_on":"2026-06-24T08:34:22.161Z","updated_on":"2026-06-24T08:34:22.161Z","__v":0},{"_id":"6a3b968e5b5032995b110082","widgetName":"FAQ","isVisible":true,"isEditable":true,"config":{"items":[{"q":"How do I get a copy of SOC 1 and SOC 2 report?","a":"Request access via the Documents tab and accept the NDA when prompted; our team typically approves within one business day, after which the document is available to download."},{"q":"Where is my data stored?","a":"You choose your hosting region during onboarding. Darwinbox operates in India, Singapore, US, Frankfurt, Jakarta, UAE. with data residency guarantees per region."},{"q":"Do you support single sign-on?","a":"Darwinbox supports both SAML 2.0 and OpenID Connect (OIDC) for Single Sign-On (SSO) integration with major identity providers. SCIM provisioning and Multi-Factor Authentication (MFA) are also supported to enable secure identity and access management."},{"q":"How are vulnerabilities handled?","a":"Darwinbox performs continuous internal security testing prior to every release and engages CERT-In empaneled security firms to conduct independent VAPT on a semi-annual basis. Identified vulnerabilities are prioritized based on risk and remediated within defined SLAs."}]},"created_on":"2026-06-24T08:34:22.167Z","updated_on":"2026-08-17T23:28:25.698Z","__v":0},{"_id":"6a3b968e5b5032995b110085","widgetName":"Subprocessors","isVisible":true,"isEditable":true,"config":{"items":[{"name":"Amazon Web Services, Inc.","purpose":"Cloud Service Provider","location":"Mumbai, Singapore, North Virginia, Frankfurt, Jakarta, UAE.","logo":"AWS"},{"name":"Microsoft Azure","purpose":"Cloud Service Provider","location":"Central India, Singapore, Frankfurt, UAE, East US.","logo":"Azure"},{"name":"Sendgrid, Inc.","purpose":"Email Campaign Service","location":"United States","logo":"Sendgrid"},{"name":"MongoDB, Inc. (Atlas)","purpose":"Cloud hosting service for MongoDB","location":"United States.","logo":"MongoDB"},{"name":"Microsoft Office 365","purpose":"Email, SharePoint & Security services","location":"India","logo":"O 365"}]},"created_on":"2026-06-24T08:34:22.173Z","updated_on":"2026-08-17T10:17:10.228Z","__v":0}]