Skip to content
AnithraSolutions
Trust Centre

Everything your security review is about to ask for.

Gathered in one place so vendor onboarding takes days rather than months. If something you need is not here, ask — we would rather send it than have you infer it.

ISO 27001 alignedSOC 2 Type II controlsGDPR & UK GDPRDPDP Act 2023PCI DSS alignedWCAG 2.2 AA
Security posture

Six control domains.

Described at the level a reviewer can assess rather than the level a brochure can assert.

Information security management

  • ISMS aligned to ISO/IEC 27001 with an annual management review
  • SOC 2 Type II control coverage across production environments
  • Documented risk register reviewed quarterly by the leadership group
  • Security policies acknowledged by every employee at onboarding and annually

Access control

  • Single sign-on with mandatory phishing-resistant multi-factor authentication
  • Least privilege by default; production access is time-boxed and justified
  • Quarterly access reviews with automatic revocation on role change or exit
  • All privileged actions logged to an append-only audit trail

Infrastructure & data

  • TLS 1.2+ in transit, AES-256 at rest, keys managed in a dedicated KMS
  • Segregated development, staging and production environments
  • Infrastructure defined as code, peer-reviewed, with no manual production changes
  • Backups encrypted, replicated cross-region, and restore-tested quarterly

Secure development

  • Mandatory peer review; no direct commits to protected branches
  • SAST, dependency and secret scanning enforced in continuous integration
  • Threat modelling for every new service or material architecture change
  • Annual independent penetration testing with remediation tracked to closure

Monitoring & response

  • Centralised logging with alerting on anomalous access and error-budget burn
  • 24×7 on-call rotation with a documented escalation path
  • Incident response plan tested at least annually with a tabletop exercise
  • Post-incident reviews shared with affected clients within 10 working days

People

  • Background verification appropriate to role and jurisdiction before start
  • Security and privacy training at onboarding and annually thereafter
  • Confidentiality obligations that survive the end of employment
  • Documented joiner, mover and leaver process with asset and access recovery
Certifications & frameworks

Where we stand, stated precisely.

We distinguish between 'certified', 'aligned' and 'in progress', because conflating them is how vendors lose trust at exactly the wrong moment.

ISO/IEC 27001

Aligned; certification programme in progress

Full ISMS operating with documented Statement of Applicability.

SOC 2 Type II

Control coverage in place

Security, availability and confidentiality criteria across production.

UK GDPR & EU GDPR

Compliant

DPA available with IDTA and SCCs annexed. Article 30 records maintained.

DPDP Act 2023 (India)

Compliant

Consent framework, grievance officer and data-principal rights implemented.

PCI DSS

Aligned (SAQ-A scope)

Card data handled entirely by certified processors; we never store PANs.

WCAG 2.2 Level AA

Substantially conformant

Independently audited; see the Accessibility Statement for exceptions.

Commitments

Service levels.

Contractual where a signed SLA is in place, and targets otherwise.

Production uptime commitment
99.9% monthly, with service credits
P1 incident acknowledgement
15 minutes, 24×7
P1 target resolution
4 hours
P2 acknowledgement
1 business hour
Breach notification to clients
Within 24 hours of confirmation
Regulator notification
Within 72 hours where required
Data subject request acknowledgement
72 hours
Sub-processor change notice
30 days
Documentation

What we can send you.

Most of it goes out the same day. NDA items need a mutual NDA in place first, which we can turn around in 24 hours.

  • Data Processing Agreement (with SCCs & IDTA)On request
  • Security whitepaperUnder NDA
  • Penetration test executive summaryUnder NDA
  • SOC 2 Type II reportUnder NDA
  • Certificate of insuranceOn request
  • Business continuity & DR plan summaryUnder NDA
  • Standard security questionnaire (CAIQ / SIG Lite)Pre-completed
  • Sub-processor listPublished
Responsible disclosure

Found something? Tell us.

We will not pursue legal action against researchers acting in good faith within this policy.

Report vulnerabilities to security@anithrasolutions.com. Include the affected asset, reproduction steps and impact. A PGP key is available on request.

Our commitments

  • Acknowledgement within 1 business day
  • Triage and severity assessment within 5 days
  • Regular updates until resolution
  • Public credit if you would like it

Please do not

  • Access, modify or exfiltrate other people's data
  • Run denial-of-service or volumetric tests
  • Use social engineering against our staff or clients
  • Publish before we have had a chance to fix it

Related reading: Privacy Policy, Sub-processors and Accessibility Statement.

Need something for your vendor review?

Send us the questionnaire. We keep pre-completed CAIQ and SIG Lite responses on file and can usually return a bespoke one within three business days.

Prefer email? sales@anithrasolutions.com · We reply within one business day