Skip to content
Security & assurance

We are not certified yet. Check us anyway.

AONE does not hold ISO/IEC 27001 today — we are implementing it, and we will not describe ourselves as certified until a certificate exists with a number we can print. What follows is everything you would examine if we did hold it: the layers, the lifecycle, the controls, and the evidence we can put in front of your assessor for each one.

6 hrCERT-In reportingIncident process built to the window
180 dLog retentionHeld within Indian jurisdiction
0Shared admin accountsEvery action attributable to a person
100%Privileged actions loggedImmutable, reconstructable
Where we actually stand

Status, stated without spin.

Held means a certificate exists. In progress means it does not. Aligned means we design and build to the standard but claim no third-party attestation.

In progress

ISO/IEC 27001 — Information security management

Our information security management system is being implemented against the standard. We are not certified, and we will not describe ourselves as certified until a certificate is issued and its number appears in this row.

In progress

ISO 9001 — Quality management

Quality management processes are being documented against the standard ahead of assessment. Not certified today.

Aligned

OWASP ASVS & Top 10

Application controls are designed against the OWASP Application Security Verification Standard, and the Top 10 categories form part of our code review checklist.

Aligned

CERT-In directions — incident reporting & log retention

Incident handling is built to the six-hour reporting window, and systems retain logs for the required 180-day period within Indian jurisdiction.

Aligned

Digital Personal Data Protection Act, 2023

Personal data handling, purpose limitation, retention and data-principal request routes are designed to the Act. A named contact handles requests.

Aligned

GIGW — Government website guidelines

Public-facing government surfaces are built to the Guidelines for Indian Government Websites, including accessibility and multilingual requirements.

Per engagement

Independent VAPT

Vulnerability assessment and penetration testing is performed by an independent party rather than by us. Where procurement requires a CERT-In empanelled auditor, we engage one.

If certification is a hard gate in your procurement, say so at the first conversation. We would rather tell you the timing does not work than waste a bid cycle for both of us.

Defence in depth

Seven layers, and the question each one gets asked

Security layers and the assessment question for eachSeven layers from identity through to audit, with what we build at each and the question a vendor assessment asks about it.LAYERWHAT WE BUILDWHAT AN ASSESSOR ASKSIdentityL1Named accounts only, MFA on all privileged access,joiner-mover-leaver processWho can log in, and how fast can you revoke them?AccessL2Role-based control, least privilege by default, time-boundelevation with approvalCan an engineer read production data today?DataL3TLS in transit, encryption at rest, managed key stores,stated residency and retentionWhere does our data live, and for how long?ApplicationL4Input validation, output encoding, dependency and secretscanning on every buildHow do you find a vulnerable dependency before we do?InfrastructureL5Environment separation, infrastructure as code, noproduction data downstreamIs your staging environment using our real records?MonitoringL6Centralised logging, alerting on privileged and anomalousactivity, retention to policyWould you notice a breach, or would we tell you?AuditL7Immutable records of privileged and record-affectingactions, queryable per subjectReconstruct what happened on this date, for thisuser.
The right-hand column is not rhetorical. These are the questions institutional procurement actually sends, and a firm that has answered them before answers them in a day rather than a month.
Secure development

Controls in the pipeline, not in a policy document

Security controls across the development lifecycleThreat modelling at design, automated scanning on every commit, a human security review before release, least-privilege deployment, and continuous monitoring in operation.EVERY RELEASEDesignThreat model beforethe first line of codeBuildDependency, secret andstatic analysis on commitRELEASE GATEReviewA person signs off thesecurity review. Noexceptions for deadlines.DeployLeast-privilege pipeline,no human credentialsOperateMonitoring, alertingand patch cadenceRUNS ON EVERY COMMITNone of these are periodic audits. They run inthe pipeline, and a failure blocks the mergerather than raising a ticket somebody closeslater.Dependency scanBLOCKINGSecret scanBLOCKINGStatic analysisBLOCKINGLicence checkREPORTED
The release gate is a person, not a pipeline stage that can be skipped with a flag. It is the same design position we take on AI output entering a public record.
Data

Who can reach your data, at which point

Data lifecycle and who can access it at each stageData moves through collection, transit, storage, processing, retention and deletion. The access band beneath shows who can reach it at each stage: the client at collection, named individuals under time-bound approval while in use, and nobody at rest or after deletion. All stages sit inside the agreed residency boundary.RESIDENCY BOUNDARYAgreed in writing per engagement · Indian jurisdiction for government work01CollectedAt the sourcePurpose stated,minimum fields02In transitMovingTLS 1.2+ everywhere03At restStoredEncrypted, managedkeys04In useProcessedRBAC, time-boundelevation05RetainedHeldContractual retentionclock06DeletedGoneVerified erasure,certificate on requestWHO CAN REACH ITCLIENTat sourceNO ACCESSencrypted / erasedNO ACCESSencrypted / erasedAPPROVEDsecond-person sign-offAPPROVEDsecond-person sign-offNO ACCESSencrypted / erasedClient / data subjectNamed, time-bound, loggedNobody
Access is not a single policy statement — it changes stage by stage. Nobody holds standing access to data at rest; in-use access is named, time-bound and requires a second person to approve it.
Controls register

Every control, and the evidence behind it.

This is the page's actual argument. A certificate says a third party saw evidence once. This names the artefact we will put in front of your assessor, control by control.

AreaControlEvidence we can produce
AccessEvery account is attributable to a named individual; no shared credentials exist.Account inventory with owner, role and last review date.
AccessProduction access is time-bound and requires approval from a second person.Elevation request log showing requester, approver, scope and expiry.
AccessLeavers are de-provisioned across all systems as part of exit.Offboarding checklist with per-system sign-off.
DataData residency and retention are agreed in writing before build begins.Signed data-handling schedule attached to the engagement contract.
DataNo production data is copied into development or staging environments.Environment configuration and seeded-data generation scripts.
DataDeletion is verified rather than assumed, and can be certified on request.Deletion procedure and completion record per data set.
ApplicationDependency and secret scanning block the merge; they do not raise a ticket.Pipeline configuration and a sample of blocked builds.
ApplicationSecurity review by a person is a required gate before any production release.Release records showing reviewer and date for each deployment.
InfrastructureInfrastructure is defined as code; console changes are exceptions that get reviewed.Repository history and drift-detection output.
InfrastructureSecrets live in managed key stores, never in source control.Key store inventory and repository scan history.
MonitoringPrivileged and record-affecting actions are logged immutably and retained to policy.Log schema, retention configuration and a worked query.
ResponseIncidents follow a defined severity model with agreed response targets.Incident runbook, on-call roster and past post-mortems where disclosable.
When it goes wrong

Nobody believes “it won’t break”.

They believe a firm that has published its severity model, its response targets and what it does in the first hour. These are our standard targets; a contract may set tighter ones.

DefinitionResponseUpdates
S1CriticalSystem unavailable, data at risk, or a security incident in progress. Includes any suspected breach of personal data.30 minutesHourly, until resolved
S2MajorCore function unavailable or materially degraded for a significant share of users, with no workaround.2 hoursEvery 4 hours
S3MinorA function is impaired, but a workaround exists and normal operation continues.1 working dayDaily
S4LowCosmetic or non-urgent, scheduled into the normal delivery cycle.3 working daysOn change
What we commit to
  • A suspected security incident is treated as S1 until proven otherwise, not after it is confirmed.
  • Reportable incidents are notified to CERT-In within the six-hour window their directions require.
  • Affected clients are told what we know, when we know it — including while the picture is still incomplete.
  • Every S1 produces a written post-mortem covering cause, timeline, impact and the change that prevents recurrence.
  • Post-mortems are blameless in tone and specific in content. A vague one is not accepted internally.

Send us your vendor assessment

We keep our answers current between engagements rather than assembling them per request, so a completed questionnaire comes back with the proposal instead of three weeks later. Send it with your first enquiry.

Questions we get asked

The awkward ones, answered first.

Are you ISO 27001 certified?
No. We are implementing an information security management system against the standard and intend to certify, but we do not hold the certificate today and will not imply otherwise. Everything on this page describes controls that are in place now, and we will evidence any of them on request. If certification is a hard gate in your procurement, tell us early and we will tell you honestly whether the timing works.
Then why should we trust your security posture?
Because you can check it. The controls register on this page names the evidence we can produce for each control — access logs, pipeline configuration, elevation records, retention schedules. A certificate is a third party asserting that such evidence existed on the day they looked. We are offering to show you the evidence directly.
Can you complete our vendor security questionnaire?
Yes, and quickly. We keep answers current between engagements rather than assembling them per request. Send it with your first enquiry and it comes back with the proposal, not three weeks later.
Who can access our production data?
By default, nobody. Production access is time-bound, requires approval from a second person, and every elevation is logged with requester, approver, scope and expiry. Where an engagement requires standing access for named individuals, they are named in the contract.
Where is our data stored?
Wherever the engagement requires, stated in writing before build begins and honoured in the deployment topology. For legislative and government data that means Indian jurisdiction. We are equally happy to deploy into your own cloud tenancy so the data never sits in an account we control.
Do you carry out penetration testing?
We coordinate it rather than perform it on our own work — marking your own homework is not assurance. Where your procurement requires a CERT-In empanelled auditor, we engage one and share the report and remediation record with you.
What happens if you are breached?
A suspected incident is treated as critical from the first minute rather than after confirmation. You are told what we know while we still know very little, CERT-In is notified inside the six-hour window, and a written post-mortem follows covering cause, timeline, impact and the specific change that prevents recurrence.
Start here

Let’s build what’s next.

Tell us where your business wants to grow. In one conversation we will show you where AI and software will pay back first, and whether we are the right team to build it.

  • 30 minutes, free, no obligation
  • A clear, practical recommendation
  • Your ideas and data kept confidential
+91 9274 57 58 59Talk to us directly
Businesses & enterprises

Book a free strategy call

We look at your goals, your current systems and your biggest time and cost drains, then recommend the first AI or software move with the fastest payback.

Book my strategy call
Public sector

Request a briefing

A working session on your requirement, our reference deployments and a capability statement.

Public sector