Information Security
Our commitment on your Information security
PEOPLE, PROCESS AND PRACTICES
The foundation of our organization’s credibility rests on the Three Pillars of Strength: People, Process, and Practices. These three pillars are tightly intertwined and have been pivotal in shaping our path to success.
Our dedicated team is comprised of highly qualified and experienced professionals who prioritize the utmost confidentiality in all their endeavors. We take pride in our unwavering commitment to maintaining the highest levels of data and information security, as evidenced by our ISO 27001 certification, which guides our processes. Furthermore, our physical infrastructure is designed to facilitate seamless operations while upholding stringent security measures. It’s worth noting that Infiprosol can proudly attest to a spotless record of zero security breaches within our office to date.
People
- Dedicated IT Team for Constant Monitoring
- Responsible & Dependable Employees
- Employee Pool with Deep Knowledge of US Accounting
- Experience on Major Accounting Software
Process
- Employees Hired After Due Background/Reference Checks
- Robust Policies to Safeguard Client Data
- Non-Disclosure Contract at Employment Commencement
- Paperless Operations
Practices
- No Pens-Papers-Printers in the operations area
- Controlled/Limited Internet Access
- Restricted Social Media and E-Commerce websites
- Blocked Access to Personal emails
- Prohibited Mobile Devices of Staff
- Key Card Access-based Restrictions
- 24×7 CCTV Surveillance
- Disabled USB and Data Transfer Devices
- Multi-Layer Authentication
- Strong Firewalls and 256-bit SSL encryption
- Process-defined Access to File Type Download and Access
- Server access on a need-to-know basis
- Monitored Instant Messaging and Email Exchange
Our Certification
ISO 27001:2015 Certification:
Infiprosol has achieved ISO 27001 certification, a globally recognized standard for information security management systems. This certification validates our commitment to ensuring the security of our client's data by implementing robust security controls against unauthorized access, theft, and data loss. To attain this certification, our security measures underwent a rigorous external audit by an independent third-party certification body, ensuring that we not only meet but exceed industry best practices. ISO, the International Organization for Standardization, is a globally respected authority responsible for developing and publishing international standards across diverse industries and sectors.
GDPR Compliance:
Infiprosol is committed to upholding the rigorous standards set forth by the General Data Protection Regulation (GDPR), which serves as a comprehensive framework governing the management of personal data pertaining to European Union residents. Our dedication to GDPR compliance entails the establishment of robust technical and organizational safeguards to protect personal data and preserve the privacy rights of individuals. Our multifaceted approach includes the implementation of data protection policies and procedures, comprehensive staff training in data protection practices, routine security assessments, and the development of well-defined data breach response strategies. Moreover, we have appointed a dedicated Data Protection Officer (DPO) who oversees and ensures the fulfillment of GDPR obligations within our organization.
Data & Network Security
- Each employee has their own distinct username and password to log in to their respective workstations.
- Electronic devices, including mobile phones and PDAs, are strictly prohibited on the production floor, and all USB ports and other media drives have been deactivated to ensure compliance with this policy.
- Ongoing surveillance of internet traffic is conducted, and appropriate measures are implemented in response to any breaches of regulations.
- Access to the local drives of our server are restricted based on the process the employee is assigned to.
- Appropriate backup mechanism is in place to prevent data loss.
- Weekly updating of the anti-virus pattern on every system.
Confidentiality
- Every employee is required to sign a Non-Disclosure Agreement upon joining the company, and any violation of this agreement results in termination of employment.
- Restricted access to internet websites and the same is allowed only if it is a process requirement.
- Continuous monitoring of the web traffic and disciplinary actions are taken for any violation.