DRC Infotech LLP

Security, privacy & responsible AI

How we protect your systems and data across every engagement — access management, data handling, incident response, our use of subcontractors, and exactly how we use AI in delivery. Written plainly, for your due-diligence team.

Firewall-protected infrastructure Need-to-know access Clean-data policy Zero material breaches to date
01 — Access & endpoints

Internal security controls

Access to client environments is granted only to authorised team members on a need-to-know basis. Our controls cover people, devices and code:

  • Role-based access control (RBAC) based on project responsibilities.
  • Our own firewall-protected infrastructure enforcing user-wise access controls across the network.
  • Company-managed endpoint protection — antivirus/endpoint security and regular OS updates.
  • Strong password policies and secure password management.
  • Encrypted communication — HTTPS, VPN and encrypted channels where applicable.
  • Separated development, testing and production environments wherever practical.
  • Source code held in secure version-control repositories with controlled access.
02 — Governance

Policies & compliance

DRC Infotech LLP maintains a set of written internal policies, and signs the necessary confidentiality, data-privacy and IP-protection agreements before work begins.

Information Security Confidentiality & NDA Access Control Password Management Secure Software Development Data Protection & Privacy Acceptable Use of Systems
03 — Data residency

Data access, processing & storage

Our engineering team is primarily located in Surat, Gujarat, India. Team members may work remotely using secured devices and authenticated access. Here is how client data is handled:

  • Client systems are accessed only by authorised project personnel.
  • Client data is processed only to deliver the contracted services.
  • Where possible, data stays within client-controlled infrastructure or infrastructure the client designates.
  • We do not retain client production data longer than required for project delivery.
Prefer that no data touches our infrastructure?

We can work directly inside your environment via secure remote access (VPN or remote desktop), subject to your security policies and IP allow-listing. All work then happens within your own systems — so your team can monitor developer activity whenever you need. Our own infrastructure is firewall-protected for every project by default.

04 — Third parties

Subcontractors & third parties

Project delivery is generally performed by DRC Infotech LLP employees. We take on subcontracting engagements only when the client agrees that the assigned resources will work exclusively from our premises.

  • Every project is covered by agreements for security, confidentiality, data privacy and IP protection.
  • On completion, we follow a clean-data policy — all client data is securely removed from our systems per the agreed terms.
05 — Response

Incident response & notification

We generally do not store or retain confidential data from live production environments — wherever possible we develop and test using demo, dummy or anonymised data. In the unlikely event we identify or suspect a security incident involving our premises, infrastructure or servers, we act immediately:

01

Contain & engage

Initiate our response process and notify our appointed third-party cybersecurity team to investigate.

02

Notify the client

Inform the affected client without unnecessary delay.

03

Explain the impact

Set out the nature and potential impact of the incident clearly.

04

Remediate & prevent

Provide a remediation plan and the preventive measures put in place.

06 — Track record

Past incidents & breach history

0
Material security incidents or data breaches to date. Because we generally do not retain client data during development — using demo, dummy or test data and credentials wherever possible — our exposure is minimised by design.
  • If a client authorises live data for a specific purpose, we store only the minimum required, only for the approved duration.
  • Once work completes or the data is no longer needed, it is securely removed per our data-retention and clean-data policies.
07 — Responsible AI

Use of AI in delivery

Our developers are permitted to use generative AI and coding assistants where appropriate, to improve productivity, code quality and efficiency — always under clear controls. Approved tools:

Claude Code — coding assistant Cowork Agent — coding assistant Google Gemini — generative AI
  • Client code and confidential information are treated as confidential at all times.
  • Client code, confidential information or data will not be entered into public or non-approved AI services without prior written authorisation from the client.
  • All AI-generated output is reviewed by a qualified engineer before use.
  • Client obligations and contractual confidentiality requirements always take precedence over AI usage.
  • AI is used as an engineering assistant only — never a replacement for professional judgement or security review.

Need a completed security questionnaire?

Share your vendor assessment or DDQ and our team will complete it, along with any NDAs or data-processing agreements you require.

Talk to our team