Enterprise-Grade Security Certified
Operated By
OwnTrip OPC Pvt. Ltd.
Sahorachak, Jehanabad BR, India-804427
Phone: +91-96671-99771
Email: support@owntrip.co.in
Security Contact: Rahul Kr. Sharma
1. Our Security Commitment
At Workforce Management System, we understand that your employee data is one of your most valuable assets. We are committed to implementing and maintaining industry-leading security practices to protect your information against unauthorized access, disclosure, alteration, and destruction.
Our security program complies with the Information Technology Act, 2000, IT (Reasonable Security Practices and Procedures) Rules, 2011, and the Digital Personal Data Protection Act, 2023.
2. Security Practices
While we are a growing organization, we are committed to implementing robust security practices aligned with industry standards:
Compliance Ready
Full compliance with Information Technology Act 2000, IT Rules 2011, and DPDP Act 2023.
Data Encryption
TLS 1.3, AES-256 encryption for data at rest and in transit.
Access Control
Role-based access control with multi-factor authentication capabilities.
Infrastructure
Multi-zone cloud deployment with automated backups and disaster recovery.
Vulnerability Management
Regular security audits, penetration testing, and vulnerability assessments.
Continuous Improvement
Actively pursuing industry certifications and security best practices.
3. Data Encryption
3.1 Encryption in Transit
All data transmitted between your devices and our servers is encrypted using:
- TLS 1.3 Protocol: Latest Transport Layer Security for web communications
- 256-bit SSL Certificates: Extended validation certificates from trusted authorities
- Perfect Forward Secrecy: Unique session keys that cannot be compromised retroactively
- HTTPS Strict Transport Security (HSTS): Enforced secure connections
3.2 Encryption at Rest
All stored data is encrypted using:
- AES-256 Encryption: Military-grade encryption for database storage
- Encrypted File Systems: OS-level encryption on all storage volumes
- Encrypted Backups: All backup data encrypted before storage
- Key Management: Hardware Security Modules (HSM) for encryption key protection
3.3 Biometric Data Protection
Biometric data (fingerprints, facial recognition) receives enhanced protection:
- One-way hashing algorithms (cannot be reverse-engineered)
- Stored as mathematical representations, not actual images
- Separate encrypted database with restricted access
- Automatic deletion upon account termination
4. Infrastructure Security
4.1 Cloud Infrastructure
Our platform is hosted on enterprise-grade cloud infrastructure:
- Multi-Zone Deployment: Redundant servers across multiple data centers in India
- DDoS Protection: Advanced threat detection and mitigation
- Firewall Protection: Web Application Firewall (WAF) with real-time threat intelligence
- Intrusion Detection: 24/7 monitoring for suspicious activities
- Load Balancing: Distributed traffic to prevent single points of failure
4.2 Data Centers
Our data is stored in secure, certified data centers located in India:
- ISO 27001 certified facilities
- 24/7 physical security and surveillance
- Biometric access controls
- Redundant power and cooling systems
- Fire suppression systems
- Regular third-party security audits
4.3 Network Security
- Network segmentation and isolation
- Virtual Private Cloud (VPC) architecture
- Regular penetration testing
- Vulnerability scanning and patching
- Security Information and Event Management (SIEM)
5. Application Security
5.1 Secure Development Practices
We follow industry best practices in software development:
- Secure Coding Standards: OWASP Top 10 compliance
- Code Reviews: Peer review of all code changes
- Security Testing: Automated and manual security testing
- Dependency Scanning: Regular checks for vulnerable libraries
- Container Security: Hardened Docker containers with minimal attack surface
5.2 Authentication and Authorization
- Multi-Factor Authentication (MFA): Optional 2FA via SMS/email/authenticator app
- Strong Password Policy: Minimum 8 characters with complexity requirements
- Password Hashing: bcrypt with high-cost factor
- Session Management: Secure tokens with automatic timeout
- Role-Based Access Control (RBAC): Granular permissions by user role
- OAuth 2.0: Industry-standard authorization for API access
5.3 API Security
- Rate limiting to prevent abuse
- API key authentication with restrictions
- Request validation and sanitization
- Response encryption
- Comprehensive logging and monitoring
6. Access Controls
6.1 Employee Access
Our employees have limited access to customer data:
- Principle of Least Privilege: Access granted only when necessary
- Background Checks: All employees undergo security clearance
- Confidentiality Agreements: Legal non-disclosure obligations
- Access Logging: All data access is logged and audited
- Regular Training: Mandatory security awareness training
6.2 Administrative Controls
- Segregation of duties
- Change management procedures
- Incident response protocols
- Security policy enforcement
- Regular access reviews and revocations
7. Data Privacy and Protection
7.1 Data Minimization
We collect only the data necessary to provide our services and comply with legal obligations.
7.2 Data Localization
All customer data is stored within India in compliance with data localization requirements. Data is not transferred outside India without explicit consent.
7.3 Data Segregation
Each organization's data is logically segregated using:
- Multi-tenant architecture with strict isolation
- Organization-specific encryption keys
- Database-level access controls
- No data sharing between organizations
8. Backup and Disaster Recovery
8.1 Data Backup
- Automated Backups: Daily incremental, weekly full backups
- Multiple Locations: Backups stored in geographically diverse locations
- Encrypted Storage: All backups encrypted with AES-256
- Retention Policy: 30-day rolling backup retention
- Regular Testing: Quarterly restore tests to verify integrity
8.2 Business Continuity
- High Availability: 99.9% uptime SLA
- Failover Systems: Automatic switching to backup systems
- Disaster Recovery Plan: Documented procedures with RPO < 1 hour, RTO < 4 hours
- Regular Drills: Annual disaster recovery testing
9. Monitoring and Incident Response
9.1 24/7 Monitoring
- Real-time security event monitoring
- Automated alerting for suspicious activities
- Performance and availability monitoring
- Log aggregation and analysis
- Threat intelligence integration
9.2 Incident Response
We maintain a comprehensive incident response plan:
- Immediate Detection: Automated systems detect anomalies
- Rapid Response Team: Dedicated security team on call 24/7
- Containment: Immediate isolation of affected systems
- Investigation: Root cause analysis and forensics
- Notification: Customer notification within 72 hours as required by law
- Remediation: Corrective actions and preventive measures
10. Vulnerability Management
- Regular Scanning: Weekly automated vulnerability scans
- Penetration Testing: Annual third-party security audits
- Bug Bounty Program: Rewards for responsible disclosure
- Patch Management: Critical patches applied within 24 hours
- Security Updates: Regular platform updates and improvements
11. Third-Party Security
We carefully vet all third-party vendors:
- Security assessments before engagement
- Contractual security obligations
- Data Processing Agreements (DPA)
- Regular audits of vendor compliance
- Limited access with strict controls
12. Mobile Application Security
- Code obfuscation to prevent reverse engineering
- Certificate pinning to prevent man-in-the-middle attacks
- Biometric authentication support
- Secure local storage with encryption
- Regular security updates via app stores
13. User Security Best Practices
We recommend the following practices for our users:
- Enable two-factor authentication
- Use strong, unique passwords
- Do not share login credentials
- Log out after using shared devices
- Report suspicious activities immediately
- Keep software and apps updated
- Verify email authenticity before clicking links
- Review account activity regularly
14. Audit and Compliance
- Internal Audits: Quarterly security audits
- External Audits: Annual third-party audits
- Compliance Reviews: Regular reviews of legal compliance
- Certifications: Maintained and renewed annually
- Documentation: Comprehensive security documentation
15. Security Training and Awareness
All employees undergo:
- Security awareness training during onboarding
- Annual refresher training
- Phishing simulation exercises
- Role-specific security training
- Security policy acknowledgment
16. Reporting Security Issues
We encourage responsible disclosure of security vulnerabilities:
Security Contact
Security Team
Email: support@owntrip.co.in
Subject: [SECURITY] Description of issue
Phone: +91-96671-99771
Contact: Rahul Kr. Sharma
Response Time: We acknowledge security reports within 24 hours and provide updates within 72 hours.
Responsible Disclosure Guidelines
- Report vulnerabilities privately before public disclosure
- Provide detailed information about the vulnerability
- Allow reasonable time for remediation (typically 90 days)
- Do not access or modify user data beyond what's necessary to demonstrate the vulnerability
- Do not perform attacks that could harm availability
17. Regulatory Compliance
Workforce Management System complies with:
Information Technology Act, 2000
IT Rules, 2011
DPDP Act, 2023
Payment and Settlement Systems Act, 2007
Companies Act, 2013
RBI Guidelines
18. Continuous Improvement
We are committed to continuously improving our security posture through:
- Regular risk assessments
- Security roadmap and investments
- Adoption of emerging security technologies
- Participation in security communities
- Customer feedback integration
- Industry best practice adoption
19. Transparency and Trust
We believe in transparency regarding our security practices:
- Regular security updates to customers
- Annual security reports
- Incident disclosure when required
- Public security documentation
- Open communication channels
20. Questions and Support
For any security-related questions or concerns, please contact:
OwnTrip OPC Pvt. Ltd.
Security Team
Sahorachak, Jehanabad BR, India-804427
Phone: +91-96671-99771
Email: support@owntrip.co.in
Website: https://owntrip.co.in
Our Security Promise:
We are committed to protecting your data with the highest standards of security. Your trust is our most valuable asset, and we work tirelessly to maintain it through robust security practices, continuous improvement, and transparent communication.