1. Security Overview
GoNexel employs a defence-in-depth approach to data security, combining multiple layers of protection — encryption, access controls, network security, monitoring, and incident response — to safeguard client data and business operations.
Security is embedded in every layer of our operations — from infrastructure to employee training. We follow industry best practices and pursue ISO 27001 certification (expected 2026).
2. Encryption Standards
| Data State | Standard | Protocol |
|---|---|---|
| Data in Transit | SSL/TLS 1.2+ | HTTPS enforced on all endpoints |
| Data at Rest | AES-256 | Full-disk and database encryption |
| Key Encryption | RSA-2048 | AWS KMS for key management |
| Backups | AES-256 | Encrypted before transfer and storage |
| Passwords | bcrypt with salt | Industry-standard hashing |
3. Access Controls
3.1 Role-Based Access Control (RBAC)
- Principle of Least Privilege: Employees are granted minimum access necessary for their role
- Role Definitions: Owner → Admin → Manager → Developer → Support → Read-Only
- Access Reviews: Quarterly reviews of all access permissions
- Immediate Revocation: Access revoked within 24 hours of role change or termination
3.2 Authentication
- Multi-Factor Authentication (MFA): Required for all administrative access
- Password Policy: Minimum 12 characters, complexity requirements, 90-day rotation
- Session Management: Automatic timeout after 30 minutes of inactivity
- API Access: Secured with API keys, OAuth 2.0, JWT tokens
4. Infrastructure Security
4.1 Cloud Infrastructure
- Hosting: AWS Mumbai region (ap-south-1), India
- Firewall: AWS Security Groups and WAF (Web Application Firewall)
- DDoS Protection: Cloudflare and AWS Shield
- Network Segmentation: VPC isolation between environments (production, staging, development)
- Geo-Compliance: Primary data residency in India, compliant with Indian data protection laws
4.2 Network Security
- IDS/IPS: Intrusion detection and prevention systems active 24/7
- Logging: All access and events logged and retained for 90 days
- Monitoring: 24/7 automated monitoring with real-time alerting
5. Vulnerability Management
| Activity | Frequency | Scope |
|---|---|---|
| Automated Scanning | Weekly | All production systems |
| Penetration Testing | Annually | Full infrastructure and applications |
| Code Review | Every deployment | All application code |
| Dependency Audit | Monthly | All third-party libraries and packages |
| Security Patches | Within 48 hours | Critical patches applied immediately |
6. Incident Response
6.1 Response Process
- Detection: Monitoring systems, employee reports, or client notification
- Classification: Severity assessment (Critical / High / Medium / Low)
- Containment: Isolate affected systems to prevent spread
- Investigation: Root cause analysis by the security team
- Remediation: Implement fixes, patch vulnerabilities, restore services
- Notification: Inform affected clients, authorities, and stakeholders
- Post-Incident Review: Lessons learned and preventive measures documented
6.2 Notification Timelines
Clients: Within 24 hours of confirmed breach, via email to registered contact.
EU Authorities: Within 72 hours as required by GDPR.
Indian Authorities: As required under applicable Indian data protection laws.
7. Backup & Disaster Recovery
- Backup Frequency: Daily automated backups (incremental); weekly full backups
- Storage: Geographically distributed across multiple AWS availability zones
- Encryption: All backups encrypted with AES-256 before transfer
- Retention: Minimum 90 days of backup history
- Recovery Time Objective (RTO): 24 hours
- Recovery Point Objective (RPO): 24 hours
- Testing: Quarterly disaster recovery drills with documented outcomes
8. Compliance & Certifications
| Framework | Status | Details |
|---|---|---|
| ISO 27001 | In Progress | Expected certification by end of 2026 |
| PCI DSS | Compliant | Payment card data handled by certified payment processors |
| GDPR | Compliant | Full compliance for EU customers. See GDPR Policy |
| CCPA | Compliant | California Consumer Privacy Act compliance |
| SOC 2 | Planned | Planned for 2027 |
9. Employee Security
- Background Checks: All employees undergo background verification before onboarding
- NDA: All employees sign non-disclosure agreements
- Security Training: Mandatory annual security awareness training
- Phishing Tests: Regular simulated phishing exercises
- Secure Development: Developers trained in OWASP Top 10 and secure coding practices
- Offboarding: All access revoked, devices wiped, within 24 hours of termination
10. Client Responsibilities
- Use strong, unique passwords and enable MFA
- Keep software, plugins, and integrations updated
- Report suspected security incidents immediately
- Do not share access credentials with unauthorised parties
- Follow secure coding practices for any custom integrations
- Comply with GoNexel's Acceptable Use Policy
11. Contact
GoNexel Security Team
Email: info@gonexel.com
Subject: "Security Inquiry" or "Security Incident"
Response: Within 4 hours for security incidents
Support Hours: Mon–Fri, 9 AM – 6 PM IST (24/7 for critical incidents)