Data Security & Compliance Policy
This Data Security & Compliance Policy outlines the security principles, operational controls, and governance practices applied across APPHOX products, cloud services, enterprise software, and digital platforms.
APPHOX Technologies Pvt. Ltd. ("APPHOX", "Company", "we", "our", or "us") is committed to protecting customer data, maintaining information security, and operating its technology platforms in accordance with recognized security and compliance practices.
This Data Security & Compliance Policy outlines the security principles, operational controls, and governance practices applied across APPHOX products, cloud services, enterprise software, and digital platforms.
1. Company Information
APPHOX Technologies Pvt. Ltd.
Website: https://www.apphoxtech.com
Security Contact: security@apphoxtech.com
2. Scope
This Policy applies to all APPHOX platforms and services, including but not limited to:
- Prime360 ERP
- Cortex360 HRMS
- TailorEx360
- Equidae360
- AgroNova360
- Poultrix360
- CRM Solutions
- Finance Solutions
- Procurement Solutions
- Warehouse Management
- Fleet Management
- Document Management
- AI Platforms
- Cloud Applications
- Mobile Applications
- APIs
- Customer Portals
- Managed IT Services
3. Our Security Principles
APPHOX's information security program is built around the following core principles:
- Confidentiality
- Integrity
- Availability
- Accountability
- Privacy by Design
- Secure by Design
- Least Privilege Access
- Continuous Risk Management
- Operational Resilience
These principles guide the design, development, deployment, and operation of all APPHOX solutions.
4. Data Protection
APPHOX implements technical and organizational safeguards to protect customer information throughout its lifecycle.
Security measures may include:
- Encryption of data in transit using TLS/SSL
- Encryption of sensitive data at rest where applicable
- Role-Based Access Control (RBAC)
- Multi-factor authentication support
- Secure authentication mechanisms
- Audit logging
- Session management
- Secure credential handling
- Backup and recovery procedures
5. Identity & Access Management
Access to APPHOX systems is governed through identity and access controls designed to ensure that only authorized individuals can access information appropriate to their responsibilities.
Controls may include:
- User authentication
- Role-based permissions
- Least privilege access
- Session expiration
- Password security policies
- Administrative access controls
- Account lifecycle management
6. Infrastructure Security
APPHOX deploys its platforms using secure cloud and enterprise infrastructure.
Security practices include:
- Network segmentation
- Firewalls
- Secure cloud architecture
- Infrastructure monitoring
- Secure VPN access where applicable
- Environment separation
- Production access controls
- Operating system hardening
7. Application Security
Security is integrated throughout the software development lifecycle.
Practices may include:
- Secure software design
- Code review
- Dependency management
- Vulnerability remediation
- API security controls
- Input validation
- Authentication and authorization testing
- Logging and monitoring
APPHOX continuously improves application security practices as technology evolves.
8. Artificial Intelligence Security
APPHOX develops AI-powered capabilities across multiple enterprise platforms.
To support responsible AI deployment:
- AI features are designed to assist decision-making rather than replace professional judgment.
- Access to AI capabilities is governed by user permissions.
- AI outputs should be independently reviewed before being relied upon for business-critical decisions.
- Customer business data is not used to train publicly available AI models without explicit authorization.
9. Data Privacy
APPHOX processes personal information in accordance with its Privacy Policy and applicable data protection laws.
Privacy principles include:
- Data minimization
- Purpose limitation
- Lawful processing
- Transparency
- Appropriate retention
- Secure disposal
10. Backup & Disaster Recovery
APPHOX implements backup and recovery processes designed to support business continuity.
Depending on the deployment model, measures may include:
- Scheduled backups
- Secure backup storage
- Disaster recovery planning
- Recovery testing
- Data restoration procedures
Recovery objectives may vary based on customer agreements and service plans.
11. Incident Management
APPHOX maintains processes for identifying, investigating, managing, and responding to security incidents.
Incident response activities may include:
- Detection and assessment
- Containment
- Investigation
- Recovery
- Root cause analysis
- Preventive improvements
Where required by applicable law or contractual obligations, affected customers may be notified of qualifying security incidents.
12. Compliance & Regulatory Alignment
APPHOX strives to align its information security and data protection practices with applicable laws and recognized industry standards, including, where relevant:
- Digital Personal Data Protection Act, 2023 (India)
- Information Technology Act, 2000 (India)
- General Data Protection Regulation (GDPR) principles
- Industry-recognized information security practices
- Applicable contractual and regulatory requirements
Unless expressly stated, references to standards reflect alignment of practices and should not be interpreted as certification or accreditation.
13. Customer Responsibilities
Customers also play an important role in protecting information.
Customers are encouraged to:
- Maintain secure passwords.
- Enable multi-factor authentication where available.
- Keep user devices updated.
- Manage user permissions responsibly.
- Protect API credentials and access tokens.
- Report suspected security incidents promptly.
- Regularly review user access rights.
14. Third-Party Providers
APPHOX may use trusted third-party providers to support infrastructure and service delivery.
Where third-party providers are engaged, APPHOX seeks to work with organizations that maintain appropriate security and compliance practices.
Customers remain responsible for reviewing the terms and privacy practices of third-party services integrated into their own environments.
15. Security Reporting
Customers, partners, and researchers who identify potential security vulnerabilities are encouraged to report them responsibly.
Reports may be submitted to:
📧 security@apphoxtech.com
APPHOX will review reported issues and take appropriate action.
16. Continuous Security Improvement
Security is an ongoing process.
APPHOX continuously evaluates and enhances its:
- Security architecture
- Infrastructure
- Development practices
- Monitoring capabilities
- Operational controls
- Employee awareness
- Risk management processes
to address evolving technologies and emerging threats.
17. Policy Updates
APPHOX may revise this Policy periodically to reflect changes in legal requirements, technology, security practices, or business operations.
Updated versions become effective upon publication on the website unless otherwise stated.
18. Contact Us
For security or compliance enquiries, please contact:
Information Security Team
APPHOX Technologies Pvt. Ltd.
📧 Security: security@apphoxtech.com
📧 Privacy: privacy@apphoxtech.com
📧 General Enquiries: info@apphoxtech.com
🌐 Website: https://www.apphoxtech.com