securityTrust & Security

Protecting Your Online Safety

Softpal runs SaaS products used by millions of people, and security runs through all of them: our people, our processes, and our products. This page explains how we protect customer data across data, operational, and physical security.

Protecting Your Online Safety
check_circle
0AES-256
Data at Rest

Organizational security

Our Information Security Management System (ISMS) sets out our security objectives alongside the risks and mitigations that concern everyone with a stake in the platform. Policies and procedures cover the security, availability, processing, integrity, and confidentiality of customer data.

shield_check Employee background checks

Every employee goes through background verification, carried out by reputed external agencies on our behalf. It covers criminal records, previous employment where applicable, and educational background. Until the check clears, the employee is not assigned work that could put users at risk.

shield_check Security Awareness

New employees sign a confidentiality agreement and acceptable use policy when they join, then train in information security, privacy, and compliance. Tests and quizzes show where their understanding is thin, and role-specific security training follows from there.

Security education continues after induction. Our internal community keeps employees current on the organization's security practices, and internal events raise awareness and surface new ideas in security and privacy.

shield_check Dedicated security and privacy teams

Dedicated security and privacy teams run our security programs. They build and maintain our defenses, set up security review processes, and watch the networks continuously for suspicious activity. They also advise our engineering teams within their domains.

shield_check Internal audit and compliance

A dedicated compliance team reviews Softpal's procedures and policies against the relevant standards and works out which controls, processes, and systems are needed to meet them. The team runs periodic internal audits and coordinates independent audits and assessments by third parties.

shield_check Endpoint security

Every workstation issued to Softpal employees runs an up-to-date OS with anti-virus software, configured to our security standards: properly set up, patched, and tracked through our endpoint management tools. They are secure by default, encrypting data at rest, requiring strong passwords, and locking when idle. Business mobile devices are enrolled in mobile device management so they meet the same standards.

Physical security

shield_check At workplace

Access to buildings, infrastructure, and facilities is controlled through access cards. Employees, contractors, vendors, and visitors each hold cards scoped strictly to the purpose of their visit, with HR defining what each role requires. Access logs are kept so anomalies can be spotted and addressed.

shield_check At Data Centers

At our data centers, a co-location provider handles the building, cooling, power, and physical security while we supply the servers and storage. Only a small group of authorized personnel can enter; anything else goes through a ticket and requires manager approval first. Two-factor and biometric authentication are both required on site. Access logs, activity records, and camera footage are available if an incident needs investigating.

shield_check Monitoring

Entry and exit movements at all business centers and data centers are monitored by CCTV, deployed in line with local regulations. Backup footage is retained for a period that depends on each location's requirements.

Infrastructure security

shield_check Network security

Our network defenses are layered. Firewalls block unauthorized access and unwanted traffic, and systems are segmented into separate networks so sensitive data stays isolated. Testing and development run on a network entirely separate from Softpal's production infrastructure.

Firewall access is monitored on a strict schedule: a network engineer reviews every change daily, and the rules themselves are revised quarterly. Our Network Operations Center team watches infrastructure and applications for discrepancies or suspicious activity, with crucial parameters monitored continuously through our proprietary tooling and alerts triggered whenever the production environment misbehaves.

shield_check Network redundancy

Every component of the platform is redundant. A distributed grid architecture shields the system and services from server failures, so if a server goes down, users keep working and their data stays available.

Multiple switches, routers, and security gateways add device-level redundancy, so no single piece of the internal network can take the whole thing down.

shield_check DDoS prevention

DDoS protection comes from well-established providers. Their mitigation capabilities filter out bad traffic while letting good traffic through, keeping our websites, applications, and APIs available and responsive during attacks.

shield_check Server hardening

Development and testing servers are hardened before use: unused ports and accounts disabled, default passwords removed, and so on. Hardening is built into the base OS image itself, so every server starts from the same secure baseline.

shield_check Intrusion detection and prevention

Intrusion detection draws on host-based signals from individual devices and network-based signals from monitoring points across our servers. Administrative access, privileged commands, and system calls on all production servers are logged, and rules plus machine intelligence over that data warn our security engineers of possible incidents. At the application layer, our proprietary WAF applies both whitelist and blacklist rules.

At the ISP level, defense is layered again: scrubbing, network routing, rate limiting, and filtering handle attacks from the network layer up to the application layer, providing clean traffic, a reliable proxy service, and prompt attack reporting.

Data security

shield_check Secure by design

A change management policy governs every change and new feature, so nothing reaches production without authorization. Our SDLC requires secure coding practices, and code changes are screened for security issues by analyser tools, vulnerability scanners, and human review.

Our application-layer security framework follows OWASP standards and mitigates threats such as SQL injection, cross-site scripting, and application-layer DoS attacks.

shield_check Data isolation

The framework allocates and maintains cloud space for each customer, and service data is logically separated using secure protocols, so no customer's data can ever be reached by another.

When you use our services, your data is stored on our servers, but it remains yours, not Softpal's. We do not share it with any third party without your consent.

shield_check Encryption

In transit: all customer data crossing public networks to our servers is protected by strong encryption. Every connection to our servers, whether web, API, mobile app, or IMAP/POP/SMTP email client, must use Transport Layer Security (TLS 1.2/1.3) with strong ciphers. This authenticates both ends of the connection and encrypts everything transferred.

Encrypted connections support Perfect Forward Secrecy (PFS), so even a future compromise could not decrypt past communications. HTTP Strict Transport Security (HSTS) is enabled on all web connections.

At rest: customer data is encrypted with 256-bit Advanced Encryption Standard (AES). Keys are owned and managed through our in-house Key Management Service (KMS), with data encryption keys themselves encrypted under master keys. Master keys and data keys are stored on separate servers with tightly limited access.

shield_check Data retention and disposal

We hold the data in your account for as long as you use Softpal services. After you terminate your account, the data is deleted from the active database during the next clean-up, which runs every 6 months, and removed from backups 3 months after that. If an unpaid account stays inactive for 120 continuous days, we terminate it, but only after prior notice and a chance to back up your data.

Unusable devices are disposed of by a verified, authorized vendor, and until then they are categorized and stored securely. Data is wiped from devices before disposal: failed hard drives are degaussed and then physically shredded, and failed SSDs are crypto-erased and shredded.

Identity and Access control

shield_check Single Sign-On (SSO)

Single sign-on (SSO) lets users reach multiple services through one sign-in page and one set of credentials. All sign-ins to our services pass through our integrated Identity and Access Management (IAM) service, and we support SAML so customers can connect their own identity provider, such as LDAP or ADFS.

SSO simplifies login, supports compliance, gives effective access control and reporting, and removes the password fatigue that leads to weak passwords.

shield_check Multi-Factor Authentication

Multi-factor authentication adds a verification step beyond the password, something the user has to possess. If a password is compromised, this greatly reduces the chance of unauthorized access. Supported modes currently include biometric Touch ID and Face ID, push notifications, QR codes, and time-based OTP.

shield_check Administrative access

Technical access controls and internal policies stop employees from opening user data at will. We follow least privilege and role-based permissions to keep exposure risk down.

Production access is managed through a central directory and authenticated with strong passwords, two-factor authentication, and passphrase-protected SSH keys. It runs over a separate network with stricter rules and hardened devices, and every operation is logged and audited periodically.

Operational security

shield_check Logging and Monitoring

We monitor and analyze information from services, internal network traffic, and device and terminal usage, recording it as event, audit, fault, administrator, and operator logs. Automated monitoring and analysis surface anomalies such as unusual activity in employee accounts or attempts to reach customer data. The logs live on a secure server isolated from full system access, keeping access control central and the logs themselves available.

shield_check Vulnerability management

A dedicated vulnerability management process scans actively for threats using certified third-party and in-house tools, alongside automated and manual penetration testing. Our security team also reviews inbound security reports and watches public mailing lists, blogs, and wikis for incidents that could touch our infrastructure.

When a vulnerability needs fixing, it is logged, prioritized by severity, and given an owner. We assess the associated risks and track it until it closes, either by patching the affected systems or applying controls.

shield_check Malware and spam protection

All user files pass through our automated scanning system, built to stop malware spreading through the Softpal ecosystem. Our anti-malware engine takes regular updates from external threat intelligence sources and checks files against blacklisted signatures and malicious patterns, with machine learning in the detection engine adding another layer of protection for customer data.

Softpal supports Domain-based Message Authentication, Reporting, and Conformance (DMARC) to prevent spam, using SPF and DKIM to verify that messages are genuine. Our proprietary detection engine also identifies abuse of Softpal services, including phishing and spam activity.

shield_check Backup

Full backups run weekly and incremental backups daily. Backup data stays in the same data center as the original and is encrypted at rest, and we restore and validate backups weekly to confirm they work. Backed up data is retained for three months.

If a customer requests data recovery within the retention period, we restore their data from backup and make it available.

shield_check Disaster recovery and business continuity

Application data lives on resilient storage replicated across data centers, with the primary data center mirrored to the secondary in near real time. If the primary fails, the secondary takes over and operations continue with minimal or no interruption. Both centers connect through multiple ISPs.

Power backup, temperature control, and fire prevention systems provide the physical side of business continuity. Beyond data redundancy, we maintain a business continuity plan covering major operations such as support and infrastructure management.

Incident Management

shield_check Reporting

A dedicated incident management team notifies you of incidents in our environment that affect you, along with any actions you should take. Incidents are tracked and closed with corrective measures, and where applicable we provide the evidence you need. Controls go in place afterwards to stop the same situation recurring.

Security and privacy incidents get high-priority responses. General incidents are announced through our blogs, forums, and social media; incidents affecting a specific user or organization are notified directly by email.

shield_check Breach notification

As data controllers, we notify the relevant Data Protection Authority of a breach within 72 hours of becoming aware of it, as the General Data Protection Regulation (GDPR) requires. We notify customers too where specific requirements call for it, and as data processors we inform the concerned data controllers without undue delay.

Responsible Disclosure

Our Bug Bounty program reaches the security research community and recognizes and rewards their work. We are committed to working with researchers to verify, reproduce, and respond to reported vulnerabilities and to put proper fixes in place.

If you happen to find any, please submit the issues at https://www.softpal.com/.

If you believe any of the policies above have been violated, please tell our Network Abuse department through our online form or at [email protected].

handshake Work With Us

Security is our priority. Yours too?

Questions about our security practices, compliance, or responsible disclosure? Our security team will answer.