1. Our approach to security
Subhx Infotech OPC Pvt Ltd (“Subhx”, “we”, “us” or “our”) treats the security of the SubhX Nexus platform (the “Service”) and the data within it as fundamental. We apply security by design and defence in depth, and we keep our controls proportionate to the sensitivity of HR and payroll data. This page describes the measures we maintain; it forms part of our Data Processing Agreement.
2. Hosting and infrastructure
- The Service is hosted on managed cloud infrastructure located in India, operated by a reputable cloud-hosting provider that maintains recognised security and availability certifications for its data centres.
- Production systems run within isolated network segments, with firewalls and security groups restricting traffic to only what is required.
- Administrative access to infrastructure is limited to authorised personnel and protected by strong authentication.
- We separate production environments from development and testing environments.
3. Encryption
- Data transmitted between you and the Service is protected in transit using TLS (HTTPS).
- Data at rest in our primary databases and object storage is protected using industry-standard encryption.
- Particularly sensitive identifiers — such as government IDs used for KYC and certain provider secrets — are additionally encrypted at the application layer and access to them is restricted and audit-logged.
4. Access control and authentication
- User sign-in uses one-time passcodes (OTP) or supported single sign-on, and the Service supports role-based access controls so organisations can apply least-privilege within their workspace.
- Each organisation's data is logically isolated, and access checks are enforced on the server so that users can only reach data within their own organisation.
- Internal access by Subhx personnel to customer data is restricted to those with a legitimate need, granted on a least-privilege basis, and subject to confidentiality obligations.
- Administrative actions are logged to support accountability and investigation.
5. Application security
- We follow secure-development practices, including code review and dependency management, and we apply rate limiting and input validation to guard against common web vulnerabilities.
- Uploaded files are validated by type and size, scanned for malware, and stored privately so they can only be retrieved by authorised users.
- We apply security patches to the application and its dependencies on a risk-prioritised basis.
6. Monitoring and logging
We monitor the Service for availability, errors and unusual activity, and we retain operational and security logs to help us detect, investigate and respond to incidents. Error and performance monitoring may be supported by trusted providers described in our Sub-processors list, configured to limit the data they receive to what is needed.
7. Backups and resilience
- We take regular backups of production databases and store them securely so that we can recover from data loss or corruption.
- We periodically review our ability to restore from backups.
- Our architecture aims for high availability, and we work to minimise single points of failure within practical limits.
8. Incident response
We maintain processes to identify, assess and respond to security incidents. On confirming a personal-data breach affecting customer data, we will notify the affected customer without undue delay and provide the information reasonably available to us to help them meet their obligations under applicable law, as set out in our Data Processing Agreement. We conduct a review after significant incidents to reduce the chance of recurrence.
9. Personnel and organisational measures
- Personnel with access to customer data are bound by confidentiality obligations and receive guidance on their data-protection and security responsibilities.
- We apply joiner, mover and leaver controls so that access is granted and revoked appropriately as roles change.
- We maintain internal policies covering acceptable use, access management and incident handling, and we review them periodically.
11. Reporting a vulnerability
We welcome responsible disclosure. If you believe you have found a security vulnerability in the Service, please report it to us promptly at support@subhx.in with enough detail to reproduce the issue, and avoid accessing or modifying data that does not belong to you. We will acknowledge legitimate reports and work to address confirmed issues in a timely manner. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and remediate it.
12. Contact
For any question about our security practices, or to request available security documentation, please contact us using the details below.
Subhx Infotech OPC Pvt Ltd
- Product
- SubhX Nexus
- support@subhx.in
- Jurisdiction
- India