Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted (AES-256) by the storage in your environment, under keys you control.
Fragiliti runs entirely within your own infrastructure. Your data stays in your environment - we don't host, store or back it up.
We have no standing access to your data. You control authentication, RBAC and SSO inside your deployment; MFA and least privilege govern our own systems.
Dependency scanning, peer code review, OWASP-aligned development and annual third-party penetration testing of the product.
A documented process for issuing security advisories and patches to on-premises customers.
Working towards SOC 2 Type II. Aligned to the DPDP Act 2023, GDPR and CCPA.
Fragiliti is delivered as software that you deploy and operate inside your own environment (on-premises or your private cloud). The data you load and everything the platform computes stays within your infrastructure at all times. Much of the computation runs in the browser and on servers you control - Fragiliti operates no hosted, multi-tenant service that holds your data.
Security is therefore shared: you secure the environment Fragiliti runs in, and we secure the software we ship and the systems we run.
| You are responsible for | Fragiliti is responsible for |
|---|---|
| Hosting, servers, network and firewall configuration | Secure software development lifecycle (SDLC) |
| Encryption at rest, key management and storage | Vulnerability scanning and patching of the product |
| Backups, retention and disaster recovery | Security advisories and hardening guidance |
| Identity, SSO, RBAC and user provisioning | Security of our own corporate systems and website |
| Physical security and data residency | Support under your enterprise agreement |
Your data never leaves your environment. Fragiliti does not receive, host or store the data you work with. We have no access to it unless you explicitly grant time-limited access for a specific support engagement.
| Layer | Method |
|---|---|
| Data in transit | TLS 1.2 or higher for connections within your deployment. TLS 1.0 and 1.1 are disabled. |
| Data at rest | AES-256 supported; performed by the storage in your environment, under keys you manage. |
| Backups | Configured and controlled by you; we provide guidance and tooling. |
| Data residency | Determined entirely by your environment - your data stays wherever you host it. |
| Framework / Regulation | Status | Notes |
|---|---|---|
| SOC 2 Type II | โณ In Progress | Controls aligned to the SOC 2 Trust Service Criteria; audit in preparation. |
| ISO 27001 | โณ Aligned | Controls aligned; formal certification planned. |
| India DPDP Act 2023 | โ Aligned | Applies to the limited personal data we process (enquiries, sales and support). Your platform data stays in your environment. |
| EU GDPR | โ Aligned | Data-subject rights honoured for the personal data we hold. |
| CCPA (California) | โ Aligned | We do not sell or share personal data; rights honoured. |
| India IT Act 2000 | โ Aligned | Reasonable security practices per Section 43A and the SPDI Rules 2011. |
| CERT-In Directions 2022 | โ Aligned | Incident-reporting procedures in place for our own systems. |
Because your platform data resides in your environment, you own incident response for your own infrastructure. Fragiliti's incident response covers vulnerabilities in the product and incidents affecting our own systems or website:
Full details of our incident response process are available to enterprise customers on request.
If you discover a security vulnerability in Fragiliti, please disclose it responsibly via our Vulnerability Disclosure Policy.
Email: contact@fragiliti.com with subject line "Security Disclosure".
We do not pursue legal action against researchers who follow responsible disclosure guidelines and act in good faith.