Trust Center

Security Compliance Overview

๐Ÿ”„ Last updated: 21 June 2026
Our commitment: Fragiliti is currently deployed on-premises, inside your own environment. Your data never leaves it. This page explains how we secure the software we ship and our own systems, and how security responsibilities are shared with you.

Security at a Glance

๐Ÿ”

Encryption

Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted (AES-256) by the storage in your environment, under keys you control.

๐Ÿข

Deployment model

Fragiliti runs entirely within your own infrastructure. Your data stays in your environment - we don't host, store or back it up.

๐Ÿ”‘

Access control

We have no standing access to your data. You control authentication, RBAC and SSO inside your deployment; MFA and least privilege govern our own systems.

๐Ÿ›ก๏ธ

Vulnerability management

Dependency scanning, peer code review, OWASP-aligned development and annual third-party penetration testing of the product.

๐Ÿšจ

Advisories & patches

A documented process for issuing security advisories and patches to on-premises customers.

๐Ÿ“‹

Compliance

Working towards SOC 2 Type II. Aligned to the DPDP Act 2023, GDPR and CCPA.

Deployment & Shared Responsibility

Fragiliti is delivered as software that you deploy and operate inside your own environment (on-premises or your private cloud). The data you load and everything the platform computes stays within your infrastructure at all times. Much of the computation runs in the browser and on servers you control - Fragiliti operates no hosted, multi-tenant service that holds your data.

Security is therefore shared: you secure the environment Fragiliti runs in, and we secure the software we ship and the systems we run.

You are responsible forFragiliti is responsible for
Hosting, servers, network and firewall configurationSecure software development lifecycle (SDLC)
Encryption at rest, key management and storageVulnerability scanning and patching of the product
Backups, retention and disaster recoverySecurity advisories and hardening guidance
Identity, SSO, RBAC and user provisioningSecurity of our own corporate systems and website
Physical security and data residencySupport under your enterprise agreement

Data Security

Your data never leaves your environment. Fragiliti does not receive, host or store the data you work with. We have no access to it unless you explicitly grant time-limited access for a specific support engagement.

LayerMethod
Data in transitTLS 1.2 or higher for connections within your deployment. TLS 1.0 and 1.1 are disabled.
Data at restAES-256 supported; performed by the storage in your environment, under keys you manage.
BackupsConfigured and controlled by you; we provide guidance and tooling.
Data residencyDetermined entirely by your environment - your data stays wherever you host it.

Access Control

Your data

Fragiliti's own systems

Vulnerability Management

Organisational Security

Compliance Status

Framework / RegulationStatusNotes
SOC 2 Type II โณ In Progress Controls aligned to the SOC 2 Trust Service Criteria; audit in preparation.
ISO 27001 โณ Aligned Controls aligned; formal certification planned.
India DPDP Act 2023 โœ“ Aligned Applies to the limited personal data we process (enquiries, sales and support). Your platform data stays in your environment.
EU GDPR โœ“ Aligned Data-subject rights honoured for the personal data we hold.
CCPA (California) โœ“ Aligned We do not sell or share personal data; rights honoured.
India IT Act 2000 โœ“ Aligned Reasonable security practices per Section 43A and the SPDI Rules 2011.
CERT-In Directions 2022 โœ“ Aligned Incident-reporting procedures in place for our own systems.

Incident Response

Because your platform data resides in your environment, you own incident response for your own infrastructure. Fragiliti's incident response covers vulnerabilities in the product and incidents affecting our own systems or website:

Full details of our incident response process are available to enterprise customers on request.

Reporting a Security Issue

If you discover a security vulnerability in Fragiliti, please disclose it responsibly via our Vulnerability Disclosure Policy.

Email: contact@fragiliti.com with subject line "Security Disclosure".

We do not pursue legal action against researchers who follow responsible disclosure guidelines and act in good faith.