Security
Security and confidentiality, described honestly
We describe controls we actually operate and commitments we are willing to put into a contract. We do not claim certifications we do not hold.
Access control
- Least-privilege access aligned to the agreed scope
- Client-owned accounts wherever systems allow it
- Multi-factor authentication where the system supports it
- Access reviewed on joiner, mover and leaver events
Confidentiality
- Company-level and individual confidentiality undertakings
- Need-to-know handling of client information
- Controlled file sharing through approved channels
- No reuse of client material outside the engagement
Device and workspace
- Supervised delivery workspace
- Screen-lock and clear-desk practices
- Controls on removable media and unauthorised copying
- Restrictions on personal messaging channels for client data
Incident response
- Defined internal reporting route for suspected incidents
- Prompt notification to the client contact
- Containment, investigation and corrective actions
- Documented lessons learned
Contractual protection
- Non-disclosure agreement before detailed discussions
- Data-processing agreement where personal information is involved
- Appropriate contractual transfer documentation where required
- Agreed data-return and deletion procedure at exit
People and training
- Onboarding briefing on confidentiality and data handling
- Role-specific process training
- Refresher training and periodic reminders
- Supervision by a named delivery lead
Summary
Baseline operating controls
- Role-based access
- Multi-factor authentication where supported
- Least-privilege access
- Confidentiality and NDA controls
- Controlled file sharing
- Documented retention and deletion
- Incident escalation procedures
- Approved software and device controls
- Client-defined access restrictions
- Regular access review
Outsourcebar Private Limited does not currently claim ISO 27001, SOC 2 or any equivalent certification. Security measures are agreed per engagement and recorded in the applicable contract and service schedule.
Where UK or European personal information is accessed from India, an appropriate contractual transfer mechanism is agreed with the client before access is granted. Clients remain responsible for determining a lawful basis and an appropriate transfer arrangement for personal information they provide or make accessible.
Security enquiry
Ask a security or data-protection question
Send due-diligence questions, security questionnaires or data-processing queries and we will respond with documented answers.
Tell us which part of your operation needs more capacity.
Share your current workload, business objective or service challenge. We will review the requirement and propose an appropriate delivery structure.