At OntrackSoft, we prioritize the security of your proprietary code and business intelligence. This policy outlines how we handle sensitive information during the software development lifecycle (SDLC) and IT consultancy engagements.
1. Information Architecture
We collect data through multiple channels to facilitate project delivery:
- Project Data: Technical specifications, source code access (GitHub/GitLab), and API credentials provided for development.
- Communication Data: Logs from Slack, Jira, and email used for sprint planning and coordination.
- Telemetry Data: Application logs and performance metrics during the QA and deployment phases.
2. Data Processing & Utilization
Your information is processed strictly for the engineering objectives defined in our Master Service Agreement (MSA):
- Architecture design and full-stack software development.
- Deployment orchestration and cloud infrastructure management.
- Predictive analysis and machine learning model training (using anonymized datasets).
- Technical support and critical system maintenance.
3. Enterprise Security Shield
We employ rigorous security standards to protect your IP:
- Encryption: AES-256 data-at-rest and TLS 1.3 for all data-in-transit.
- Access Control: Zero-Trust architecture with MFA-enforced developer access.
- Vulnerability Management: Continuous CI/CD security scanning and automated dependency audits.
4. Sub-Processors & Partners
To deliver elite tech services, we integrate with industry-leading infrastructure providers:
- Cloud Infrastructure: AWS (US/EU), Google Cloud Platform, and Microsoft Azure.
- SaaS Tools: GitHub, Jira, and Slack for project orchestration.
- Security Providers: Cloudflare (WAF/DDoS) and Auth0 (IAM).
5. Data Ownership & Retention
Upon project completion or termination, OntrackSoft adheres to strict data handoff protocols:
- Source Code: Full transfer of IP to the client as per contract.
- Credentials: Immediate decommissioning of shared keys and access tokens.
- Storage: Deletion of production snapshots and local datasets within 30 days of closure.