Overview
Weblinear Technologies LLP is committed to safeguarding your business data. This document describes the technical and organizational measures we implement to protect the confidentiality, integrity, and availability of information processed through the Weblinear ERP platform.
Our security program is designed around the principle of defense in depth, applying multiple layers of protection across infrastructure, application, and operational domains.
Encryption
We apply strong encryption standards to protect data at every stage:
- Data at Rest: All database volumes, file storage, and backups are encrypted using AES-256. Encryption keys are managed through hardware security modules (HSM).
- Data in Transit: All network communication between clients, APIs, and internal microservices is secured via TLS 1.3 with Perfect Forward Secrecy.
- Key Management: Encryption keys are rotated on a regular schedule and are never stored alongside the data they protect.
Infrastructure Security
The Weblinear ERP platform is hosted on enterprise-grade cloud infrastructure (AWS / Google Cloud) within data centers that maintain SOC 2 Type II and ISO 27001 certifications.
- All compute resources operate within isolated Virtual Private Clouds (VPC) with no direct public internet exposure
- Network access is controlled through security groups and firewall rules following the principle of least privilege
- DDoS mitigation is provided through managed protection services
- Infrastructure is provisioned through immutable, version-controlled deployments
Application Security
Security is integrated into our software development lifecycle:
- Code Review: All code changes undergo mandatory peer review before deployment
- Vulnerability Scanning: Automated static (SAST) and dynamic (DAST) security analysis is performed on every release
- Dependency Management: Third-party libraries are continuously monitored for known vulnerabilities
- Multi-Tenancy: Strict data isolation between organizations is enforced at the database level through row-level security policies
Access Control
- Role-Based Access Control (RBAC): Administrators can define granular permissions for each user within their organization
- Authentication: JWT-based authentication with short-lived access tokens and secure HTTP-only refresh token rotation
- Audit Logging: All user actions and data mutations are recorded in tamper-resistant audit logs, including IP address, timestamp, and user identity
- Session Management: Sessions are invalidated on password change and can be revoked by administrators
Business Continuity
- Backups: Point-in-time recovery backups are taken at 15-minute intervals and stored in geographically separate locations
- Recovery Objectives: We target a Recovery Time Objective (RTO) of less than 2 hours and a Recovery Point Objective (RPO) of less than 15 minutes
- Redundancy: Critical system components are deployed across multiple availability zones to ensure continued operation during infrastructure failures
Compliance
Weblinear Technologies LLP maintains internal compliance programs aligned with ISO/IEC 27001 standards. Our infrastructure providers hold SOC 2 Type II, ISO 27001, and PCI DSS certifications. We undergo periodic third-party security assessments and provide audit access for enterprise-tier subscribers upon request.
Incident Reporting
If you discover a security vulnerability or suspect unauthorized access to your data, please report it immediately to support@weblinear.in. We investigate all reported incidents promptly and will notify affected customers in accordance with applicable law.