Trust Center
At SustainableX, we understand that the confidentiality, integrity, and availability of your ESG data is vital to your business success. We are committed to implementing robust security practices to protect your information.
Our Security Commitment
As a service provider, we prioritize clear information about our security practices, tools, and responsibilities so our customers can feel confident in choosing us as a trusted partner. This Trust Center highlights our steps to identify and mitigate risks, implement best practices, and continuously improve our security posture.
Compliance & Certifications
We are actively working towards achieving industry-recognized security certifications. Our security program is aligned with ISO/IEC 27001:2013 standards, and we are implementing controls to meet SOC 2 requirements.
ISO/IEC 27001:2013
Our information security management system is designed in alignment with ISO 27001 standards for comprehensive security controls.
SOC 2
We are implementing controls to meet SOC 2 Trust Services Criteria for security, availability, and confidentiality.
Security Controls
Our security program includes comprehensive controls across multiple domains to protect your data:
Data Security
Encryption at rest and in transit (AES-256, TLS 1.3)
User subscription tiers (Free, Basic, Pro, Enterprise)
Email verification for account security
Regular access reviews and audits
Data retention and deletion policies
Infrastructure Security
AWS cloud infrastructure (Mumbai region)
Network segmentation and VPC isolation
DDoS protection and WAF
Automated vulnerability scanning
Patch management and system hardening
Application Security
Secure SDLC with code reviews
Dependency vulnerability scanning
Input validation and sanitization
Session management and timeout controls
Security headers and CSP implementation
Operational Security
Incident response procedures
Business continuity and disaster recovery
Employee security training
Third-party vendor assessments
Regular security assessments
Subprocessors
We use the following third-party subprocessors to provide our services. All subprocessors are evaluated for security and compliance before integration.
☁️
AWS
Cloud Infrastructure
Mumbai, India☁️
OpenAI
AI Services
Cloud-based☁️
Anthropic
AI Services
Cloud-based☁️
Google (Gemini)
AI Services
Cloud-based☁️
Groq
AI Services
Cloud-based☁️
xAI
AI Services
Cloud-basedResources & Policies
Access our key policies and documentation:
Have Security Questions?
Contact us at info@sustainablex.in for any security or compliance inquiries.