Security & Compliance

Last updated: August 2026

Wittier Software Solutions designs and builds websites, web apps, platforms and brands for clients in India and around the world. We understand that when you trust us with a project, you often trust us with sensitive information — your data, your customers’ data, and your commercial knowledge. This page sets out the security, confidentiality and data-protection practices we follow on every engagement.

1. Confidentiality & NDA

We treat all client information as confidential. We are happy to sign a Non-Disclosure Agreement (NDA) — either ours or your own — before any sensitive information is shared. Access to client information within our team is limited to the people working on your project.

2. Data Protection & Privacy

We handle personal data in line with recognised data-protection principles — lawful and limited collection, purpose limitation, security, and respect for the rights of data subjects. Our practices are aligned with:

  • India — Digital Personal Data Protection (DPDP) Act, 2023
  • European Union — GDPR principles, for clients and users in the EU/UK
  • Australia — the Australian Privacy Principles (APPs), for clients and users in Australia

Where we process personal data on your behalf, we do so only on your documented instructions, and we are willing to enter into a Data Processing Agreement (DPA) that reflects your regulatory requirements.

3. Information Security

  • All websites and applications we deliver are served over HTTPS / TLS encryption.
  • Data is encrypted in transit, and encrypted at rest on the reputable cloud and hosting providers we use.
  • Role-based access control and strong authentication (including multi-factor authentication where supported) protect the systems we manage.
  • Credentials and secrets are stored securely and never committed to source code.

4. Secure Development Practices

  • All work is version-controlled, with a clear change history and review before release.
  • We follow secure-coding practices to guard against common vulnerabilities (e.g. injection, cross-site scripting, insecure access control).
  • We keep frameworks, libraries and dependencies up to date and apply security patches.
  • Sensitive configuration is separated from code and managed through protected environment settings.

5. Reliability & Continuity

  • Regular, automated backups of the systems and data we host or manage.
  • Documented deployment and hand-over, so your project is never dependent on a single individual.
  • Ongoing support, patching and a clear change-management process for the solutions we maintain.

6. Sub-processors & Hosting

Where a project relies on third-party platforms (for example cloud hosting, email delivery, analytics or payment providers), we use established, reputable providers and select data-centre regions appropriate to your requirements. We will disclose the relevant sub-processors used for your project on request.

7. Formal Certifications

Wittier is a specialist software and digital studio. Where a project requires alignment with a specific standard or framework, or a formal audit, we will work with you and, if needed, qualified partners to meet those requirements. For most engagements, the practices described on this page — together with an NDA and, where applicable, a signed DPA — provide the assurance our clients need. We are glad to complete a client security questionnaire on request.

8. Requesting Our Compliance Statement

If your procurement or security team needs a written security and data-protection statement, an NDA, a DPA, or a completed vendor security questionnaire, we are happy to provide it. Please contact us and we will respond promptly.

Contact

Wittier Software Solutions
Email: contact@wittier.in
Phone: +91 866 039 9438
Address: No. 2, 3rd Cross, 5th Block, Nandini Layout, Bangalore - 560096, India

This statement describes our current practices and is provided for information. It does not, by itself, create contractual obligations; project-specific terms are set out in the agreements signed for each engagement.