Document Overview & Enforceability
This document is published under the engineering and governance authority of Yash Kumar Jha, Founder & Chief Solutions Architect of New Age Technology. Please review all terms, data privacy practices, and SLA specifications carefully.
1. Architecture & Infrastructure Security
- Cloud Hosting: Primary infrastructure hosted on tier-1 cloud providers (AWS / Google Cloud / DigitalOcean) across ISO 27001, SOC 2 Type II, and PCI-DSS certified data centers.
- Tenant Isolation: Multi-tenant SaaS architectures implement logical data separation using database-level access controls, row-level security (RLS), and tenant-scoped API token validation.
- Redundancy & High Availability: Automated database backups with point-in-time recovery (PITR) across geographically separated availability zones.
2. Encryption Standards
- Data in Transit: All traffic over public networks is strictly enforced with TLS 1.3 / HTTPS and HTTP Strict Transport Security (HSTS). Unencrypted HTTP traffic is rejected.
- Data at Rest: All application databases, object storage buckets, and automated backups are encrypted using industry-standard AES-256.
- Key Management: Cryptographic keys and secrets are rotated periodically and managed via dedicated hardware-backed Key Management Services (KMS).
3. Application Security & Secure SDLC
- Continuous Integration/Deployment (CI/CD): Automated code scanning pipelines incorporating Static Application Security Testing (SAST) and software dependency vulnerability auditing.
- Vulnerability Remediation: High-severity vulnerabilities and zero-day dependency patches are prioritized for deployment within standard SLA response windows.
- Code Review: Mandatory peer review for every commit merged into production branches.
4. WhatsApp Business API & Webhook Security
- Signature Verification: All incoming webhook payloads from Meta servers require SHA256 HMAC signature verification using secret app keys.
- Zero Payload Persistence (Optional Configuration): Enterprise tier configurations offer ephemeral memory-only message transit, ensuring message bodies are forwarded to client endpoints and immediately purged from RAM.
- Rate Limiting & DDoS Mitigation: Ingress traffic passes through Cloudflare/WAF layers with automated DDoS mitigation and adaptive API rate limiting.
5. Access Control & Operational Governance
- Least Privilege: Internal access to production systems is granted on a strict least-privilege, need-to-know basis.
- MFA Enforcement: Mandatory hardware/app-based Multi-Factor Authentication (MFA) across all administrative tools, cloud consoles, and source code repositories.
- Audit Logging: Tamper-evident logging for administrative access, API configuration changes, and sensitive operations, retained for security audits.
6. Vulnerability Disclosure & Reporting
If you identify a security vulnerability within our platforms, APIs, or infrastructure, report it directly to:
- Security Team:
support@newagetechnology.co.in - Response Commitment: Initial acknowledgment within 24–48 business hours, followed by status updates as triage progresses.
N
New Age Technology Legal Governance
Signed & Approved by Yash Kumar Jha