Trust, Security & Compliance
Security, privacy, compliance and responsible AI practices supporting SDLC Corp's software, AI, cloud and enterprise engineering services.
Review our certifications, security controls, privacy practices, AI governance standards and assurance resources in one place.
Security & Quality Assurance
SDLC Corp maintains company-level security and quality assurance programs designed to support enterprise software, AI and cloud delivery.
SOC 2 Type II
Independent assurance over relevant security and operational controls.
Status: SOC 2 Type II
Available: Report access on request, subject to appropriate confidentiality requirements.
ISO 27001 Certified
Certified information-security management processes supporting the protection of customer and company information.
Standard: ISO/IEC 27001:2022
Available: Certificate details and verification information.
ISO 9001 Certified
Certified quality-management processes supporting consistent delivery, review and continuous improvement.
Standard: ISO 9001:2015
Available: Certificate details and verification information.
Certificate Numbers
Issued by SIS Certifications Pvt. Ltd. on 16 September 2026. Each certificate number can be verified on the SIS Certifications website.
| Certificate No. | Standard | Certified Entity | Location |
|---|---|---|---|
| SIS010926Q062 | ISO 9001:2015 | SDLC Corp (Transform Digital DMCC) | Dubai, United Arab Emirates |
| SIS010926Q063 | ISO 9001:2015 | SDLC Corp (Codefork Technologies Private Limited) | Noida, Uttar Pradesh, India |
| SIS010926Q064 | ISO 9001:2015 | SDLC Corp (Transform Digital LLC) | Batavia, Illinois, USA |
| SIS010926I065 | ISO/IEC 27001:2022 | SDLC Corp (Transform Digital DMCC) | Dubai, United Arab Emirates |
| SIS010926I066 | ISO/IEC 27001:2022 | SDLC Corp (Codefork Technologies Private Limited) | Noida, Uttar Pradesh, India |
| SIS010926I067 | ISO/IEC 27001:2022 | SDLC Corp (Transform Digital LLC) | Batavia, Illinois, USA |
Privacy & Data Protection
We design and operate systems around applicable privacy and data-protection requirements based on the geography, industry, data involved and customer obligations.
GDPR
SDLC Corp follows GDPR requirements for applicable personal-data processing.
Our delivery and engineering practices can include:
- Data minimization
- Access controls
- Retention controls
- Processor/subprocessor management
- International-transfer safeguards
- Auditability
- Data-subject request support
CCPA / CPRA
For applicable California consumer-data workflows, systems can be designed around relevant privacy, access, deletion and data-handling requirements.
India DPDP
For Indian personal-data workflows, AI and software systems can be designed around applicable obligations under India's Digital Personal Data Protection framework.
UAE PDPL
For UAE workloads, systems can account for applicable UAE data-protection requirements.
DIFC Data Protection
Organizations operating within DIFC may have additional data-protection obligations that should be considered during architecture and deployment planning.
Industry Compliance
HIPAA
SDLC Corp maintains HIPAA-compliant practices for applicable healthcare systems and workflows involving protected health information.
Controls may include:
- Access control
- Encryption
- Audit logging
- Least-privilege access
- Secure data handling
- Retention controls
- Incident response
Where required, healthcare projects are designed around the applicable HIPAA security and privacy requirements.
PCI DSS
For payment and cardholder-data environments, SDLC Corp designs and operates workflows around applicable PCI DSS requirements.
This may include:
- Payment-provider integration
- Segmentation
- Access control
- Secure transmission
- Logging
- Credential protection
- Reduction of cardholder-data exposure
Responsible AI & AI Governance
AI systems introduce operational, legal and governance risks that extend beyond traditional software.
Our responsible-AI and governance practices address the full lifecycle, from use-case selection through deployment, monitoring and retirement.
EU AI Act
For systems falling within the scope of the EU AI Act, governance can address applicable requirements around:
- Risk classification
- Transparency
- Human oversight
- Documentation
- Lifecycle controls
- Monitoring
NIST AI Risk Management Framework
Our AI risk-management practices can be informed by the voluntary NIST AI Risk Management Framework.
ISO/IEC 42001
AI governance practices can align with ISO/IEC 42001 principles for AI management systems.
ISO/IEC 23894
AI risk-management activities can be informed by ISO/IEC 23894 guidance.
Human Oversight
Depending on the system and risk level, controls can include:
- Approval gates
- Escalation
- Manual override
- Confidence thresholds
- Reversible actions
- Accountable owners
AI Lifecycle Controls
Governance can cover:
- AI inventory
- Risk classification
- Evaluation
- Approvals
- Change management
- Monitoring
- Incident review
- Re-evaluation
- Retirement
Security Controls
Our engineering and operating practices can include controls across identity, infrastructure, software development and production operations.
Identity & Access
- Role-based access control
- Least privilege
- MFA
- SSO where supported
- Privileged-access controls
Data Protection
- Encryption in transit
- Encryption at rest
- Controlled secrets management
- Environment separation
- Retention and deletion controls
Secure Development
- Code review
- Dependency management
- Static analysis
- Vulnerability scanning
- Secure development practices
- Controlled release processes
Infrastructure Security
- Network isolation
- Private networking where required
- Firewall/security-group controls
- Environment segmentation
- Monitored infrastructure
Vulnerability Management
- Vulnerability assessment
- Patch management
- Dependency review
- Remediation tracking
- Penetration testing where appropriate
Logging & Monitoring
- Audit logs
- Operational logs
- Security monitoring
- Alerting
- Incident investigation
Backup & Recovery
- Backup controls
- Recovery planning
- Environment-specific continuity procedures
AI & Customer Data
Customer data should remain under clear operational and contractual controls when used with AI systems.
Customer Data Usage
Customer information is handled according to the agreed purpose, contract, privacy requirements and system architecture.
Model Providers
Where third-party AI/model providers are used, provider selection and configuration can account for:
- Data retention
- Training-data usage
- Regional processing
- Enterprise privacy settings
- Contractual controls
Private AI
Where required, AI systems can use:
- Private cloud
- Customer-managed cloud
- On-premises infrastructure
- Private/open models
- Isolated retrieval environments
RAG & Knowledge Systems
Enterprise knowledge systems can be designed with:
- Document-level access controls
- Tenant isolation
- Restricted retrieval
- Auditability
- Source-level permissions
Prompts & Conversations
Prompt, conversation and inference-data handling depends on the selected provider, deployment architecture and customer requirements.
Data Residency
Deployment architecture can support regional and customer-controlled data-residency requirements.
Options may include:
- United States
- European regions
- UAE
- India
- Private cloud
- Customer-managed infrastructure
- On-premises deployment
Availability depends on the selected technologies, infrastructure providers and product architecture.
For products with specific residency commitments, refer to the relevant product security documentation.
Compliance & Assurance Documents
Enterprise customers may request applicable assurance documents as part of security review and vendor due diligence.
Available or Planned Documents
- SOC 2 Type II report
- ISO 27001 certificate
- ISO 9001 certificate
- Data Processing Agreement
- Standard Contractual Clauses where applicable
- Business Associate Agreement where applicable
- Security overview
- Penetration-testing summary where available
- Subprocessor information
- Privacy documentation
- Security questionnaire responses
Vendor & Subprocessor Management
Third-party services used in customer environments are evaluated according to the requirements of the project.
Review may include:
- Security posture
- Privacy terms
- Data location
- Data retention
- Contractual safeguards
- Operational dependency
- Model-provider terms
- Compliance requirements
Where appropriate, customer-facing subprocessor information can be provided.
Incident Response
SDLC Corp maintains processes for identifying, investigating and responding to security and operational incidents.
Depending on the incident, response activities may include:
- Triage
- Containment
- Investigation
- Remediation
- Evidence preservation
- Customer communication
- Post-incident review
Contractual and regulatory notification obligations are handled according to the applicable engagement and legal requirements.
Business Continuity
Enterprise systems should be designed with recovery requirements appropriate to their business impact.
Depending on the engagement, controls can include:
- Backups
- Recovery procedures
- Failover
- Infrastructure redundancy
- Restoration testing
- Disaster-recovery planning
Security Reviews & Vendor Due Diligence
For enterprise procurement and security teams, SDLC Corp can support vendor-review workflows such as:
- Security questionnaires
- Compliance-document requests
- Architecture review
- DPA review
- BAA requests where applicable
- Subprocessor review
- Deployment-security discussions
Report a Security Issue
If you believe you have identified a security vulnerability affecting SDLC Corp, its products or systems, use the approved security-reporting channel.
Include:
- Affected product/system
- Description
- Reproduction steps
- Potential impact
- Supporting evidence
Trust Center FAQ
Is SDLC Corp SOC 2 certified?
Yes. SDLC Corp maintains SOC 2 Type II assurance over relevant organizational controls.
Is SDLC Corp ISO 27001 certified?
Yes. SDLC Corp operates an ISO 27001-certified information-security management system.
Is SDLC Corp ISO 9001 certified?
Yes. SDLC Corp operates an ISO 9001-certified quality-management system.
Is SDLC Corp GDPR compliant?
SDLC Corp follows GDPR requirements for applicable personal-data processing and incorporates privacy and data-protection controls into relevant systems and engagements.
Is SDLC Corp HIPAA compliant?
Yes. SDLC Corp maintains HIPAA-compliant practices for applicable healthcare systems and workflows involving protected health information.
Does SDLC Corp support PCI DSS requirements?
Yes. Relevant payment and cardholder-data systems can be designed and operated around applicable PCI DSS controls and compliant payment infrastructure.
How does SDLC Corp approach responsible AI?
Responsible-AI practices can include risk classification, evaluation, human oversight, privacy, security, explainability, monitoring and lifecycle governance.
Does SDLC Corp support private or on-premises AI?
Yes, where the selected technology and use case support it. Architectures can include cloud, private cloud, customer-managed and on-premises deployments.
Can customers request compliance documents?
Yes. Applicable security and compliance documents can be provided through the appropriate review process and confidentiality requirements.
Need Security or Compliance Information?
Request certification details, compliance documentation or support for your vendor-security review.
- Contact Us
Let's Talk About Your Product
What happens next?
- We review your requirements
- Strategy call with experts
- Clear roadmap & estimate
- NDA Protected
- Enterprise Grade Delivery
- Global Clients





