Trust Center

Trust, Security & Compliance

Security, privacy, compliance and responsible AI practices supporting SDLC Corp's software, AI, cloud and enterprise engineering services.

Review our certifications, security controls, privacy practices, AI governance standards and assurance resources in one place.

Section 01

Security & Quality Assurance

SDLC Corp maintains company-level security and quality assurance programs designed to support enterprise software, AI and cloud delivery.

SOC 2 Type II

Independent assurance over relevant security and operational controls.

Status: SOC 2 Type II

Available: Report access on request, subject to appropriate confidentiality requirements.

ISO 27001 Certified

Certified information-security management processes supporting the protection of customer and company information.

Standard: ISO/IEC 27001:2022

Available: Certificate details and verification information.

ISO 9001 Certified

Certified quality-management processes supporting consistent delivery, review and continuous improvement.

Standard: ISO 9001:2015

Available: Certificate details and verification information.

Certificate Numbers

Issued by SIS Certifications Pvt. Ltd. on 16 September 2026. Each certificate number can be verified on the SIS Certifications website.

Certificate No.StandardCertified EntityLocation
SIS010926Q062ISO 9001:2015SDLC Corp (Transform Digital DMCC)Dubai, United Arab Emirates
SIS010926Q063ISO 9001:2015SDLC Corp (Codefork Technologies Private Limited)Noida, Uttar Pradesh, India
SIS010926Q064ISO 9001:2015SDLC Corp (Transform Digital LLC)Batavia, Illinois, USA
SIS010926I065ISO/IEC 27001:2022SDLC Corp (Transform Digital DMCC)Dubai, United Arab Emirates
SIS010926I066ISO/IEC 27001:2022SDLC Corp (Codefork Technologies Private Limited)Noida, Uttar Pradesh, India
SIS010926I067ISO/IEC 27001:2022SDLC Corp (Transform Digital LLC)Batavia, Illinois, USA
Section 02

Privacy & Data Protection

We design and operate systems around applicable privacy and data-protection requirements based on the geography, industry, data involved and customer obligations.

GDPR

SDLC Corp follows GDPR requirements for applicable personal-data processing.

Our delivery and engineering practices can include:

  • Data minimization
  • Access controls
  • Retention controls
  • Processor/subprocessor management
  • International-transfer safeguards
  • Auditability
  • Data-subject request support
Read our Privacy Policy

CCPA / CPRA

For applicable California consumer-data workflows, systems can be designed around relevant privacy, access, deletion and data-handling requirements.

India DPDP

For Indian personal-data workflows, AI and software systems can be designed around applicable obligations under India's Digital Personal Data Protection framework.

UAE PDPL

For UAE workloads, systems can account for applicable UAE data-protection requirements.

DIFC Data Protection

Organizations operating within DIFC may have additional data-protection obligations that should be considered during architecture and deployment planning.

Section 03

Industry Compliance

HIPAA

SDLC Corp maintains HIPAA-compliant practices for applicable healthcare systems and workflows involving protected health information.

Controls may include:

  • Access control
  • Encryption
  • Audit logging
  • Least-privilege access
  • Secure data handling
  • Retention controls
  • Incident response

Where required, healthcare projects are designed around the applicable HIPAA security and privacy requirements.

PCI DSS

For payment and cardholder-data environments, SDLC Corp designs and operates workflows around applicable PCI DSS requirements.

This may include:

  • Payment-provider integration
  • Segmentation
  • Access control
  • Secure transmission
  • Logging
  • Credential protection
  • Reduction of cardholder-data exposure
Section 04

Responsible AI & AI Governance

AI systems introduce operational, legal and governance risks that extend beyond traditional software.

Our responsible-AI and governance practices address the full lifecycle, from use-case selection through deployment, monitoring and retirement.

EU AI Act

For systems falling within the scope of the EU AI Act, governance can address applicable requirements around:

  • Risk classification
  • Transparency
  • Human oversight
  • Documentation
  • Lifecycle controls
  • Monitoring

NIST AI Risk Management Framework

Our AI risk-management practices can be informed by the voluntary NIST AI Risk Management Framework.

ISO/IEC 42001

AI governance practices can align with ISO/IEC 42001 principles for AI management systems.

ISO/IEC 23894

AI risk-management activities can be informed by ISO/IEC 23894 guidance.

Human Oversight

Depending on the system and risk level, controls can include:

  • Approval gates
  • Escalation
  • Manual override
  • Confidence thresholds
  • Reversible actions
  • Accountable owners

AI Lifecycle Controls

Governance can cover:

  • AI inventory
  • Risk classification
  • Evaluation
  • Approvals
  • Change management
  • Monitoring
  • Incident review
  • Re-evaluation
  • Retirement
Section 05

Security Controls

Our engineering and operating practices can include controls across identity, infrastructure, software development and production operations.

Identity & Access

  • Role-based access control
  • Least privilege
  • MFA
  • SSO where supported
  • Privileged-access controls

Data Protection

  • Encryption in transit
  • Encryption at rest
  • Controlled secrets management
  • Environment separation
  • Retention and deletion controls

Secure Development

  • Code review
  • Dependency management
  • Static analysis
  • Vulnerability scanning
  • Secure development practices
  • Controlled release processes

Infrastructure Security

  • Network isolation
  • Private networking where required
  • Firewall/security-group controls
  • Environment segmentation
  • Monitored infrastructure

Vulnerability Management

  • Vulnerability assessment
  • Patch management
  • Dependency review
  • Remediation tracking
  • Penetration testing where appropriate

Logging & Monitoring

  • Audit logs
  • Operational logs
  • Security monitoring
  • Alerting
  • Incident investigation

Backup & Recovery

  • Backup controls
  • Recovery planning
  • Environment-specific continuity procedures
Section 06

AI & Customer Data

Customer data should remain under clear operational and contractual controls when used with AI systems.

Customer Data Usage

Customer information is handled according to the agreed purpose, contract, privacy requirements and system architecture.

Model Providers

Where third-party AI/model providers are used, provider selection and configuration can account for:

  • Data retention
  • Training-data usage
  • Regional processing
  • Enterprise privacy settings
  • Contractual controls

Private AI

Where required, AI systems can use:

  • Private cloud
  • Customer-managed cloud
  • On-premises infrastructure
  • Private/open models
  • Isolated retrieval environments

RAG & Knowledge Systems

Enterprise knowledge systems can be designed with:

  • Document-level access controls
  • Tenant isolation
  • Restricted retrieval
  • Auditability
  • Source-level permissions

Prompts & Conversations

Prompt, conversation and inference-data handling depends on the selected provider, deployment architecture and customer requirements.

Section 07

Data Residency

Deployment architecture can support regional and customer-controlled data-residency requirements.

Options may include:

  • United States
  • European regions
  • UAE
  • India
  • Private cloud
  • Customer-managed infrastructure
  • On-premises deployment

Availability depends on the selected technologies, infrastructure providers and product architecture.

For products with specific residency commitments, refer to the relevant product security documentation.

Section 08

Compliance & Assurance Documents

Enterprise customers may request applicable assurance documents as part of security review and vendor due diligence.

Available or Planned Documents

  • SOC 2 Type II report
  • ISO 27001 certificate
  • ISO 9001 certificate
  • Data Processing Agreement
  • Standard Contractual Clauses where applicable
  • Business Associate Agreement where applicable
  • Security overview
  • Penetration-testing summary where available
  • Subprocessor information
  • Privacy documentation
  • Security questionnaire responses
Section 09

Vendor & Subprocessor Management

Third-party services used in customer environments are evaluated according to the requirements of the project.

Review may include:

  • Security posture
  • Privacy terms
  • Data location
  • Data retention
  • Contractual safeguards
  • Operational dependency
  • Model-provider terms
  • Compliance requirements

Where appropriate, customer-facing subprocessor information can be provided.

Section 10

Incident Response

SDLC Corp maintains processes for identifying, investigating and responding to security and operational incidents.

Depending on the incident, response activities may include:

  • Triage
  • Containment
  • Investigation
  • Remediation
  • Evidence preservation
  • Customer communication
  • Post-incident review

Contractual and regulatory notification obligations are handled according to the applicable engagement and legal requirements.

Section 11

Business Continuity

Enterprise systems should be designed with recovery requirements appropriate to their business impact.

Depending on the engagement, controls can include:

  • Backups
  • Recovery procedures
  • Failover
  • Infrastructure redundancy
  • Restoration testing
  • Disaster-recovery planning
Section 12

Security Reviews & Vendor Due Diligence

For enterprise procurement and security teams, SDLC Corp can support vendor-review workflows such as:

  • Security questionnaires
  • Compliance-document requests
  • Architecture review
  • DPA review
  • BAA requests where applicable
  • Subprocessor review
  • Deployment-security discussions
Section 13

Report a Security Issue

If you believe you have identified a security vulnerability affecting SDLC Corp, its products or systems, use the approved security-reporting channel.

Include:

  • Affected product/system
  • Description
  • Reproduction steps
  • Potential impact
  • Supporting evidence
Section 14

Trust Center FAQ

Is SDLC Corp SOC 2 certified?

Yes. SDLC Corp maintains SOC 2 Type II assurance over relevant organizational controls.

Is SDLC Corp ISO 27001 certified?

Yes. SDLC Corp operates an ISO 27001-certified information-security management system.

Is SDLC Corp ISO 9001 certified?

Yes. SDLC Corp operates an ISO 9001-certified quality-management system.

Is SDLC Corp GDPR compliant?

SDLC Corp follows GDPR requirements for applicable personal-data processing and incorporates privacy and data-protection controls into relevant systems and engagements.

Is SDLC Corp HIPAA compliant?

Yes. SDLC Corp maintains HIPAA-compliant practices for applicable healthcare systems and workflows involving protected health information.

Does SDLC Corp support PCI DSS requirements?

Yes. Relevant payment and cardholder-data systems can be designed and operated around applicable PCI DSS controls and compliant payment infrastructure.

How does SDLC Corp approach responsible AI?

Responsible-AI practices can include risk classification, evaluation, human oversight, privacy, security, explainability, monitoring and lifecycle governance.

Does SDLC Corp support private or on-premises AI?

Yes, where the selected technology and use case support it. Architectures can include cloud, private cloud, customer-managed and on-premises deployments.

Can customers request compliance documents?

Yes. Applicable security and compliance documents can be provided through the appropriate review process and confidentiality requirements.

Need Security or Compliance Information?

Request certification details, compliance documentation or support for your vendor-security review.

Let's Talk About Your Product

Get expert guidance on architecture, scope, timelines, and delivery approach so you can move forward with confidence.

What happens next?