Security and privacy, engineered for autonomous operations.
Two disciplines, one standard of care
Security and privacy aren’t separate workstreams at Digitate they’re the same accountability, applied to how we protect your systems and how we handle your data.
Security
As an enterprise SaaS partner, we operate dedicated security teams and layered controls to protect customer data at every stage of the ignio platform — from infrastructure to application.
- check_circleAligned to ISO 27001:2022, ISO 31000, and ISO 22301:2019
- check_circleIndependent assessments under SOC 2 Plus Type 2
- check_circleAlign to CSA Cloud Controls Matrix (CCM)
- check_circleIndependent assessments covers HIPAA and GDPR controls readiness
Privacy
Your data is the asset you're trusting us with. We use it only for the services you've agreed to — never for marketing, advertising, or undisclosed secondary purposes.
- check_circleDigitate does not engage subcontractors for SaaS operations.
- check_circleRegional data residency options are available to support applicable local requirements.
- check_circleCustomer data is not disclosed to government or law enforcement authorities unless required by law or directed by the customer.
- check_circleOur legal, security, and privacy teams work together through a coordinated governance program.
Where our responsibility ends and yours begins
Enterprise security is a partnership. Knowing the boundary is what makes both sides of it effective.
The platform, infrastructure & operations
- dnsAzure and AWS infrastructure managed with security and reliability controls.
- vpn_lockTenant isolation supported through dedicated networks, VPCs, and WAFs.
- monitor_heartSaaS environments monitored 24/7 through SIEM and SOC capabilities.
- backupEncrypted backups maintained with three-copy redundancy and test restorations.
Access, identity & configuration
- admin_panel_settingsSupports SAML SSO, LDAP integration, and enterprise MFA.
- groupsRole-based access control managed through periodic access reviews.
- tuneIntegrates with ServiceNow, SCOM, Datadog, and supported adapters.
- descriptionCustomers may request access to their instance data during offboarding, subject to Digitate’s applicable data classification, retention, and purge policies.
Documentation your security team will ask for
Public reports are available instantly. Private documentation is shared under NDA during evaluation.
From onboarding to offboarding, accounted for
Your data’s journey through ignio follows a defined path with controls at every transition.
Collection
Digitate minimizes personal data collection, processing telemetry only through approved adapters for agreed use cases.
Protection
Customer data is AES-256 encrypted at rest, TLS-protected in transit, within isolated tenant environments.
Use & Monitoring
Customer data is used only for services; audit and access activities are continuously logged.
Offboarding
Upon termination, customer environments are decommissioned; instance data access available per retention policies.
The controls behind the certifications
Data handling & access posture
helpWhat customer data does the SaaS application process and store?
ignio collects minimal PII — name and business email — solely for registration. The application proxy integrates with tools such as ServiceNow CMDB, ServiceNow ITSM, SCOM, Nagios, and Datadog to process customer telemetry for IT analysis and intelligence use cases. Full detail is available in our Data Privacy Notice.
helpHow is physical security ensured in the SaaS environment?
ignio is hosted on Microsoft Azure and Amazon AWS (PaaS), both ISO 27001 and SOC 2 certified, with physical security owned by the cloud provider. Offshore delivery centers are independently ISO 27001 certified with enforced physical controls. See Azure's physical security documentation and AWS data center controls.
helpHow does the data classification policy work?
Our data classification policy is aligned with NIST IR 8496, ensuring data is categorized and handled consistently with its sensitivity across the platform.
Identity, audit & integration controls
helpHow does the application support SSO integration?
ignio integrates with your existing Identity and Access Management system, supporting both SAML and LDAP binding to enterprise directories. SAML integration enables enterprise MFA at login, and ignio also offers native TOTP-based MFA where enterprise MFA isn't available.
helpHow does the platform support auditing?
Application activity is audited across multiple event types, retrievable via API. Proxy component logs can be integrated into Splunk or similar SIEM tooling. A complete list of audit events is available on request during evaluation.
helpWhat integrations and adapters are supported?
ignio ships with adapters for major industry platforms — ServiceNow, AppDynamics, SNMP, SolarWinds, SCOM, Splunk, Azure Data Factory, Remedy, Cherwell, HPSM, ScienceLogic, Nagios, Cisco DNAC, Jira, CyberArk, Amazon CloudWatch, Azure Monitor, SummitAI, GCP, and more. A complete adapter list is available on request.
helpIs role-based access control (RBAC) supported?
Yes. Access policies follow the principle of least privilege under the ISO 27001 framework, with periodic access reviews. RBAC integrates with your Active Directory so your team manages access control directly.
Encryption, retention & continuity
helpHow is access managed across the platform?
Every user authenticates with a uniquely named ID; IDs unused for 90 days are automatically disabled. Access approvals run through a formal change-management process with segregation of duties between grant and approval, and audit trail access is restricted to authorized personnel.
helpWhat is the backup management policy?
ignio runs on Azure and AWS container-based architecture. Complete snapshot backups use native Azure/AWS backup services with 3-copy cloud redundancy, encrypted at rest, with periodic test restorations.
helpWhat happens to data on retention, archival & disposal?
ignio is a cloud-hosted SaaS solution with no physical media. On contract termination, all data except logs is purged and the tenant is fully decommissioned, including underlying infrastructure. Customers may request export of Blueprint static data prior to offboarding.
helpWhat is the Business Continuity & Disaster Recovery approach?
Our Business Continuity Management Program aligns to ISO 22301 and TCS ISMS policy, with an annual business impact assessment and infrastructure/application changes brought into BCP review scope. RTO/RPO detail is published in our Software Support Policy.
Privacy program & regulatory alignment
helpWho are Digitate's subprocessors?
Our subprocessor list is published and available via the Data Processing Addendum.
helpWhat is the data breach notification policy?
Customers receive initial notification of a suspected breach within 72 hours of Digitate becoming aware of it.
helpHow does ignio approach HIPAA?
ignio does not store or process electronic health information, but the underlying SaaS infrastructure is assessed against HIPAA controls as part of our SOC 2+ program to demonstrate readiness.
helpHow does ignio approach GDPR?
ignio collects minimal information necessary for its functioning, and the SaaS infrastructure is assessed under SOC 2+ to demonstrate compliance with GDPR requirements.
Tenant isolation & resilience
helpHow are tenant environments isolated?
Each SaaS tenant runs in a segregated environment with a dedicated VNET / VPC, protected by Azure or AWS WAF.
helpWhat DDoS protection is in place?
All tenants are protected by Azure Premium DDoS Protection and AWS Shield. Reference: Azure DDoS Protection and AWS Shield.
helpHow is SIEM/SOC monitoring handled?
SaaS infrastructure security logs feed a centralized SIEM/SOC for 24/7 monitoring and event analysis. Infrastructure logs are not shared into client SIEM, but application audit events from the proxy component can be integrated with your SIEM.
Threat detection at the workload layer
helpHow is container infrastructure secured?
Real-time threat detection and protection is active across all container clusters and nodes, continuously monitoring for anomalous workload behavior.
Device-level controls
helpWhat endpoint protections are enforced?
Disk encryption, data leakage prevention, and threat detection software are installed across all endpoints and managed centrally by a dedicated team.
Perimeter & application-layer defense
Governance & people controls
helpHow is the security organization governed?
A dedicated CSO organization is established under the ISO 27001 ISMS framework to oversee and manage security risk governance.
helpWhat HR security checks apply?
All associates and third parties undergo security review, sign NDAs before engagement, and complete background verification before being onboarded — permanent or temporary.
helpHow are security incidents managed?
Incident response and privacy incident management processes are defined at the organizational level, with clear roles and responsibilities for the Incident Response team. Customers log incidents via the support portal, and reviews occur at periodic intervals.
helpIs security training provided to staff?
Yes. Regular security awareness training is conducted for all associates, third-party vendors, and partners.
