Security and data handling

What we do not have, and what we do instead.

A company our size that claims an ISO certificate is usually claiming something else too. Here is the honest version, in enough detail that you can check it against how we actually behave on an engagement.

Certification posture

Stated plainly.

Kyron Infotech is not ISO 27001 certified and does not hold a SOC 2 report.

We will not write “ISO 27001 aligned” or “SOC 2 ready” either. Those are phrases that exist to sound like a certificate without being one, and a technical buyer reads them as a no. If your procurement process requires a certified vendor, we are not the right fit today and we would rather tell you now than at contract stage.

Practices

How your code and data are actually handled.

Repository access
Repos are created in your organisation on day one, not transferred later. Access is least privilege, named per person, and revoked at project close.
Credentials and secrets
Secrets never enter source control. They are held in a managed secrets store or your own cloud project, and rotated when an engagement ends.
Cloud and store accounts
Firebase, Supabase, Vercel, Play Console and App Store Connect are opened in your name with us added as members. You can remove us without losing anything.
Devices
Full disk encryption and a screen lock on every machine that touches client code. No client source on personal phones.
Client data in development
We build against seeded or anonymised data by default. Where production data is genuinely required, it is agreed in writing first and deleted at close.
Contracts
Mutual NDA, master services agreement, statement of work, and a data processing agreement on request. We are happy to sign your paper instead of ours.
Breach and incident contact
Keval Patel, info.kyroninfotech@gmail.com. Reports are read the same working day.
Data protection

DPDP Act and GDPR.

For this website, Kyron Infotech is the data fiduciary. The only personal data we collect is what you send us in an enquiry, and it is used to answer that enquiry and nothing else.

On client engagements we are a data processor acting on your instructions, and a data processing agreement is available on request. Grievance officer: Keval Patel, info.kyroninfotech@gmail.com.

The full notice, including the rights you can exercise and the timeline we answer within, is on the privacy page.

Next step

Tell us the platform and what you are trying to ship.

A 45 minute scoping call, then a written proposal with scope, price and dates inside two working days. Keval reads every enquiry and replies within one working day.

I need

Book a scoping call

Email info.kyroninfotech@gmail.com

Or start a conversation on WhatsApp: +91 84889 97200