Security, Built In
by Design.


















Who we are and what this covers
XEqualTo Analytics (“XEqualTo”, “we”, “us” or “our”) is a data, AI and cloud consultancy. This Security & Trust statement covers the security of xequalto.com (the “Site”), our internal business systems, and the information we hold about visitors, prospects, clients and partners.
It is a description of our practices, not a contractual commitment. Where we provide services to a client, the specific security obligations that apply are set out in the agreement for that engagement. This statement should be read together with our Privacy Policy, which explains how we handle personal data.
Our approach to security
Security is central to the work we do for clients, and we apply the same discipline to our own operations. We take a risk-based approach: we identify the systems and information that matter most, understand how they could be compromised, and apply controls that are proportionate to that risk.
Our practices are guided by widely recognised frameworks and cloud provider best practice, and are designed around a few core principles:
- Least privilege — people and systems get only the access they need, for only as long as they need it.
- Defence in depth — multiple, overlapping controls rather than reliance on any single safeguard.
- Secure by design — security considered from the start of every project, not added at the end.
- Transparency — clear communication with clients about how their information is handled.
Security measures we apply
We apply appropriate technical and organisational measures to protect our website, business systems and information. Our approach includes practices such as:
Access and identity
- access controls and least-privilege principles across our systems and cloud accounts;
- secure authentication practices, including multi-factor authentication for internal systems and administrative access;
- prompt removal of access when roles change or people leave.
Data protection
- encryption where appropriate, including encryption of data in transit and, where supported, at rest;
- controlled access to customer and business information, limited to the people who need it for their role;
- secure handling and disposal of information when it is no longer required.
Engineering and operations
- secure software development practices, including code review, dependency management and separation of environments;
- infrastructure and system monitoring to detect unusual or unauthorised activity;
- vulnerability management, including patching and remediation of identified issues in line with their severity;
- hardened configuration of cloud resources and regular review of security settings.
Governance
- employee security awareness and training;
- incident response procedures;
- regular review of security controls and of the third-party services we rely on.
Protecting customer and business information
Information belonging to our clients is handled under the terms agreed in each engagement and is used only for the purpose of delivering the work. We restrict access to the team members working on the engagement, keep client environments logically separated from our own, and return or securely delete client data at the end of the engagement in line with the contract.
Our own business information — including enquiry details, proposals and internal records — is stored in reputable cloud services with appropriate access controls, and is retained only for as long as described in our Privacy Policy.
Security in consulting engagements
When delivering consulting engagements, security responsibilities and controls are defined according to the scope, the customer environment and the contractual requirements of each engagement. In practice this means:
- we work within the client’s identity, access and security tooling wherever possible, rather than duplicating it;
- we follow the client’s security policies, data classification and change-management processes;
- we design data platforms, pipelines and AI solutions with security controls built in — encryption, role-based access, audit logging and network isolation as appropriate;
- we agree clearly, in writing, who is responsible for which controls before work begins.
Where a client has specific compliance requirements — for example under the DPDP Act, GDPR, HIPAA, SOC 2 or industry regulation — we work with the client to ensure our activities support those requirements.
People and awareness
Security depends on people as much as technology. All XEqualTo team members are bound by confidentiality obligations and receive security awareness guidance covering topics such as phishing, secure handling of credentials, safe use of devices and the appropriate use of AI tools. Access to sensitive information is granted based on role and reviewed periodically.
Incident response
We maintain incident response procedures that set out how we identify, contain, investigate and recover from security incidents. If an incident affects a client’s information or systems, we will notify the client without undue delay in accordance with our contractual obligations. If an incident involves personal data, we will notify affected individuals and the relevant authorities as required by applicable law.
After any significant incident, we conduct a review to understand the root cause and improve our controls.
Continuous review
We continually review our security practices as technologies, threats and business requirements evolve. This includes periodic review of access rights, configuration of cloud environments, third-party services, and the effectiveness of our policies and training. Findings are tracked and addressed according to their risk.
Reporting a security issue
If you believe you have identified a security issue related to XequalTo — whether in our website, our systems or a solution we have delivered — please contact us at connect@xequalto.com with the subject line “Security”. Please include enough detail for us to reproduce the issue, and allow us reasonable time to investigate and respond before sharing it publicly.
We appreciate responsible disclosure and will acknowledge reports promptly. Please do not access, modify or delete data that does not belong to you, and do not perform testing that could degrade our services.
Contact our security team
For security questions, vulnerability reports or to request further information about our practices as part of a procurement or vendor review, email connect@xequalto.com with the subject line “Security”, or call +91 9147391433.
