Foundational Pillars

Security

  • Data Encryption: Data is consistently protected in transit using secure protocols (such as TLS) and encrypted at rest using strong, industry-standard or cloud-native mechanisms.
  • Identity & Access Management (IAM): Secure access is enforced across the portfolio through Role-Based Access Controls (RBAC), least-privilege policies, and integration with enterprise Single Sign-On (SSO) or federated identity providers.
  • Secure Development Lifecycle (SDLC): Security is deeply embedded throughout the product lifecycle, incorporating practices like threat modeling, automated security testing, and secure design reviews.
  • Incident Response: Vulnerabilities and security events across all products are centrally managed through the HCLSoftware Product Security Incident Response Team (PSIRT) for coordinated tracking and remediation

Compliance

  • Enterprise Standards Alignment: Security and risk governance operate under HCLSoftware’s enterprise Information Security Management System (ISMS) and align with globally established Governance, Risk, and Compliance (GRC) frameworks.
  • Continuous Governance: Products maintain continuous risk monitoring, control mapping, and regular security assessments to support operational reliability and global compliance requirements.

Privacy & Data Handling

  • Privacy by Design & Default: Privacy principles and data protection safeguards are embedded directly into the architecture, development, and standard operations of all platforms by default.
  • Data Roles & Responsibilities: Across all products, customers act as the data controllers, retaining full ownership and control of their data. HCLSoftware operates strictly as the data processor fulfilling contractual obligations.
  • Data Minimization: Platforms are explicitly designed to process only the data required for intended functionality and service delivery, avoiding the collection or processing of special sensitive personal data categories.

Responsible AI

AI powers many capabilities across the AI & IO ecosystem, but always with oversight, transparency, and accountability.

Note: This section applies specifically to the products in the portfolio that utilize AI capabilities, such as HCL BigFix AEX, HCL AION, HCL BigFix Service Management, HCL IEM, HCL MyXalytics, HCL Runbook AI, and HCL iControl

  • Ethical Principles & Governance: Where AI is utilized, capabilities operate within clearly defined boundaries and are governed by HCLSoftware’s ethical AI guidelines and enterprise risk management practices.
  • Human Oversight & Accountability: AI is used in an assistive manner to support insights and automation. Critical workflows and high-impact actions rely on human-in-the-loop validation to ensure accountability.
  • Transparent & Secure Processing: AI features respect privacy-by-design principles. Customer data used in AI processes is handled with strict data protection controls, minimization, and transparency to ensure explainable and reliable outputs

Foundational Pillars

Trust by Products