Standards & Certifications
How HCL BigFix Cloud Lifecycle Management Protects Your Data and Services
Security
HCL BigFix Cloud Lifecycle Management integrates security controls across the platform lifecycle to protect infrastructure, user access, and operational data.
Data encryption
Data in transit is secured using TLS 1.2, while stored data and automated backups are encrypted using AES-GCM-256.
Availability and disaster recovery
The platform supports high availability through scalable architecture, load balancing, and resilient system components.
Identity and access management
Role-based access controls enforce least-privilege access, with support for SAML-based SSO and external identity providers such as Azure AD or Okta.
Secure development and testing
Secure development practices include threat modeling, design reviews, penetration testing and automated security analysis.
Incident response and monitoring
Security vulnerabilities and incidents are managed through HCLSoftware’s Product Security Incident Response Team (PSIRT) and coordinated remediation processes.
Privacy & Data Handling
HCL BigFix Cloud Lifecycle Management applies privacy-focused practices to protect customer data and ensure transparent governance.
Privacy by design and default
Privacy and data protection assessments are integrated into the product development lifecycle.
Data roles and responsibilities
Customers remain data controllers and retain ownership of their data, while HCLSoftware processes data as a service provider.
Data minimization and purpose limitation
The platform processes only the data required for administration and service delivery, avoiding sensitive personal data categories.
Data residency and retention
Data retention and storage practices ensure operational continuity while maintaining controlled handling of customer information.
Support
To report a potential security vulnerability or raise a
security concern, please contact our security team at
bigfixclm-ps-team@hcl-software.com