Standards & Certifications
How HCL BigFix Runbook AI Protects
Your Data and Services
Security
HCL BigFix Runbook AI applies security-first controls to protect automation data, user access, and platform interactions.
Data encryption
All stored data is encrypted using AES-GCM 256-bit encryption, and data in transit (including shared logs) is secured using TLS 1.2/1.3.
Data protection
Customer and ticket-related data is handled using privacy-aligned processing, PII minimization, consent controls, and configurable data redaction mechanisms.
Identity & access management
Secure access is enforced through SAML 2.0–based SSO, role-based access control, authenticated APIs, session timeouts, and audit logging.
Secure development & testing
Security is built into the lifecycle through threat modeling, code analysis, and regular penetration testing.
Vulnerability management & response
The HCL PSIRT manages vulnerability reporting, investigation, and remediation, supported by ongoing security assessments and published advisories.
Compliance
HCL BigFix Runbook AI maintains compliance through risk and security practices aligned with globally recognized standards, including ISO 27001/27002, ISO 31000, and ISO 27005 applied across operational, human, and AI risk management.
Privacy & Data Handling
HCL BigFix Runbook AI applies privacy-focused controls to ensure responsible handling of customer and user data.
Data roles & responsibilities
The enterprise retains ownership and control of their data, while we operate as the data processor in accordance with contractual obligations.
Data minimization & purpose limitation
Personal data is processed only for product administration and service delivery purposes, with collection limited to what is necessary and no processing of special categories of sensitive personal data.
Responsible AI
HCL BigFix Runbook AI applies responsible AI practices to ensure secure, governed and accountable automation.
AI usage overview
AI capabilities are used to support intelligent runbook automation, recommendations, and content generation within defined operational boundaries.
Ethical principles & governance
AI usage follows established security, risk, and governance frameworks, with controls aligned to our responsible AI and risk management practices.
Human oversight & accountability
AI-driven outputs are governed through defined oversight mechanisms, with human review applied to critical workflows and decisions.
Fairness, bias & model quality monitoring
Model lifecycle controls include governance, explainability, and performance monitoring to help detect bias, track quality, and manage accuracy over time.
Support
To report a potential security vulnerability or raise a
security concern, please contact our security team at
ifso-pmg@hcl-software.com