Standards & Certifications
How HCL BigFix Service Management Protects Your Data and Services
Security
HCL BigFix Service Management applies layered security controls to safeguard enterprise data, user access, and service continuity.
Data encryption
Data is secured using TLS for in-transit data and AES-256 for at-rest data, including databases, backups, and archived data.
Data protection
Access controls, encryption, backup processes, and defined retention and deletion policies protect data across its lifecycle.
Identity & access management
Secure access is enforced through role-based permissions, least-privilege policies, SAML 2.0 single sign-on, and authenticated APIs.
Platform architecture & isolation
A secure SaaS architecture ensures logical tenant separation and encrypted integrations between platform components.
Availability & disaster recovery
The service is deployed across multiple availability zones with redundancy and defined recovery objectives to support service continuity.
Secure development & testing
Security is built into the development lifecycle through threat modeling, secure design reviews, automated testing, and penetration testing.
Incident response
Security incidents and vulnerabilities are managed through established response processes led by our Product Security Incident Response Team(PSIRT).
Compliance
HCL BigFix Service Management follows established security and governance frameworks to support compliance, audit readiness, and regulatory requirements.
Global standards alignment
Aligned with industry-recognized security principles, including defense-in-depth, secure-by-design, and zero-trust architectures.
Independent audits & attestations
Subject to regular internal reviews and external assessments as part of HCLSoftware’s governance, risk, and compliance program.
Certification scope & maintenance
Certifications are maintained within defined scopes through ongoing compliance and governance processes.
Regulatory & regional compliance
Supports regional and regulatory requirements through data residency controls and compliance-aligned data handling practices.
Continuous governance & control mapping
Data governance, access controls, and confidentiality measures are enforced through documented policies, defined roles, and lifecycle controls.
Privacy & Data Handling
HCL BigFix Service Management applies privacy-first controls to protect enterprise data and ensure transparent handling.
Privacy by design & default
Privacy safeguards are built into data collection, processing, and storage by default.
Data roles & responsibilities
The enterprise remains the data controller, while we act as the data processor under defined agreements.
Data minimization & purpose limitation
Only data required for service delivery is processed, with no support for special categories of sensitive personal data.
Data residency & retention
Data is stored in appropriate regions and managed through defined archival, backup, retention, and deletion policies.
Data subject rights & transparency
Clear processes govern data disclosure and transparency around how enterprise data is handled.
Responsible AI
HCL BigFix Service Management governs the use of AI capabilities through defined controls to ensure data protection, accountability, and responsible operation.
AI usage overview
AI capabilities are used to support predictive and generative use cases within defined operational boundaries and governance controls.
Data handling & privacy in AI
AI features follow strict data minimization, consent, redaction, and isolation practices, ensuring data is processed securely and only within the organization’s environment.
Transparency & explainability
AI-driven outputs are traceable, auditable, and designed to provide clarity into how results are generated, supporting accountability and oversight.
Support
To report a potential security vulnerability or raise a
security concern, please contact our security team at
hclbigfixsm-pmg@hcl-software.com