How HCL iControl Protects
Your Data and Services
Security
HCL iControl is designed with built-in safeguards to protect platform access, data handling, and operational reliability.
Data encryption
All data in transit is protected using TLS, with sensitive data encrypted at rest using cloud native mechanisms.
Data protection
HCL iControl does not require PII by default; customers control what data is ingested and retained.
Identity & access management
Access is governed through federated identity and role-based permissions via Keycloak or native Splunk controls.
Availability & disaster recovery
A container-based architecture supports high availability, fault tolerance and recovery aligned with customer infrastructure.
Logging and monitoring
Application activity and configuration changes are logged for visibility and auditability.
Secure architecture and infrastructure
HCL iControl runs in customer-managed cloud or Splunk environments using platform-native security controls.
Secure development and testing
Security checks and testing are embedded across the product lifecycle.
Incident response and monitoring
Vulnerabilities and incidents are handled through HCLSoftware’s PSIRT process.
Compliance
HCL iControl aligns with HCLSoftware’s enterprise security practices, embedding secure development and privacy controls to support regulatory and audit requirements.
Secure development and privacy controls
Built on secure SDLC practices, including threat modeling, security testing, and privacy-by-design principles.
Security validation and testing
Regular penetration testing and security assessments help identify vulnerabilities and strengthen platform security.
Privacy & Data Handling
HCL iControl enables trusted business observability embedding privacy and data protection principles across its design and operations.
Privacy by design and default
Privacy principles are built into iControl’s architecture and development lifecycle, with safeguards applied by default to limit data exposure.
Data roles and responsibilities
Customers act as data controllers and retain ownership of their data, while HCLSoftware operates as a data processor in accordance with contractual obligations.
Data minimization and purpose limitation
The platform is designed to process only the data required for intended functionality and does not require personal data by default.
Data residency and retention
Data is stored and managed within customer-controlled environments, with residency and retention policies defined and enforced by the customer.
Data transparency and control
HCL iControl provides visibility into data usage, enabling customers to manage and govern their data in line with regulatory requirements.
Responsible AI
HCL iControl applies responsible AI practices to ensure transparency, control, and safe usage across its AI-assisted capabilities.
AI usage overview
AI is used in a limited, assistive capacity to support process flow and template generation, with no autonomous execution of actions.
Human oversight and control
All AI-generated outputs require human review and validation before use, ensuring accountability and preventing unintended outcomes.
Transparency in AI usage
Users are informed when data is shared with AI services, enabling clear visibility into AI interactions.
Data handling and privacy
AI features follow privacy-by-design principles, with data encrypted in transit and not used for model training by default.
Safe and intended use
AI capabilities are designed for specific, controlled use cases, reducing the risk of misuse or unintended behavior.
Support
To report a potential security vulnerability or raise a
security concern, please contact our security team at
ifso-pmg@hcl-software.com