Standards & Certifications
How HCL iObserve Protects
Your Data and Services
Security
HCL iObserve applies security-by-design practices across development, infrastructure, and product operations to protect platform integrity and customer data.
Data encryption
Sensitive data is encrypted both at rest and in transit using AES-256 encryption and secure protocols such as TLS.
Data protection
Customer data is protected through least-privilege access controls and encryption of sensitive information.
Identity and access management
Role-based access controls and multi-factor authentication enforce secure and controlled platform access.
Secure development and testing
Secure development practices follow NIST SSDF guidelines with automated security testing, static analysis, and hardened build environments.
Incident response and monitoring
Vulnerabilities and security incidents are managed through the HCLSoftware Product Security Incident Response Team (PSIRT).
Compliance
HCL iObserve aligns with globally recognized security standards and compliance practices.
Standards & certifications
Aligned with internationally recognized frameworks and certifications, including ISO 27001 and Common Criteria.
Independent audits and validation
Regular security assessments, penetration testing, and red-team exercises ensure continuous validation of security controls.
Privacy & Data Handling
HCL iObserve protects customer information through privacy-first data handling and strong governance practices.
Privacy by design and default
Privacy and data protection controls are embedded into platform design and development processes.
Data transparency and protection
Practices include encryption (AES-256, TLS), role-based access controls, minimal data collection, and secure communication protocols, ensuring data is handled and protected in line with global privacy principles.
Support
To report a potential security vulnerability or raise a
security concern, please contact our security team at
ifso-pmg@hcl-software.com