Last updated: July 2026
Security
At OncyTech, we value transparency, privacy, and security. This page outlines the security practices and standards we apply across all our services.
Our Commitment
Security is integrated into every stage of our development process — from initial planning and architecture through to deployment and ongoing maintenance. We apply layered security controls and follow industry-recognized best practices to protect client data and the integrity of our systems.
Infrastructure Security
Our infrastructure is built on hardened, enterprise-grade cloud environments with the following protections in place:
- SSL/TLS encryption for all data in transit
- Secure cloud hosting with network segmentation
- Firewall protection and DDoS mitigation
- Automated daily backups with tested restoration
Application Security
We apply secure coding standards and automated tooling throughout our development lifecycle:
- Secure authentication with multi-factor support
- Role-based access control (RBAC)
- Encrypted data storage using AES-256
- API security with rate limiting and input validation
- Dependency scanning and OWASP Top 10 compliance
- Static and dynamic analysis in CI/CD pipelines
Access Controls
Access to client data and internal systems is restricted on a strict need-to-know basis. We enforce multi-factor authentication for all team members, maintain detailed access audit logs, and follow the principle of least privilege. Access is immediately revoked upon team member offboarding.
Compliance
Our security program aligns with the following regulatory frameworks:
- GDPR — General Data Protection Regulation (EU)
- CCPA — California Consumer Privacy Act (USA)
- India DPDP Act — Digital Personal Data Protection Act
We regularly review our practices to remain current with evolving compliance requirements.
Responsible Disclosure
If you discover a security vulnerability in our systems or services, we encourage responsible disclosure. Please report it directly to our security team rather than posting it publicly. We commit to acknowledging all valid reports within 48 hours and providing timely updates on remediation.
Security contact: contact@oncytech.com
We appreciate the security research community and will not pursue legal action against researchers acting in good faith.
Need Help?
If you have questions about our policies or services, feel free to contact our team.
Contact Us