Skip to content

Security

Security and confidentiality, described honestly

We describe controls we actually operate and commitments we are willing to put into a contract. We do not claim certifications we do not hold.

Access control

  • Least-privilege access aligned to the agreed scope
  • Client-owned accounts wherever systems allow it
  • Multi-factor authentication where the system supports it
  • Access reviewed on joiner, mover and leaver events

Confidentiality

  • Company-level and individual confidentiality undertakings
  • Need-to-know handling of client information
  • Controlled file sharing through approved channels
  • No reuse of client material outside the engagement

Device and workspace

  • Supervised delivery workspace
  • Screen-lock and clear-desk practices
  • Controls on removable media and unauthorised copying
  • Restrictions on personal messaging channels for client data

Incident response

  • Defined internal reporting route for suspected incidents
  • Prompt notification to the client contact
  • Containment, investigation and corrective actions
  • Documented lessons learned

Contractual protection

  • Non-disclosure agreement before detailed discussions
  • Data-processing agreement where personal information is involved
  • Appropriate contractual transfer documentation where required
  • Agreed data-return and deletion procedure at exit

People and training

  • Onboarding briefing on confidentiality and data handling
  • Role-specific process training
  • Refresher training and periodic reminders
  • Supervision by a named delivery lead

Summary

Baseline operating controls

  • Role-based access
  • Multi-factor authentication where supported
  • Least-privilege access
  • Confidentiality and NDA controls
  • Controlled file sharing
  • Documented retention and deletion
  • Incident escalation procedures
  • Approved software and device controls
  • Client-defined access restrictions
  • Regular access review

Outsourcebar Private Limited does not currently claim ISO 27001, SOC 2 or any equivalent certification. Security measures are agreed per engagement and recorded in the applicable contract and service schedule.

Where UK or European personal information is accessed from India, an appropriate contractual transfer mechanism is agreed with the client before access is granted. Clients remain responsible for determining a lawful basis and an appropriate transfer arrangement for personal information they provide or make accessible.

Security enquiry

Ask a security or data-protection question

Send due-diligence questions, security questionnaires or data-processing queries and we will respond with documented answers.

Tell us which part of your operation needs more capacity.

Share your current workload, business objective or service challenge. We will review the requirement and propose an appropriate delivery structure.

CallWhatsAppRequest a Proposal