The controls behind the claims — infrastructure, access, monitoring, resilience and what happens when something goes wrong.
EnterFirst runs on AWS with Indian customer workloads in AWS Mumbai and encrypted backup replication to AWS Hyderabad. Production is network-isolated from development and staging, with no shared credentials and no production data in non-production environments.
Object storage holds documents with versioning enabled and server-side encryption, so a superseded draft can always be produced for audit.
AES-256 for data at rest, including databases, object storage and backups. TLS 1.3 for data in transit, with HSTS enforced and older cipher suites disabled. Keys are managed through a dedicated key management service with rotation and no key material in application code.
Role-based permissions at client, module and action level, configurable by your administrators. Multi-factor authentication is available on every plan and enforceable organisation-wide. Session timeouts, device tracking and forced revocation are supported.
EnterFirst staff access to customer environments is request-based, approved, time-boxed and logged. Verification professionals see only the matter assigned to them.
Each firm or entity is logically isolated. There are no shared document buckets, no cross-tenant search index, and no configuration in which one customer can enumerate another.
Every view, edit, version, approval, export and administrative action is written to an append-only audit log with a timestamp and actor. Logs are exportable in full for regulatory review or internal audit and cannot be edited by customers or staff.
Input validation and output encoding against injection and cross-site scripting, parameterised queries, CSRF protection, rate limiting and anomaly detection on authentication endpoints. Dependencies are scanned continuously and patched on a documented severity schedule.
Daily encrypted backups retained for 30 days, replicated to AWS Hyderabad as a second Indian region, with restoration tested periodically. Target recovery point is 24 hours and target recovery time is 4 hours. Paid plans carry a 99.9% uptime commitment.
Infrastructure, application and authentication telemetry is monitored continuously with alerting on anomalous access patterns, privilege escalation attempts and unusual export volumes.
A documented incident response procedure covers detection, triage, containment, eradication, recovery and post-incident review. Severity-one incidents are escalated immediately and affected customers are notified without undue delay, with a written post-incident report following.
Staff are background-verified on hire, bound by confidentiality obligations, and trained on data handling annually. Sub-processors are assessed before onboarding, listed in a register available on request, and given notice periods before any change takes effect.
Security researchers may report vulnerabilities to [email protected]. We acknowledge within two business days, do not pursue legal action for good-faith research conducted without data exfiltration or service disruption, and credit reporters who wish to be named.
Questions about this document: [email protected]. Data protection and privacy requests: [email protected]. Grievances: grievance redressal.
EnterFirst Private Limited, 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001, India · CIN U64990DL2023PTC411277. EnterFirst Pte Ltd, 6001 Beach Road, #12-04, Golden Mile Tower, Singapore 199589.