EnterFirstKBook a demo
Home/ Legal/ Data Security

Data Security

The controls behind the claims — infrastructure, access, monitoring, resilience and what happens when something goes wrong.

Last updated: 15 August 2026· EnterFirst Private Limited · CIN U64990DL2023PTC411277· EnterFirst Pte Ltd, Singapore
01

Infrastructure

EnterFirst runs on AWS with Indian customer workloads in AWS Mumbai and encrypted backup replication to AWS Hyderabad. Production is network-isolated from development and staging, with no shared credentials and no production data in non-production environments.

Object storage holds documents with versioning enabled and server-side encryption, so a superseded draft can always be produced for audit.

02

Encryption

AES-256 for data at rest, including databases, object storage and backups. TLS 1.3 for data in transit, with HSTS enforced and older cipher suites disabled. Keys are managed through a dedicated key management service with rotation and no key material in application code.

03

Access control

Role-based permissions at client, module and action level, configurable by your administrators. Multi-factor authentication is available on every plan and enforceable organisation-wide. Session timeouts, device tracking and forced revocation are supported.

EnterFirst staff access to customer environments is request-based, approved, time-boxed and logged. Verification professionals see only the matter assigned to them.

04

Tenant isolation

Each firm or entity is logically isolated. There are no shared document buckets, no cross-tenant search index, and no configuration in which one customer can enumerate another.

05

Audit logging

Every view, edit, version, approval, export and administrative action is written to an append-only audit log with a timestamp and actor. Logs are exportable in full for regulatory review or internal audit and cannot be edited by customers or staff.

06

Application security

Input validation and output encoding against injection and cross-site scripting, parameterised queries, CSRF protection, rate limiting and anomaly detection on authentication endpoints. Dependencies are scanned continuously and patched on a documented severity schedule.

07

Backup and resilience

Daily encrypted backups retained for 30 days, replicated to AWS Hyderabad as a second Indian region, with restoration tested periodically. Target recovery point is 24 hours and target recovery time is 4 hours. Paid plans carry a 99.9% uptime commitment.

08

Monitoring and alerting

Infrastructure, application and authentication telemetry is monitored continuously with alerting on anomalous access patterns, privilege escalation attempts and unusual export volumes.

09

Incident response

A documented incident response procedure covers detection, triage, containment, eradication, recovery and post-incident review. Severity-one incidents are escalated immediately and affected customers are notified without undue delay, with a written post-incident report following.

10

Personnel and vendors

Staff are background-verified on hire, bound by confidentiality obligations, and trained on data handling annually. Sub-processors are assessed before onboarding, listed in a register available on request, and given notice periods before any change takes effect.

11

Responsible disclosure

Security researchers may report vulnerabilities to [email protected]. We acknowledge within two business days, do not pursue legal action for good-faith research conducted without data exfiltration or service disruption, and credit reporters who wish to be named.

Questions about this document: [email protected]. Data protection and privacy requests: [email protected]. Grievances: grievance redressal.

EnterFirst Private Limited, 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001, India · CIN U64990DL2023PTC411277. EnterFirst Pte Ltd, 6001 Beach Road, #12-04, Golden Mile Tower, Singapore 199589.