Trust & Compliance

Security and compliance
you can verify.

DigiBoxx is built on a foundation of certified security controls, regulatory compliance, and transparent data practices. Here's everything you need to know.

ISO 9001:2015ISO 27001:2022GDPRDPDP Act 2023

Certifications & Regulatory Compliance

ISO

ISO 9001:2015

Quality Management System

DigiBoxx is certified to ISO 9001:2015, demonstrating our commitment to consistent quality in service delivery, customer satisfaction, and continuous improvement across all operations.

ISO

ISO 27001:2022

Information Security Management

Our ISO 27001:2022 certification covers the full scope of DigiBoxx's information security management system, from data storage and access control to incident response and business continuity.

GDPR

GDPR

EU General Data Protection Regulation

DigiBoxx complies with the EU's General Data Protection Regulation for all users in the European Economic Area. This includes lawful basis for processing, data subject rights, and breach notification obligations.

DPDP

DPDP Act 2023

India's Digital Personal Data Protection Act

DigiBoxx is fully aligned with India's Digital Personal Data Protection Act 2023. Including consent management, data principal rights, data fiduciary obligations, and cross-border transfer restrictions.

Security Controls

Encryption at Rest

AES-256 encryption for all stored data across DigiBoxx infrastructure.

Encryption in Transit

TLS 1.3 for all data transmitted between clients and DigiBoxx servers.

Zero-Knowledge Vault

DigiVault uses client-side encryption, DigiBoxx cannot access your vault contents.

Multi-Factor Authentication

TOTP-based 2FA available for all accounts; mandatory for enterprise plans.

Role-Based Access Control

Granular permission management for teams and enterprise deployments.

Penetration Testing

Annual third-party penetration testing by CERT-In empanelled auditors.

Data Residency

All data stored exclusively on servers located in India, no foreign transfers.

Audit Logs

Comprehensive audit trails for all file access, sharing, and admin actions.

Your Data Rights

Under the DPDP Act 2023 and GDPR, you have the following rights regarding your personal data held by DigiBoxx.

Right to Access

Request a copy of all personal data DigiBoxx holds about you.

Right to Correction

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data, subject to legal retention requirements.

Right to Portability

Export your data in machine-readable format at any time.

Right to Withdraw Consent

Withdraw consent for non-essential data processing at any time.

Right to Grievance

Lodge a complaint with our Grievance Officer within 30 days of any concern.

To exercise any of these rights, contact our Data Protection Officer:

[email protected]

Incident Response & Breach Notification

In the event of a data breach, DigiBoxx will notify affected users and relevant authorities within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33 and DPDP Act Section 8(6).

Our incident response team operates 24/7. All security incidents are logged, investigated, and reported in accordance with our ISO 27001:2022 certified incident management procedures.

1

Detection

Automated monitoring detects anomalous activity within minutes.

2

Containment

Affected systems are isolated to prevent further exposure.

3

Notification

Users and authorities notified within 72 hours.

4

Remediation

Root cause addressed and controls strengthened.