iTrackStudio logoiTrackStudio
iTrackStudio Legal and Company Information

Security Policy

iRoot Technologies Private Limited is committed to protecting customer data and maintaining the confidentiality, integrity, and availability of iTrackStudio.

Last Updated: April 9, 2026

Security Governance

Security is integrated into the product lifecycle at iRoot Technologies Private Limited, including design review, access governance, deployment controls, and ongoing risk management.

Internal responsibilities are assigned across engineering, operations, and support functions to maintain secure service delivery.

Encryption and Data Protection

  • Data in transit is protected using modern transport encryption protocols.
  • Sensitive data at rest is protected using industry-standard encryption and access restrictions.
  • Backups and recovery workflows follow controlled and monitored processes.

Access Control and RBAC

iTrackStudio supports role-based access control (RBAC) to enforce least-privilege access across features and workflows.

  • User and admin permissions can be scoped by role and responsibility.
  • Administrative actions are controlled and reviewed through audit mechanisms.
  • Account credentials and privileged access are subject to stricter operational controls.

Monitoring, Logging, and Auditability

Platform activity is monitored to detect abnormal behavior, operational failures, and potential security events.

Audit logs are maintained for critical actions to support investigations, compliance requirements, and accountability.

Infrastructure and Application Security

  • Production environments are segmented and access-restricted.
  • Security patches and dependency updates are applied through controlled release processes.
  • Application-level controls are used to reduce common web security risks.

Incident Response

iRoot Technologies Private Limited maintains internal incident handling procedures for identification, containment, remediation, and post-incident review.

Where applicable, affected customers are notified in line with contractual commitments and regulatory obligations.

Customer Responsibilities

Customers are responsible for safeguarding account credentials, assigning permissions appropriately, and following internal security hygiene practices.

Security is a shared responsibility between platform provider and customer administrators.