Last Updated: 23 September, 2026
Enterprise Security at Monitor360
Protecting Customer Data Through Security by Design
Softhealer Technologies Pvt. Ltd. ("Softhealer", "we", "our", or "us") develops and operates Monitor360, an enterprise workforce monitoring and productivity platform.
Protecting customer information is fundamental to how Monitor360 is designed, developed and operated. We implement multiple technical, administrative and operational safeguards to help protect customer data against unauthorized access, disclosure, alteration and destruction.
This page provides an overview of our security practices, operational controls and compliance commitments.
For information about personal data collection and processing, please refer to our Privacy Policy . For information regarding regulatory compliance, please refer to our GDPR and HIPAA pages.
1. Security by Design
Security is integrated into every stage of the Monitor360 platform.
From product design and software development to deployment and ongoing operations, we follow security-first principles to help protect customer information while maintaining platform reliability and availability.
Our objective is to provide organisations with a secure workforce monitoring platform that balances operational visibility with privacy and data protection.
2. Security Measures
Monitor360 incorporates multiple layers of security designed to protect customer information throughout its lifecycle.
Our security controls include:
- TLS 1.2 encryption for data in transit
- AES-256 encryption for data at rest
- Secure password hashing
- Secure authentication
- Role-Based Access Control (RBAC)
- Secure cloud infrastructure
- Daily database backups
- Redundant storage for user-generated files
- Disaster recovery procedures
- Configurable monitoring controls
- Continuous software maintenance
3. Data Protection
Protecting customer information is one of our highest priorities.
Encryption in Transit
All communication between monitored devices, customer browsers and Monitor360 services is protected using TLS 1.2 encryption.
Encryption at Rest
Customer data stored by Monitor360 is protected using AES-256 encryption.
Password Security
Passwords are securely hashed before storage and are never stored in plain text.
Data Residency
Customer data is hosted exclusively within the Amazon Web Services (AWS) Asia Pacific (Mumbai) Region (ap-south-1)
Currently, customer-selected data residency in other regions is not available.
4. Authentication & Access Control
Access to customer information is restricted through authentication and permission management.
Monitor360 currently provides:
- Multi-factor authentication (MFA) support
- Secure user authentication
- Role-Based Access Control (RBAC)
- Administrator and user role separation
- Session management
Customers are responsible for assigning user permissions appropriately and following the principle of least privilege.
5. Infrastructure Security
Monitor360 is hosted on Amazon Web Services (AWS), providing a secure and resilient cloud infrastructure.
Infrastructure security includes:
- Secure cloud hosting
- Network security controls
- Infrastructure monitoring
- Controlled administrative access
- Security patch management
- Regular platform maintenance
Physical security of the underlying infrastructure is managed by AWS in accordance with its published security standards.
6. Backup & Disaster Recovery
Softhealer Technologies Pvt. Ltd. maintains backup and recovery procedures designed to support business continuity and minimise service disruption.
Current practices include:
- Daily automated database backups
- Redundant storage for user-generated files, including screenshots
- Disaster recovery procedures for restoring customer data from the latest available backup
Our current Recovery Time Objective (RTO) is within a few hours, depending on the nature of the incident.
7. Secure Software Development
Security is incorporated throughout the software development lifecycle.
Our development practices include:
- Secure software design
- Secure coding practices
- Code reviews
- Dependency management
- Regular software maintenance
- Continuous platform improvements
Security considerations are evaluated before new functionality is released into production.
8. Vulnerability Management
Security is an ongoing process.
Softhealer Technologies Pvt. Ltd. continually reviews Monitor360 to identify, assess and address potential security risks.
Our vulnerability management activities include:
- Security reviews
- Risk assessments
- Dependency updates
- Security patches
- Platform maintenance
- Continuous improvement of security controls
9. Security Incident Response
Softhealer Technologies Pvt. Ltd. maintains documented procedures for identifying, investigating and responding to security incidents.
Our incident response process includes:
- Identification of potential security events
- Assessment of business impact
- Containment and remediation
- Recovery of normal operations
- Customer communication where required by applicable law or contractual obligations
Incident response procedures are reviewed periodically to support continuous improvement.
10. Compliance & Certifications
Softhealer Technologies Pvt. Ltd. is committed to maintaining internationally recognised standards for information security, quality management and data protection.
Certified Management Systems
Softhealer Technologies Pvt. Ltd. maintains the following certifications:
- ISO/IEC 27001:2022 – Information Security Management System (ISMS) (Cert. 26MEQXN18)
- ISO 9001:2015 – Quality Management System (QMS) (Cert. 26MEQXG22)
- SOC 2 Type II – System and Organisation Controls 2 (Cert. EU/SOC/00878)
- SOC 1 Type II – System and Organisation Controls 1 (Cert. EU/SOC/00879)
These certifications demonstrate our commitment to internationally recognised best practices for information security, operational excellence and continual improvement.
Privacy & Compliance
Monitor360 is designed to support organisations operating under recognised privacy and regulatory frameworks, including:
- General Data Protection Regulation (GDPR)
- Health Insurance Portability and Accountability Act (HIPAA)
- Data Processing Agreements (DPA) for eligible business customers
11. Shared Responsibility
Security is a shared responsibility between Softhealer Technologies Pvt. Ltd. and our customers.
Softhealer Technologies Pvt. Ltd. is responsible for:
- Operating and securing the Monitor360 platform
- Maintaining secure cloud infrastructure
- Protecting customer information processed through our services
- Applying security updates and maintenance
- Managing backup and disaster recovery procedures
- Maintaining certified security and quality management systems
Customers are responsible for:
- Protecting user credentials
- Assigning administrator permissions appropriately
- Configuring monitoring features according to organisational policies
- Informing employees about workplace monitoring where required by applicable law
- Maintaining their own internal security and compliance programmes
12. Continuous Improvement
Security is not a one-time activity—it is an ongoing commitment.
Softhealer Technologies Pvt. Ltd. continually reviews and enhances Monitor360 to improve platform security, operational resilience and customer protection.
As technology, regulatory requirements and customer expectations evolve, we remain committed to strengthening our security practices and continuously improving our platform.
13. Contact Us
If you have questions regarding Monitor360's security practices, compliance programme or wish to report a security concern, please Contact Us using the contact information available on our website.
We welcome responsible disclosure of security vulnerabilities and are committed to investigating all legitimate security reports promptly.