WebCastle Trust Center
Security & Trust at WebCastle
WebCastle builds and operates software for organisations that depend on it. Encryption, access control, environment separation and reviewed deployments are in place today. This Trust Center documents every one of those controls in full — including the areas still being formalized — so your security review can be completed from published information rather than a sales call.
- Encrypted in transit and at rest
- MFA on administrative access
- Separate dev, staging and production
- Reviewed changes to production
- 108
- Controls published
- 89
- Operating today
- 35
- Established practice
- 19
- Not yet in place
Across 9 security domains
82% of published controls are applied in day-to-day delivery
Operating as a consistent, repeatable practice
Under evaluation or on the roadmap, and named as such
These figures are generated from the control descriptions published on this site, not stated separately. Every control counted above is named, described and given a status on its practice page, so the numbers can be checked against the detail rather than taken on trust.
Overview
Security at WebCastle
A practical security program built around the way WebCastle actually delivers and operates software.
Reviewed 12 August 2026
This Trust Center is maintained by WebCastle and reflects the security program as assessed at the date above.
WebCastle Media Pvt. Ltd. designs, builds and operates websites, applications and custom software. Much of that work involves handling data that belongs to our customers and their users, so security is treated as part of delivery rather than as a separate function bolted on at the end.
Responsibility for security sits with WebCastle’s technical leadership. Day-to-day controls are applied by the engineering and infrastructure teams who build and run the systems, which keeps decisions close to the people with the most context. Access to production environments is deliberately narrow, changes reach production through review, and customer environments are kept logically separate from one another.
WebCastle is currently formalizing its security program: writing down practices that already operate informally, closing the gaps that review has surfaced, and establishing the documentation that enterprise customers reasonably expect. This Trust Center reports that work honestly. Where a control is established, it says so. Where a control is still being formalized, it says that too.
In place today
What is in place today
These controls operate across WebCastle-managed services now. They are not aspirations, and they are the same controls WebCastle describes when completing a customer security questionnaire.
Encryption in transit
TLS/HTTPS protects data moving between users, applications and services that WebCastle operates.
Encryption at rest
Storage and managed databases use cloud provider managed encryption by default.
Multi-factor authentication
MFA is enforced on cloud provider consoles, source control and other critical administrative services.
Narrow production access
Production access is held by a limited group of technical personnel and granted per engagement, not by default.
Environment separation
Development, staging and production are separate environments with separate access.
Peer code review
Changes reach production through review by another engineer as a routine part of the workflow.
Customer data segregation
Each customer project is kept logically separate from every other customer environment.
Managed backups
Databases and storage use the cloud provider’s native backup capabilities for the services WebCastle operates.
Named individual accounts
Access is granted to named accounts on business systems rather than shared logins.
Confidentiality obligations
Employment contracts carry confidentiality obligations, and WebCastle will sign a customer NDA.
Accountable security ownership
Security is owned by WebCastle’s technical leadership, with a monitored security contact for customers.
A working incident process
WebCastle identifies, contains, investigates and communicates security incidents today, and will notify affected customers.
Security domains
The areas our security program covers
Each domain has a dedicated page describing the controls in place, the controls being formalized, and what that means for customers.
Information Security
Governance, ownership, risk management and the policy work underpinning the program.
Read moreAccess Control
Account lifecycle, least privilege, privileged access, MFA and access reviews.
Read moreApplication Security
Secure development, code review, dependency management and deployment controls.
Read moreInfrastructure Security
Cloud hosting, network security, encryption, monitoring and infrastructure access.
Read moreData Protection
How customer data is classified, stored, transmitted, retained and deleted.
Read moreIncident Response
How WebCastle identifies, contains, investigates and communicates security incidents.
Read moreBusiness Continuity
Backups, recovery planning, service restoration and communication during disruption.
Read moreVendor Security
Third-party selection, oversight, data processors and subprocessor transparency.
Read moreSecurity maturity
Where the program is mature, and where it is being formalized
WebCastle reports maturity on two axes, because a single status hides the distinction that matters. “In practice” is whether the control is applied today. “Documentation” is whether it has been written up and approved. Across most areas the controls operate and the paperwork is what is being completed.
| Area | In practice | Documentation | Notes |
|---|---|---|---|
| Information Security | Operating | Drafting | Governance and ownership are defined and exercised; the written policy set is being drafted. |
| Access Control | Operating | In review | MFA and narrow production access operate today; a scheduled review cycle is being established. |
| Application Security | Operating | Drafting | Code review and environment separation are routine; security testing is being formalized. |
| Infrastructure Security | Operating | Drafting | Managed cloud infrastructure with encryption in place; monitoring coverage is expanding. |
| Data Protection | Operating | In review | Encryption and customer segregation are established; retention schedules are being documented. |
| Incident Response | Operating | In review | A working response process is followed today; the written plan is being completed. |
| Business Continuity | Partial | Drafting | Managed backups are in place; recovery planning and restoration testing are being developed. |
| Vendor Security | Partial | Drafting | Vendors are selected by technical leadership; a structured review process is being built. |
| Employee Security | Operating | Drafting | Confidentiality obligations and managed accounts apply; an awareness program is in development. |
| Compliance | Not yet | Planned | Framework alignment is under assessment. WebCastle holds no certifications today and does not imply otherwise. |
In practice — is the control applied today?
- Operating
- The control is applied in day-to-day delivery and operations today.
- Partial
- Applied in some environments or engagements, not yet across the estate.
- Not yet
- Not currently applied. Under evaluation or on the roadmap.
Documentation — has it been written up and approved?
- Approved
- A written policy has completed management approval and is in force.
- In review
- Drafted and moving through internal review ahead of approval.
- Drafting
- Being written up from the practices already in operation.
- Planned
- Scheduled for drafting as the security program develops.
This table reflects WebCastle’s assessment of its own program as at the review date shown in the footer. It is not an audited or independently verified rating, and WebCastle publishes it precisely so a reviewer can see the gaps rather than have to find them.
Find what you need
Start where your question does
Running a security review
Start with security practices for the control-by-control detail, then check compliance for our certification position.
Security practicesAnswering a questionnaire
The FAQ covers the questions procurement and security teams ask most often, with conservative, quotable answers.
Security FAQReporting a security issue
Found a vulnerability in a WebCastle property? Our disclosure page explains how to report it and what happens next.
Vulnerability disclosureQuestions this Trust Center does not answer?
WebCastle responds to customer security questionnaires, supports security reviews during procurement, and will sign an NDA where the discussion calls for it. Send the specifics and the security team will come back to you.