Skip to content

WebCastle Trust Center

Security & Trust at WebCastle

WebCastle builds and operates software for organisations that depend on it. Encryption, access control, environment separation and reviewed deployments are in place today. This Trust Center documents every one of those controls in full — including the areas still being formalized — so your security review can be completed from published information rather than a sales call.

  • Encrypted in transit and at rest
  • MFA on administrative access
  • Separate dev, staging and production
  • Reviewed changes to production
108
Controls published

Across 9 security domains

89
Operating today

82% of published controls are applied in day-to-day delivery

35
Established practice

Operating as a consistent, repeatable practice

19
Not yet in place

Under evaluation or on the roadmap, and named as such

These figures are generated from the control descriptions published on this site, not stated separately. Every control counted above is named, described and given a status on its practice page, so the numbers can be checked against the detail rather than taken on trust.

Overview

Security at WebCastle

A practical security program built around the way WebCastle actually delivers and operates software.

Reviewed 12 August 2026

This Trust Center is maintained by WebCastle and reflects the security program as assessed at the date above.

WebCastle Media Pvt. Ltd. designs, builds and operates websites, applications and custom software. Much of that work involves handling data that belongs to our customers and their users, so security is treated as part of delivery rather than as a separate function bolted on at the end.

Responsibility for security sits with WebCastle’s technical leadership. Day-to-day controls are applied by the engineering and infrastructure teams who build and run the systems, which keeps decisions close to the people with the most context. Access to production environments is deliberately narrow, changes reach production through review, and customer environments are kept logically separate from one another.

WebCastle is currently formalizing its security program: writing down practices that already operate informally, closing the gaps that review has surfaced, and establishing the documentation that enterprise customers reasonably expect. This Trust Center reports that work honestly. Where a control is established, it says so. Where a control is still being formalized, it says that too.

In place today

What is in place today

These controls operate across WebCastle-managed services now. They are not aspirations, and they are the same controls WebCastle describes when completing a customer security questionnaire.

  • Encryption in transit

    TLS/HTTPS protects data moving between users, applications and services that WebCastle operates.

  • Encryption at rest

    Storage and managed databases use cloud provider managed encryption by default.

  • Multi-factor authentication

    MFA is enforced on cloud provider consoles, source control and other critical administrative services.

  • Narrow production access

    Production access is held by a limited group of technical personnel and granted per engagement, not by default.

  • Environment separation

    Development, staging and production are separate environments with separate access.

  • Peer code review

    Changes reach production through review by another engineer as a routine part of the workflow.

  • Customer data segregation

    Each customer project is kept logically separate from every other customer environment.

  • Managed backups

    Databases and storage use the cloud provider’s native backup capabilities for the services WebCastle operates.

  • Named individual accounts

    Access is granted to named accounts on business systems rather than shared logins.

  • Confidentiality obligations

    Employment contracts carry confidentiality obligations, and WebCastle will sign a customer NDA.

  • Accountable security ownership

    Security is owned by WebCastle’s technical leadership, with a monitored security contact for customers.

  • A working incident process

    WebCastle identifies, contains, investigates and communicates security incidents today, and will notify affected customers.

Security maturity

Where the program is mature, and where it is being formalized

WebCastle reports maturity on two axes, because a single status hides the distinction that matters. “In practice” is whether the control is applied today. “Documentation” is whether it has been written up and approved. Across most areas the controls operate and the paperwork is what is being completed.

WebCastle security program maturity by area, reported on two axes: whether the control is applied in practice today, and whether it has been documented and approved.
AreaIn practiceDocumentationNotes
Information SecurityOperatingDraftingGovernance and ownership are defined and exercised; the written policy set is being drafted.
Access ControlOperatingIn reviewMFA and narrow production access operate today; a scheduled review cycle is being established.
Application SecurityOperatingDraftingCode review and environment separation are routine; security testing is being formalized.
Infrastructure SecurityOperatingDraftingManaged cloud infrastructure with encryption in place; monitoring coverage is expanding.
Data ProtectionOperatingIn reviewEncryption and customer segregation are established; retention schedules are being documented.
Incident ResponseOperatingIn reviewA working response process is followed today; the written plan is being completed.
Business ContinuityPartialDraftingManaged backups are in place; recovery planning and restoration testing are being developed.
Vendor SecurityPartialDraftingVendors are selected by technical leadership; a structured review process is being built.
Employee SecurityOperatingDraftingConfidentiality obligations and managed accounts apply; an awareness program is in development.
ComplianceNot yetPlannedFramework alignment is under assessment. WebCastle holds no certifications today and does not imply otherwise.

In practice — is the control applied today?

Operating
The control is applied in day-to-day delivery and operations today.
Partial
Applied in some environments or engagements, not yet across the estate.
Not yet
Not currently applied. Under evaluation or on the roadmap.

Documentation — has it been written up and approved?

Approved
A written policy has completed management approval and is in force.
In review
Drafted and moving through internal review ahead of approval.
Drafting
Being written up from the practices already in operation.
Planned
Scheduled for drafting as the security program develops.

This table reflects WebCastle’s assessment of its own program as at the review date shown in the footer. It is not an audited or independently verified rating, and WebCastle publishes it precisely so a reviewer can see the gaps rather than have to find them.

Questions this Trust Center does not answer?

WebCastle responds to customer security questionnaires, supports security reviews during procurement, and will sign an NDA where the discussion calls for it. Send the specifics and the security team will come back to you.