SOJA Time & Attendance Logo
Security

SOJA TA Platform Security Policy

Effective Date: Sep 09, 2026
Version: 1.1

At Identigate Integrated Solutions Limited ("Identigate," "the Company," "we," "us," or "our"), the protection of your organizational workforce logs and identity assets is paramount. This Security Policy defines the technical, physical, and administrative guardrails established to safeguard data managed through the SOJA Time & Attendance (SOJA TA) web ecosystem and server infrastructure. Our security framework aligns with recognized industry good practices, including the ISO/IEC 27001 standard.

1. Data Encryption & Communication Domain

  • Data in Transit: All communications between on-site biometric edge terminals, client web browsers, mobile applications, and our central web servers are systematically protected by strong authentication and encryption via HTTPS, SSL, and TLS network protocols.
  • Data at Rest: Critical data elements, including database backups, log metrics, and configuration states, are stored in encrypted form using strong, industry-accepted algorithms. Passwords are saved strictly using robust, one-way secure hash functions.
  • Biometric Vector Isolation: Raw biometric images captured during check-ins are processed strictly on local input edge terminals and are immediately destroyed after mathematical feature vector extraction; plain text biometric data is never transmitted or stored on our web infrastructure.

2. Logical Access Controls & Authentication

  • Identity Protection: Every administrator and user account is allocated a unique User ID and complex password configuration. Systems enforce secure log-on and maintain automated self-service password reset controls.
  • Principle of Least Privilege: System privileges are segregated based on job descriptions and explicit user roles. Administrative accounts are separated from normal business profiles to minimize operational risk.
  • Session and Account Defenses: Web instances detect unsuccessful log-on attempts and automatically lock out accounts after a configurable threshold. Inactive user web sessions automatically timeout and require re-authentication after a set duration of inactivity.

3. Cloud Infrastructure & Environmental Security

  • Cloud Segregation: The SOJA TA web ecosystem is hosted within vetted cloud service environments subject to thorough security and data residency assessments. Access to cloud administration consoles requires multi-factor authentication (MFA) and is restricted to approved technical personnel.
  • Network Layer Defense: Internal and external infrastructure boundaries are segmented by enterprise firewalls to prevent unauthorized network entry. Network traffic is monitored continuously via network intrusion detection and prevention systems.
  • Data Segregation: Data utilized for platform testing, staging, and feature development is strictly depersonalized or anonymized using dummy data sets to isolate it completely from active production systems.

4. Vulnerability Management & Antivirus Controls

  • Patch Management: Critical and high-severity security vulnerabilities impacting internet-facing systems are actively monitored and mitigated through systematic risk-prioritized testing and deployment cycles.
  • Malicious Code Defenses: Antivirus software is deployed across the computing environment, actively running, and kept up to date. All emails (incoming and outgoing) and file attachments are scanned to block viruses, malware, or ransomware.

5. Robust Logging & Audit Trails

The SOJA TA platform maintains a tamper-resistant system log framework tracking audit trails across all operational layers (operating system, database, and application level). System logs capture details including:

  • Source User IDs, IP addresses, and timestamps for all log-on events.
  • Successful and unsuccessful authentication attempts.
  • Changes to user access permissions, modifications to system configurations, or deletions.
  • Log files are structurally protected against modification or overwrite, even by super-user accounts, through maximum log size allocations and secure offline archival.

6. Business Continuity & Incident Handling

  • System Backups: Automated backups cover system data, frequently modified user logs, and activity logs. Backup assets are encrypted in transit and at rest, and are restricted to a dedicated server environment to support recovery in the event of any service disruption.
  • Incident Management & Escalation: In the event of a verified or suspected security incident affecting customer data structures, we maintain a critical IT incident management framework to guide escalation paths, decision-making, and prompt remediation steps.

Security Verification Inquiries

To request technical security whitepapers, review our data processor obligations under the Data Protection Act, or report a suspected vulnerability, please reach our technical operations unit at [email protected].