Trust & security

Financial-services-grade data protection, built in

We work with banks, NBFCs, fintechs, and financial-services GCCs: organisations that are themselves regulated and that assess every vendor's data handling. PeopleCap is built to meet that bar: independently certified, engineered for India's data-protection law, with your primary data hosted in India.

  • ISO/IEC 27001:2022 certified
  • Built for the DPDP Act 2023
  • Primary data hosted in India
  • AI under zero-retention contract

Why this matters for the firms we serve

People advisory means handling some of the most sensitive data an organisation has: candidate identities and compensation, hiring plans, and, in our fractional-HR work, an organisation's own people data. Our clients are regulated firms that are accountable for the vendors they use. So we hold ourselves to the standard they are held to: an independently certified security programme, a data-protection posture aligned to Indian law, and a clear answer to the question every procurement and information-security team asks: where does our data go, and how is it protected?

This page is a plain-language overview. Clients and prospective clients running a security or vendor review can request our certificate, sub-processor register, and a fuller security summary under NDA. See the last section.

Certifications and standards

Independently certified, and built ahead of the law.

Information security

ISO/IEC 27001:2022 certified

N53 Techworks LLP, which operates PeopleCap, holds a valid ISO/IEC 27001:2022 certification for the information security management system covering the operations under which the practice is run. ISO/IEC 27001 is the international standard for managing information security through documented policies, risk assessment, access control, monitoring, and continual improvement, verified by an accredited certification body. The certificate is available to clients on request.

Data protection

Built for India's DPDP Act 2023

India's Digital Personal Data Protection Act 2023 and its 2025 Rules bring substantive obligations into force in May 2027. Rather than wait, we have already built and are operating the controls the Act requires: notice and consent, data-principal rights, grievance redressal, breach response, and defined retention. We describe how in our Privacy Policy, and we adjust as the implementing rules are finalised.

Where your data lives

Your data is stored in India, in the Mumbai (ap-south-1) region: the database and the files you upload rest there. For regulated buyers who require Indian residency for their data at rest, that is the default, not an add-on.

Two things about processing we would rather state plainly than imply away. The platform's application compute runs from Singapore, which means request processing happens outside India before data comes to rest in Mumbai. Separately, two narrowly defined activities use providers outside India under contract: transactional email delivery, and limited AI text processing (résumé and job-description text needed for parsing and matching) under an enterprise data-processing agreement with a zero-retention posture. Our most sensitive content is never sent to external AI at all. Each of these cross-border steps, the providers, their regions, and their purposes, is named and disclosed in our Privacy Policy.

How we protect data

The controls behind every engagement, in plain terms.

Access control

Least privilege, and client isolation

Access is role-based and least-privilege: people and systems see only the data their role requires. Client users are isolated to their own engagements, so one client's data is never visible to another, and a confidentiality wall keeps sensitive HR-advisory content out of any cross-client analytics.

Authentication

Passwordless by design

There are no stored passwords to leak. Everyone, our team and client users, signs in with a single-use one-time code sent to their email, and sessions expire automatically. There is no public self-signup; access is provisioned deliberately.

Encryption and storage

Encrypted in transit and at rest

Data is encrypted in transit (TLS) and at rest. Uploaded files, including résumés, live in private storage and are served only through short-lived signed links, never public URLs.

Audit and monitoring

An append-only record, monitored continuously

Actions on personal data are written to an append-only audit trail that no one, including administrators, can edit or delete, retained for at least a year. Automated monitoring alerts us to failures, and authentication events are logged distinctly.

Incident response

A documented breach-response process

We maintain a breach register and an incident-response runbook: contain, preserve evidence, assess, notify, and record. Where a breach is likely to cause significant harm, we notify the Data Protection Board of India and the affected individuals in line with the DPDP Rules.

Data minimisation

Held only while needed, then erased

We keep personal data while the recruitment or engagement purpose is live, then erase it, with documents and logs held on defined timers. Erasure removes the identifying data and physically deletes stored files. We hold no dates of birth or age data, and run no behavioural tracking or targeted advertising.

AI, used responsibly

AI helps our team work faster: parsing résumés, structuring information, and suggesting how a candidate fits a role. It does not decide anything about a person on its own. A member of our practice reviews any AI-derived output before it is acted on for a decision that materially affects a candidate or client, and we do not use AI for automated decision-making, profiling, or targeted advertising.

Where a feature sends text to our AI provider, it does so under an enterprise data-processing agreement with a zero-retention posture: your information is not retained by the provider and is not used to train its models. Our most sensitive content is technically prevented from being sent to external AI at all. Candidates and clients can ask us about AI-derived processing of their data at any time.

For security and procurement teams

If you are running a vendor security assessment, we are glad to support it. On request, and under NDA where appropriate, we can share our ISO/IEC 27001:2022 certificate, our sub-processor register, a DPDP readiness summary, and a security overview, and we will work through your information-security questionnaire.

Write to privacy@peoplecap.in for data-protection and security questions. Grievances can be raised with our Grievance Officer at grievance@peoplecap.in. For candidates: your profile is yours. You control your consent, we never share it with a client without your consent for that specific role, and you can withdraw or ask us to delete it at any time. See the Privacy Policy and Terms of Use for the detail.

Running a vendor security review?

Tell us what your security and procurement teams need. We will walk you through our controls and share our documentation under NDA.

Talk to us about security

ISO/IEC 27001:2022 certified. Primary data hosted in India. Built for the DPDP Act 2023.

Send us a brief