Security at Archonova
Security is part of how we design systems rather than something added at the end. This page describes the practices we apply to our own operations and to the environments we build and run for clients.
Last updated July 2026
Architecture
We design to zero-trust principles: no implicit trust between networks or services, least-privilege access by default, segmentation between environments, and explicit authentication and authorisation at every boundary. Security requirements are captured at architecture stage, not retrofitted after go-live.
Hosting and data location
Workloads run on major public clouds or on Archonova-operated VPS and dedicated infrastructure across our datacenter regions. Where a client has data-residency requirements, we select the region and provider to match them and state the location in the engagement documentation.
Access control
- Named accounts for every engineer — no shared credentials.
- Multi-factor authentication on administrative and remote access.
- Access granted per engagement, reviewed periodically and revoked on exit.
- Secrets held in managed secret stores, never in source control.
Encryption
Traffic to this website and to systems we operate is served over TLS. Data at rest is encrypted using the storage-level encryption offered by the underlying platform. Specific cryptographic controls for a given environment are documented for that engagement.
Monitoring and patching
Managed environments are monitored for availability and anomalous activity, with patching and update cycles agreed per environment. Findings are triaged by severity, and critical issues are addressed ahead of scheduled maintenance windows.
Incident response
If we identify or are notified of a security incident affecting a client environment, we contain it, investigate the cause, notify the affected client without undue delay, and follow up with remediation steps. Notification timelines and escalation contacts are agreed in the engagement contract.
Shared responsibility
Security is shared. Cloud and licensing providers secure their platforms; Archonova secures what we design, deploy and operate; clients remain responsible for their own user accounts, endpoint hygiene, internal approvals and any systems outside our scope. The boundary for each engagement is written down before work begins.
Reporting a vulnerability
If you believe you have found a security issue in this website or in a system we operate, email info@archonovasystems.com with the subject line "Security disclosure" and enough detail to reproduce it. Please do not publicly disclose the issue until we have had a reasonable opportunity to respond, and do not access or modify data that is not yours while testing.
Questions about this page?
Write to info@archonovasystems.com or call +91 78377 94951. Archonova Systems OPC Private Limited, Bhutani Alphathum, Tower-B, 603-604, Sector 90, Noida, 201304, India.
This page is maintained by Archonova Systems and describes our current practices. It is not a certification or an independent audit result. Where a signed agreement exists with a client, the terms of that agreement take precedence.