Trust

Security Statement

PremierCore Solutions (Private) Limited · Effective 1 August 2026 · Last updated 6 September 2026

What is in place today, what is being built, and what is on the roadmap. We are a young operation and we would rather give you a short list you can verify on a call than a long one you cannot. This page is dated and is updated as controls go in.

Language: this document is published in English. Any translated version is provided for convenience only, the English text is the authoritative version and prevails in the event of any inconsistency.

Contents
  1. Our posture, stated plainly
  2. In place today
  3. In progress
  4. Roadmap
  5. Certification status
  6. How client and customer data is handled
  7. AI systems
  8. Incident response
  9. What we ask of clients
  10. Reporting a vulnerability

1. Our posture, stated plainly

Security questionnaires are where outsourcing deals stall, usually because a vendor overstates its position and then cannot evidence it. We would rather tell you exactly where we are.

What we are: a delivery operation in Lahore, contracting through a US commercial entity, running voice sales and customer experience programmes on our own operations platform.

What we do not hold: a SOC 2 report, ISO 27001 certification or an independent penetration test. Each is on the roadmap below, and we will not claim any of them until an auditor or tester has issued it.

2. In place today

Each item below can be shown to you on a call: the signed document, the setting, the log.

3. In progress

4. Roadmap

5. Certification status

FrameworkStatusDetail
SOC 2 Type IIRoadmapNo report exists. Controls are being put in place first; audit timing depends on client demand.
ISO/IEC 27001RoadmapNot certified. Same basis as SOC 2.
GDPR / UK GDPROn requestNo EU or UK personal data is processed today. A Data Processing Agreement is put in place with the first engagement that needs one.
HIPAAOn requestNo protected health information is processed today. A Business Associate Agreement and PHI training precede any healthcare engagement.
PCI DSSOut of scope by designWe do not store, process or transmit cardholder data in our own systems. Where a customer gives payment details, they are entered directly into the client's or provider's portal. The recording is paused while they are given (section 2).

6. How client and customer data is handled

7. AI systems

8. Incident response

If we confirm a security incident or personal data breach affecting a client, we notify that client without undue delay and within any period specified in the applicable agreement, tell them what we know and what we are doing about it, and support them in meeting their own regulatory notification obligations. A written incident procedure is part of the in-progress work in section 3.

9. What we ask of clients

Security is shared. We ask clients to provision access on a least-privilege basis, to notify us promptly of leavers on their side, to keep any DPAs and BAAs current, and to tell us in advance when a programme's data classification changes.

10. Reporting a vulnerability

If you believe you have found a security vulnerability in this website or in any system we operate, please report it to Info@premiercore.solutions with "Security" in the subject line.

Please give us a reasonable opportunity to investigate and remediate before public disclosure. We will acknowledge your report and keep you updated. We will not pursue action against researchers who act in good faith, avoid privacy violations and service disruption, and do not access or modify data beyond what is needed to demonstrate the issue.