Trust

Security Statement

PremierCore Solutions (Private) Limited · Effective 1 August 2026 · Last updated 4 August 2026

What we have in place today, what is still on the roadmap, and how we handle client data on the delivery floor and in our systems.

Language: this document is published in English. Any translated version is provided for convenience only — the English text is the authoritative version and prevails in the event of any inconsistency.

Contents
  1. Our posture, stated plainly
  2. Certification status
  3. Governance
  4. People and the delivery floor
  5. Access control
  6. Data protection
  7. Network and endpoint
  8. Application and development security
  9. AI systems
  10. Vendor management
  11. Resilience and continuity
  12. Incident response
  13. What we ask of clients
  14. Reporting a vulnerability

1. Our posture, stated plainly

Security questionnaires are where outsourcing deals stall, usually because a vendor overstates its position and then cannot evidence it. We would rather tell you exactly where we are.

What is in place today: documented policies, role-based access control, encryption in transit and at rest, multi-factor authentication across all staff accounts and on administrative, privileged and remote access, signed confidentiality agreements for every member of staff, controlled delivery-floor operations, logging and a defined incident response procedure.

What is not yet in place: we do not hold a SOC 2 Type II report or ISO 27001 certification. Both are on the roadmap with the status shown below, and we will not claim either until an auditor has issued it. Independent penetration testing is not yet a scheduled recurring exercise — we run vulnerability scanning in the build pipeline for software we develop, and we will arrange an independent test for a specific engagement where a client requires it.

2. Certification status

FrameworkStatusDetail
SOC 2 Type IIPlannedControls implementation underway. Audit window targeted for 2026. No report currently exists.
ISO/IEC 27001In progressISMS scoping in progress. Not yet certified.
GDPR / UK GDPRAlignedData Processing Agreements available. Standard Contractual Clauses used for restricted transfers. Records of processing maintained.
HIPAAAlignedBusiness Associate Agreement available for healthcare engagements. PHI handling training delivered before assignment to a healthcare program.
PCI DSSScopedWhere payment data is in scope we work through compliant payment processors and pause-and-resume call recording rather than storing cardholder data.

3. Governance

4. People and the delivery floor

5. Access control

6. Data protection

7. Network and endpoint

8. Application and development security

9. AI systems

10. Vendor management

Sub-processors and platform vendors are assessed before onboarding and reviewed periodically. Each is engaged under written contract with confidentiality and data protection obligations. A current sub-processor list is available to clients on request, and material changes are notified in line with the applicable DPA.

11. Resilience and continuity

12. Incident response

We maintain a documented incident response procedure covering detection, triage, containment, eradication, recovery and post-incident review. In the event of a confirmed personal data breach affecting a client, we notify that client without undue delay and within any period specified in the applicable agreement, and support them in meeting their own regulatory notification obligations.

13. What we ask of clients

Security is shared. We ask clients to provision access on a least-privilege basis, to notify us promptly of leavers on their side, to keep DPAs and BAAs current, and to tell us in advance when a program's data classification changes.

14. Reporting a vulnerability

If you believe you have found a security vulnerability in this website or in any system we operate, please report it to info@premiercore.solutions with "Security" in the subject line.

Please give us a reasonable opportunity to investigate and remediate before public disclosure. We will acknowledge your report and keep you updated. We will not pursue action against researchers who act in good faith, avoid privacy violations and service disruption, and do not access or modify data beyond what is needed to demonstrate the issue.