Security Questionnaire

Security questions, answered clearly

Review AITC International's security, privacy, compliance and software delivery practices for vendor due diligence, organized the way a questionnaire is, so you don't have to chase answers down one email at a time.

  • ISO 9001:2015 certified
  • AES-256 encryption at rest
  • MFA enforced on accounts

1. Compliance & Certifications

Is AITC International ISO 9001:2015 certified?+

Yes. AITC International is ISO 9001:2015 certified. This is a quality-management certification, not an information-security certification. Review the certificate for the legal entity, scope and validity relevant to your assessment.

Is AITC ISO/IEC 27001 certified?+

No. ISO/IEC 27001 certification is in progress and is not currently held.

Can AITC provide Standard Contractual Clauses for EU data transfers?+

Yes, Standard Contractual Clauses (SCCs) are available on request, subject to review of the proposed transfer. The agreement needs the applicable European Commission-approved clauses, modules and completed annexes, rather than custom-written clauses presented as SCCs.

Can client data be hosted in an EU region?+

Yes. EU-region hosting is available on request.

2. Data Protection & Privacy

Does AITC act as a data controller or data processor?+

When handling personal data on a client's instructions, AITC acts as a processor. A data processing agreement (DPA) is signed before that processing begins. The agreement should identify each party's role for the actual processing arrangement.

How is client data encrypted?+

Our specified encryption standards are AES-256 at rest and TLS 1.2 or TLS 1.3 in transit.

Is production data used in development or testing?+

In client-hosted environments, development and testing use anonymised or synthetic test data. Production access and non-production data handling should be reviewed separately for the engagement.

Can we review AITC's sub-processor list?+

Yes. A current sub-processor list is available on request.

3. Identity & Access Management

Does AITC enforce multi-factor authentication?+

Yes. Multi-factor authentication (MFA) is part of our account-access controls. For a formal assessment, confirm enforcement coverage for the relevant systems, client-managed accounts, non-interactive service identities and any documented exceptions.

How does AITC apply least-privilege access?+

Access is granted according to the permissions needed for a person's role. Administrative or production access should be assessed separately from ordinary project access when defining the permissions required for your engagement.

How is access managed when someone joins, changes roles or leaves?+

AITC uses a joiner-mover-leaver process to manage access changes and revocation. Confirm which systems each party controls so the offboarding arrangements cover both AITC-managed access and access granted directly by your organisation.

Is privileged or administrator access reviewed?+

Yes. Privileged and administrator access is reviewed regularly. The review cadence and supporting records can be confirmed during your assessment.

Does AITC support enterprise SSO and SAML?+

Yes. Enterprise single sign-on (SSO) and SAML support are available. Compatibility with your identity provider and the systems in scope needs to be confirmed for the engagement.

Does AITC use a Zero Trust architecture?+

Our stated controls include MFA and least-privilege access. Those controls alone do not establish a complete Zero Trust architecture. Request architecture-specific evidence where your assessment requires confirmation of that model.

How are passwords, API keys and other secrets managed?+

Credentials and secrets are handled through dedicated vault-based management rather than stored or shared in plaintext. The approved vault and access arrangements should be identified for the engagement.

4. Endpoint & Network Security

Are Data Loss Prevention controls available?+

Yes. Data Loss Prevention (DLP) controls are available where required by the client. Their scope must be agreed for the engagement; availability should not be interpreted as confirmation that the same DLP configuration is deployed across every device and service.

Are employee devices centrally managed?+

Microsoft Intune-based device management is available where required. Confirm which devices are enrolled and which policies apply to your engagement instead of assuming that a project-specific arrangement covers every company device.

Are company devices encrypted and company-managed?+

Yes. Company devices are encrypted and company-managed. During your assessment, identify the devices permitted to access your systems and confirm the applicable access and management requirements.

5. Application & Infrastructure Security

Where can AITC deploy software, and how is infrastructure access controlled?+

Deployment options include AWS, Microsoft Azure, on-premise and hybrid environments. Infrastructure access uses the access controls applicable to the chosen platform; the AWS setup described in our questionnaire uses IAM users and roles. Confirm hosting ownership, region and access responsibilities for your deployment.

How does AITC identify and manage software vulnerabilities?+

We use regular automated vulnerability scanning. Testing includes static and dynamic analysis, dependency checks and severity-based remediation. The testing scope and remediation commitments for your application need to be confirmed in the delivery and support arrangements.

Does AITC perform penetration testing?+

Applications are penetration-tested before major releases, with findings remediated and retested. Confirm the testing scope, responsible tester and evidence available for your engagement. This does not imply a separate annual independent assessment of every company system.

Does AITC follow a secure software development lifecycle?+

Yes. Our secure software development lifecycle includes peer code review and separate development, staging and production environments. Security planning also includes threat modelling. The project's security requirements and release checks should be established before implementation.

What security checks are included in the CI/CD pipeline?+

Pipelines combine SAST, dependency and secrets scanning with automated tests and SonarQube quality gates. These checks help identify findings before release; they are not a guarantee that software contains no vulnerabilities. Confirm the enabled checks and acceptance criteria for your repository.

6. Business Continuity & Incident Response

What recovery time and recovery point objectives does AITC offer?+

Recovery time objectives (RTOs) and recovery point objectives (RPOs) are agreed per system. RTO describes the targeted restoration time; RPO describes the targeted limit on data loss measured in time. Confirm both against the application’s backup and recovery design rather than treating one figure as universal.

How does AITC maintain delivery during an office or connectivity disruption?+

Continuity measures include remote-work fallback, UPS and generator backup, and dual internet service providers. These measures support delivery operations. They should not be treated as the recovery plan or availability guarantee for a client's production application.

When will AITC notify us of a security incident?+

The notification timeline must be confirmed in the DPA and incident-response terms, alongside applicable legal obligations. Define the notification trigger, named contacts and update process before the engagement; a contract should not postpone a legally required notification.

Does AITC provide a post-incident report?+

Yes. A post-incident report is provided. The reporting scope and delivery timeline need to be agreed for the engagement rather than presented as one fixed deadline for every incident.

7. Monitoring & Governance

How long are application, audit and security logs retained?+

The stated retention baseline is 12 months for application and audit logs, and at least 90 days for security and access logs. Confirm the log categories, coverage and retention requirements for your environment, especially where the client controls the logging infrastructure.

Can clients track delivery work and review its history?+

Yes. Delivery work is tracked in Jira or Azure Boards. The project's chosen system should be identified so you know where to review work items and progress. Project tracking records are separate from application-security or access logs.

8. Physical & Organizational Security

Are employees background-checked before accessing client data?+

Yes. Employees are background-checked before being granted data access. The scope of those checks and any client-specific screening requirements should be confirmed during procurement.

Do employees receive security awareness training?+

Yes. Staff receive regular security awareness training. Request the training cadence and completion evidence needed for your vendor assessment.

9. Breach History & Audit Rights

Has AITC experienced a data breach or security incident?+

Please request a dated statement covering both confirmed data breaches and security incidents for your required reporting period. A statement about breaches alone should not be interpreted as confirmation that no other security incidents occurred.

Can clients request a right-to-audit clause?+

Commercial audit arrangements are discussed during contract review. The scope, notice and confidentiality terms need to be agreed, while any applicable statutory or data-processing audit rights must also be respected. Audit rights are not universally a matter of vendor discretion.

11. US State & UK-Specific Requirements

What is AITC's position on CCPA and CPRA requirements?+

CCPA/CPRA compliance work is on our roadmap. That is not confirmation that a particular engagement meets every applicable requirement. Where California personal information is involved, the processing activities, contractual role and applicable obligations need to be assessed before a compliance statement is made.

Does AITC hold Cyber Essentials or Cyber Essentials Plus?+

No. AITC does not currently hold Cyber Essentials or Cyber Essentials Plus certification. Tell us during procurement when either certification is a mandatory supplier requirement.

12. Multi-Tenancy & Client Isolation

How are client environments separated in shared infrastructure?+

Available options include logical separation using client-specific database tables or schemas, with dedicated AWS EC2 instances where required. The actual separation model and access restrictions need application-specific review. Cloud hosting or separate tables alone should not be treated as proof of effective tenant isolation.

13. AI Governance & Client Data

Does AITC use client data to train or fine-tune AI models?+

No. AITC does not use client data to train or fine-tune AI or machine-learning models. Third-party tools require a separate review of their data-use terms and configuration; this answer should not be read as an automatic guarantee about every provider.

How does AITC govern AI-assisted development tools?+

Third-party AI tools are used, and tool selection can be restricted to client requirements. AI-assisted code remains subject to review and quality checks. Client code and data stay within the agreed tooling environment. Confirm permitted tools and data handling before use.

14. Availability, Support & Change Management

Does AITC provide an uptime SLA?+

Yes. Uptime commitments are defined for the services covered by the agreed service-level agreement (SLA). The target, measurement period, exclusions and remedies need to be confirmed for the engagement; this page does not apply one uptime percentage to every project.

How are production changes approved?+

AITC uses a formal change-management and approval process for production changes. The people authorised to approve a change and the applicable release conditions should be identified for your engagement.

What support priorities and incident response times are available?+

Support priorities distinguish P1 production outages, P2 major issues, P3 minor issues and P4 cosmetic or low-priority issues. Acknowledgement times and coverage hours are set in the support agreement. An acknowledgement target is not the same as a resolution or service-restoration guarantee.

15. Company Information & Vendor Viability

When was AITC International founded?+

AITC International was founded in 2021. For vendor onboarding, request the registration details for the specific legal entity that will enter into your contract.

How large is AITC's in-house team?+

AITC has 100+ in-house staff, with approximately 70% in software engineering. Confirm the latest headcount and proposed project team during procurement; company-wide staffing is not the number of people allocated to an individual engagement.

Where are AITC's offices and entities located?+

AITC is headquartered in Bhaktapur, Nepal, with AITC FZCO in Dubai, UAE, and AITC Inc. in Texas, USA. Confirm the contracting entity, delivery locations and permitted data-access locations for your engagement.

Can we request employee or client retention information?+

Please specify whether you need employee retention, client retention or project-team continuity information, and the period to be assessed. These are different measures and should not be represented by one undefined retention percentage.

Can AITC share financial information for vendor due diligence?+

Financial summary information is available to qualifying clients under a non-disclosure agreement (NDA), on request. Share your due-diligence requirements so the scope of information can be discussed.

Security Questionnaire

Still have questions your security team wants answered?

Some answers here depend on the specifics of your contract or region. Talk to us directly and we will confirm exact figures, timelines and documentation for your engagement.

Connect with Us and Let's Build Something Together

We'd love to hear from you! Whether you have questions, need support, or want to discuss a new project, our team is ready to assist. Fill out the form below, and we’ll get back to you as soon as possible.

Direct Consultation

Prefer a Direct Consultation?

Connect with our team for a 1-on-1 virtual session to discuss your project, understand your needs, and explore the right solution for your business.

30-Minute Consultation

What's Next?

  1. 1Connect with you at a convenient time
  2. 2Explore your needs, goals, and requirements
  3. 3Prepare a tailored proposal based on your needs

Why Choose Us

Client-CentricResults-DrivenSecurity-FocusedSolution-OrientedTechnical ExpertiseTransparent Approach
Looking for job opportunities?
Explore Jobs

Connect with AITC

Select your inquiry type to route your request to the right department.

Phone
Your data is safe and fully encrypted under our policy.

Our Office Locations

Operating across 3 key timezone hubs to serve global enterprise clients.