Skip to content
Koddox Technologies
Home

Security & Compliance

Security responsibilities, project safeguards, AI controls and compliance scope for Koddox engagements.

Effective date: 28 September 2026

Scope and assurance

This policy explains the security responsibilities and requirements to establish for a Koddox engagement. It is a service framework, not an audit report or proof that every control is implemented in every environment. A signed agreement and security schedule define the controls and evidence applicable to your project.

No ISO certification, SOC attestation, PCI DSS validation or blanket GDPR or HIPAA compliance claim is made here. Ask for current evidence of any assurance required before relying on it. Building software for a regulated sector does not itself certify the software or its operator.

Responsibility before access

Identify the client system owner, Koddox delivery lead, authorized contacts, data categories, production access needs and incident escalation route before work starts. Document which party owns hosting, configuration, backups, licenses, monitoring and regulatory decisions.

Client-controlled accounts and environments remain subject to the client’s authorization. Access should be limited to approved work and removed when no longer needed. Subcontractor access and confidentiality requirements belong in the engagement terms.

Identity and access controls

The project security schedule should specify individual accounts, least-privilege roles, multi-factor authentication where supported, secure secret storage and access review. Shared credentials and credentials in source code should be avoided.

Production changes, sensitive exports and elevated access need an agreed approval path. Record who approved and performed consequential actions where the system supports it. At handover or termination, review access and rotate relevant secrets.

Data protection and development

Agree encryption requirements in transit and at rest, environment separation, test-data handling and the permitted tools for source code and confidential information. Prefer synthetic or minimized data in development.

Define peer review, dependency checks, security testing, release approval and remediation ownership appropriate to the application. A vulnerability scan is not a complete penetration test; independent testing and its scope must be explicitly commissioned where needed.

AI and automation controls

Before connecting models or agents to business data, agree approved providers, processing regions, retention settings and permitted use of submitted data. Do not assume an AI provider excludes all training or retention without checking the applicable account terms and configuration.

Define tool permissions, retrieval access boundaries, input and output evaluation, logging with sensitive-data minimization, and human approval for consequential actions. Test prompt injection, unsupported answers, failed integrations and repeated actions. AI output can be incorrect and needs validation appropriate to the decision.

Compliance requirements

Identify applicable obligations with the client’s legal and compliance advisers during scoping. Koddox can implement agreed technical requirements and provide agreed engineering evidence; legal conclusions, regulatory approval and independent certification are separate activities.

Where required, execute confidentiality and data-processing terms before processing client information. Agree subprocessors, transfer safeguards, audit cooperation, breach responsibilities and deletion or return requirements. Do not upload regulated data until the relevant controls and agreements are established.

Security incidents and reporting

Report suspected vulnerabilities or incidents to support@koddox.com with “Security report” in the subject. Include the affected URL or system, a concise description and safe reproduction information. Do not include credentials or unnecessary personal data in ordinary email.

The incident plan should define assessment, containment, evidence preservation, remediation, notification responsibilities and recovery validation. Contractual and legally required notification deadlines take precedence over general support handling. This public page does not promise a staffed 24/7 security operation.

Responsible disclosure and service boundaries

Do not access other users’ records, disrupt availability, perform social engineering, or run intrusive testing without written authorization. This page is not permission to test and does not establish a bug-bounty payment or legal safe-harbor program.

Client infrastructure and third-party providers can affect security and availability. Security work reduces risk but cannot guarantee that a breach, outage or data loss will never occur. Review the maintenance policy for separately agreed operational support.

Company and contact

Koddox Technologies, 9 Star Arcade, Opposite DHA Bosan Road Gate, Multan, Pakistan. Security reports and questions: support@koddox.com.

Questions? support@koddox.com

Scroll to Top