Back to home
Trust Center

Security, compliance and reliability — in one place

Aphelion operates to enterprise-grade standards across every layer of our service delivery. This page documents the current status of our platform, our compliance posture, the security controls we operate, and how we respond when things go wrong.

Service Status

All systems operational

Real-time status of the platforms that underpin our managed services. Last updated by the Broadsword operations platform.

All systems operational

Managed Cloud Infrastructure

99.99% uptime over last 90 days

Operational

Broadsword MDR / SOC

24/7 monitoring, <15min P1 response

Operational

Backup & Disaster Recovery

RPO <4hrs · RTO <4hrs · tested quarterly

Operational

Managed Network & Connectivity

99.95% uptime across managed links

Operational

Tailwind Labs AI Platform

Model SLAs per engagement

Operational

Client Portal & API

Available 24/7 at portal.aphelion-group.com

Operational
Compliance

Certifications & frameworks we operate to

Every engagement inherits the controls below. Sector-specific frameworks (HIPAA, SOC 2, IEC 62443) are applied per client requirement and documented in the service agreement.

Compliant

ISO 27001

Information Security Management

Documented information security management system covering people, process and technology controls.

Compliant

ISO 9001

Quality Management

Quality management system governing service delivery, change management and continuous improvement.

Compliant

ISO 20000

IT Service Management

ITIL-aligned service management processes for incident, problem, change and release management.

Compliant

GDPR

EU General Data Protection Regulation

Lawful processing, data subject rights, international transfer safeguards and breach notification.

Compliant

Mauritius DPA 2017

Data Protection Act

Mauritius national data protection law — controller/processor obligations, data residency and subject rights.

Compliant

PCI-DSS

Payment Card Industry Data Security Standard

Cardholder data protection controls for payment processing, tokenisation and PCI-scoped segmentation.

Security Controls

Defence-in-depth, operated 24/7

The controls below run across every managed workload. Each one is owned by a named engineering team and audited on a documented schedule.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest, and customer-managed keys for workloads that require sovereignty over cryptographic material.

Least-privilege access

Role-based access control, MFA on every privileged account, just-in-time elevation and quarterly access reviews.

24/7 monitoring & alerting

Broadsword MDR correlates endpoint, identity, cloud and network telemetry — with human triage on every P1 alert.

Immutable backups

Air-gapped, immutable backup copies with quarterly ransomware recovery drills. RPO <4hrs, RTO <4hrs.

Vulnerability management

Continuous vulnerability scanning, monthly patching windows, annual penetration tests and red-team exercises.

Network segmentation

Zero-trust micro-segmentation across client environments — production, management and PCI scopes kept isolated.

Incident Response Process

What happens when something breaks

Our incident response process is documented, drilled and continuously improved. Every P1 event has a named incident commander, an SLA-bound response time, and a written post-incident report within 10 business days.

01

Detect

Continuous

Broadsword MDR sensors detect anomalies across endpoints, identities, cloud and network. SIEM correlation surfaces candidate incidents within minutes.

02

Triage

<15min (P1)

Named SOC analyst triages the alert, confirms severity and assigns an incident commander. Client point-of-contact is notified immediately for P1 events.

03

Contain

Minutes

Automated containment playbooks isolate affected hosts, revoke compromised credentials and block malicious indicators — limiting blast radius while investigation continues.

04

Eradicate & Recover

Hours

Root cause is removed, systems are rebuilt from known-good images, and clean backups are validated and restored. Services are returned to operation under documented rollback runbooks.

05

Review & Harden

Post-incident

Within 10 business days we deliver a written post-incident report: timeline, root cause, lessons learned and the specific hardening actions taken to prevent recurrence.

Have a security or compliance question?

Our DPO and security team respond to compliance, due-diligence and assurance enquiries within one business day. Download the security whitepaper for the full control catalogue, or reach out directly.