Security and compliance you can check independently

MeltX is ISO 9001:2015 and ISO/IEC 27001:2022 certified, with its web applications audited against CERT-In, OWASP and SANS 25. A vendor asserting that it is secure is worth very little, so these are the certifications, audits and controls an information security team can check independently, and the ones we evidence on request.

2
ISO certifications
6
Controls documented
2025
Last external audit
9
Recognitions in total

Certified, and what that covers

A certificate number means little without its scope. Each of these states what was assessed, not just that something was.

ISO 9001:2015

Quality management system

Certification of the quality management system covering how MeltX designs, builds, delivers and supports its software. It is the reason delivery follows a defined process rather than the habits of whoever is available.

ISO/IEC 27001:2022

Information security management system

Certification of the information security management system, covering risk assessment, access control, supplier management, incident response and technical vulnerability management across the organisation.

CERT-In, OWASP and SANS 25 audit

Web application security audit

MeltX web applications have been audited against CERT-In, OWASP and SANS 25 guidelines. The audit completion letter is dated March 2025 and is available to prospective customers and tender committees on request.

Independent application audit

Audited against CERT-In, OWASP and SANS 25

MeltX web applications were audited against CERT-In guidelines, the OWASP Top 10 and the SANS Top 25, with a completion letter dated March 2025.

Completion letter
March 2025
Standards
CERT-In, OWASP, SANS 25
Scope
MeltX web applications
Evidence
Available on request

The controls that make the claim true

What is actually in place, stated as mechanism. Each of these is something your information security team can ask us to demonstrate.

  • Encryption in transit and at rest

    Application traffic is encrypted in transit and stored data is encrypted at rest. Remote support sessions are encrypted end to end.

  • Multi factor authentication

    Multi factor authentication is enforced on privileged and remote access accounts, with no shared logins for operator activity.

  • Role based access control

    Permissions are granted by role down to field level, with maker and checker separation available where a process requires two people.

  • Immutable audit trails

    Record changes, approvals, verification events and access events are written permanently and cannot be edited after the fact.

  • Technical vulnerability management

    Patch currency is measured and reported, exceptions are registered formally with compensating controls, and exposure ageing is visible.

  • Certified disposal

    End of life hardware handled through certified e-waste routes with the certificate retained against the asset record.

How personal data is handled

Written against the Digital Personal Data Protection Act 2023, because that is the standard an Indian data fiduciary is actually held to.

Questions about a specific processing activity, retention period or sub processor are answered directly. Write to contact@meltxsoftware.com.

Full privacy policy

Purpose and consent

Personal data is collected against a stated purpose with a recorded consent artefact, which is the accountability the Digital Personal Data Protection Act 2023 expects of a data fiduciary.

Data minimisation and masking

Identifiers such as Aadhaar are masked in storage and in every screen or report that does not require them, and fields are exposed by role rather than by default.

Data residency

Deployment on premise, in a State Data Centre, or on cloud infrastructure with data held in India. The choice is confirmed against your policy before the technical proposal is finalised.

Retention and disposal

Retention periods are configured to your statutory obligation, and disposal of records and of hardware both leave a documented trail.

Assurance is not evidence

The questions an information security review actually asks, answered without reassurance language.

Is MeltX ISO certified?

Yes. MeltX Software Solutions holds ISO 9001:2015 for quality management and ISO/IEC 27001:2022 for information security management. Certificates are provided to prospective customers and tender committees on request, along with the scope of each certification.

Have MeltX applications been security audited?

Yes. MeltX web applications have been audited against CERT-In, OWASP and SANS 25 guidelines, with an audit completion letter dated March 2025. The letter is available on request, which matters for government procurement and enterprise security reviews.

How does MeltX handle the DPDP Act 2023?

Personal data is collected against a stated purpose with consent recorded, access is limited by role, identifiers are masked where the task does not require them, retention is configured to your obligation, and audit trails are immutable. Data residency options support policies that require data to remain in India.

How do we report a security issue?

Email contact@meltxsoftware.com with the subject line marked as a security disclosure. Include the affected application, the steps to reproduce and any supporting evidence. MeltX will acknowledge the report and keep the reporter informed while the issue is assessed and resolved.

See it against your own register

Configured around your asset classes before the call. Thirty minutes.

  • No obligation
  • Run on your register
  • Answered within a business day