Pharma Manufacturing ERP & BMR Solutions

INFORMATION SECURITY POLICY (ISP)

INFORMATION SECURITY POLICY (ISP)

 

The BLine Solution Private Limited’s commitment to protecting information assets, ensuring confidentiality, integrity, and availability of data, and maintaining compliance and applicable regulatory requirements across all jurisdictions we serve. This Policy applies to all BLine employees, contractors, vendors, systems, and third-party service providers, including our Google Cloud Platform (GCP) deployment and BLine Cloud Plateform (BCP).

 

1. Information Security Commitments

BLine is committed to protecting all client data, intellectual property, and business information from unauthorised access, disclosure, modification, or destruction. We maintain the confidentiality, integrity, and availability of all information assets.

We comply with all applicable laws including GMP, GDPR (EU), UK GDPR and Data Protection Act 2018, Digital Personal Data Protection Act 2023 (India), PDPA (Singapore), Privacy Act 1988 and APPs (Australia), PDPL Federal Decree-Law No. 45 of 2021 (UAE), PIPEDA and Quebec Law 25 (Canada), and PDPD No. 13/2023/ND-CP (Vietnam).

We continuously improve our information security posture through regular risk assessments, penetration testing, and audits.

 

2. Security Controls Framework

– Access Control and Identity
– Cryptography
– Physical Security
– Operations Security
– Communications Security
– Supplier Relationships
– Incident Management
– Business Continuity
– Compliance
– Human Resources Security
– Cloud Security (GCP)
– BLine Cloud Plateform (BCP) Server Security

 

3. Infrastructure & Deployment Security

BLine operates a hybrid deployment model combining Google Cloud Platform and BLine Cloud Plateform (BCP) infrastructure. Google Cloud Platform is our primary cloud platform for solution deployment, scaling, and managed services. GCP security controls include Cloud IAM with least-privilege and MFA, VPC Service Controls to prevent data exfiltration, Organization Policies to restrict resource locations by jurisdiction, Security Command Center for threat detection, Cloud Armor for DDoS and WAF protection, Confidential VMs for sensitive workloads, Cloud KMS/HSM for encryption key management, and Cloud Audit Logs for full traceability.

 

GCP compliance certifications relied upon include ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, HIPAA, and FedRAMP. Data residency is managed by selecting GCP regions based on customer jurisdiction and contract, covering EU, UK, India, Singapore, Australia, UAE, Canada, and US.

BLine Cloud Plateform (BCP) infrastructure is deployed in India and other locations as contracted. It is used for data residency and localisation requirements, client-specific workloads, low-latency edge processing, and data sovereignty mitigation for Vietnam and Canada. Local server security controls include hardened operating systems, full-disk encryption, host-based intrusion detection, secure boot and TPM, physical access controls and CCTV, network isolation and firewall rules, regular vulnerability scanning and patching, and encrypted backup to a separate geographic region fully under cntrol only BLine Solution Privte Limited.

 

Acceptable Use Policy

Permitted uses include accessing BLine systems and network resources for authorised business purposes, using personal non-shared credentials for system access, reporting suspected security incidents or policy violations, and using approved cloud and server resources in accordance with this Policy.

 

Prohibited uses include accessing, modifying, or transmitting confidential data without authorisation sharing credentials, passwords, or access tokens with any other person, installing unauthorised software on BLine-managed devices or cloud instances, connecting to BLine systems from unsecured or public Wi-Fi without VPN, using BLine systems for personal business, cryptocurrency mining, or illegal activities, attempting to bypass or circumvent any security control, removing or disabling security software, storing or processing personal data outside approved GCP regions or BCP servers without authorisation; and transferring personal data across borders without approved transfer mechanisms such as SCCs, UK Addendum, or CDPA.

 

Security Awareness & Training

All new employees complete mandatory security awareness training within their first week. Annual refresher training is required for all staff with completion tracked and documented. Role-specific training is provided for developers, system administrators, cloud engineers, and customer-facing staff. GCP-specific training covers IAM, VPC Service Controls, and Security Command Center. BCP server security training is provided for infrastructure and operations staff. Data protection and privacy training covers GDPR, DPDP Act, PDPA, PDPD, and other applicable laws.

 

Security Incident Reporting

All staff, contractors, and clients must report suspected security incidents immediately through the following channels.

Internal staff should report to support@blinesolution.com

 

Breach Notification

Where a personal data breach occurs, BLine will notify affected parties and regulators in accordance with applicable law.

EU- Supervisory Authority- within 72 hours where required.
UK- ICO- within 72 hours where required.
India- Data Protection Board of India- as prescribed under the DPDP Act.
Singapore- PDPC- without undue delay.
Australia- OAIC- as soon as practicable for eligible data breaches.
UAE- UAE Data Bureau- where required by PDPL.
Canada- Office of the Privacy Commissioner – where there is a real risk of significant harm.
Vietnam- Competent authority (A05)- within 72 hours of detection.

 

Third-Party & Supplier Security

Vendor risk assessment is conducted before onboarding. Contractual security and data protection requirements are included in all supplier agreements. Annual vendor security reviews are performed. Google Cloud Platform is assessed under GCP CDPA and Google’s compliance certifications. BCP server vendors are assessed for hardware security, firmware integrity, and supply chain risk. An SBOM (Software Bill of Materials) is maintained for critical components. A sub-processor list is available to clients on request.

 

Business Continuity & Disaster Recovery

Recovery Point Objective (RPO)- Maximum 1 hour data loss in a worst-case scenario.
Recovery Time Objective (RTO)- Service restored within 4 hours of a declared disaster.
DR Testing- Quarterly DR simulation with documented results.

 

©2026 BLine Solution Private Limited. All Rights Reserved.

Scroll to Top