Businesses increasingly use professionally managed cloud and data-centre infrastructure because
specialist hosting environments can provide layers of physical, network, infrastructure and backup
controls that are difficult for many individual businesses to maintain independently. Tez ERP
therefore supports flexible deployment models, including IESL-managed/arranged hosting,
customer-controlled cloud infrastructure and on-premise deployment, depending on the purchased
arrangement.
IESL takes commercially reasonable measures to protect data within the environments and components
under its control. The exact security architecture, hosting provider, technology stack,
certifications, backup cycle and controls may vary by deployment model, service plan, technical
environment and third-party provider.
Security Measures and Practices
-
Cloud Infrastructure:
Where IESL-arranged cloud hosting is used, data may be hosted on commercially managed
cloud/server infrastructure provided by established service providers with appropriate
operational and security capabilities.
-
Encryption in Transit:
Communication between users and hosted services may be protected using SSL/TLS encryption
or equivalent industry-standard mechanisms appropriate to the current technical environment.
-
Data-Centre Controls:
Where applicable, IESL may use hosting/data-centre providers maintaining recognised security
certifications such as ISO 27001, ISO 27017 or equivalent standards. Any such certification
applies to the relevant provider/environment and not automatically to every IESL or
customer-controlled deployment.
-
Multi-Layer Security:
Hosted servers may be protected through multiple layers of security such as network controls,
firewalls, gateway controls, access restrictions, monitoring and provider-level security
systems.
-
Database Security:
Tez ERP may use enterprise-grade relational database technology, including Microsoft SQL
Server or other supported database platforms, depending on the deployment and version.
Database access and security depend on the applicable architecture and environment.
-
Application Isolation / N-Tier Architecture:
Where technically applicable, the application may use layered architecture and isolation
so that the user-facing layer does not directly expose the database layer.
-
Automated Backups:
For applicable hosted plans, automated backup processes may create periodic backups based
on the configured backup cycle. Backup frequency, retention and availability depend on the
purchased plan, deployment model, hosting arrangement and current technical environment.
-
Offsite / Separate-Location Backup:
Where included in the applicable hosting or disaster-recovery arrangement, server or data
backups may be stored in a different logical or physical location. This is not a universal
restoration guarantee and depends on the applicable plan.
-
Role-Based Data Export:
Authorised users may, where the relevant module and permissions permit, export or download
data in standard available formats such as Excel-compatible formats. Availability of specific
exports depends on product capability, role permissions and plan.
-
Optional Backup Services:
IESL may offer optional automated backup, FTP/SFTP, SQL-compatible backup, disaster-recovery
or other backup services on a chargeable basis. Pricing and exact service parameters are
governed by the current quotation/order and are not permanently fixed by this Policy.
-
Flexible Hosting:
Customers are not necessarily required to host data on IESL-arranged servers. Customers may
choose customer-controlled cloud or on-premise deployment where commercially and technically
supported. Setup, configuration, server shifting, restoration and related services may be
chargeable at prevailing rates.
Customer Backup Recommendation
IESL strongly recommends that customers maintain regular independent backups wherever technically
available. Standard exports may be available in Excel-compatible, XML or other supported formats
depending on the Product and deployment. Customers should not rely on any single backup mechanism
for business continuity.
Backup, Retention and Restoration
Backup, retention and restoration are subject to the purchased plan, deployment model, hosting
arrangement, active AMC/subscription status, technical feasibility and available backup cycle.
IESL does not guarantee restoration to a specific point in time unless a separate disaster-recovery
or backup plan has been purchased and agreed in writing. Restoration arising from customer deletion,
overwrite, expired account, ransomware, unauthorised access, migration error, old-data requirement
or other non-IESL causes may be chargeable. Data beyond the applicable retention period may not
be recoverable.
Customer-Managed and On-Premise Security
For customer-managed cloud and on-premise deployment, the customer is responsible for server
hardware, operating system, database licence, antivirus, firewall, network, internet, backup,
UPS, physical security, remote access, IT administration, cybersecurity, patching and compliance
with IESL's technical requirements. IESL cannot be responsible for security failures or data loss
arising from customer-managed infrastructure, customer credentials, unauthorised direct database
changes, malware, ransomware, hardware failure, network failure or third-party software conflicts.
User Access and Credentials
Customers are responsible for creation, allocation, monitoring, modification and deactivation
of users, roles, passwords, privileges, approvals and access rights. Shared passwords, weak
passwords, compromised credentials, incorrect privileges and failure to remove ex-employee access
can create security risk and remain the customer's responsibility.
No Absolute Security Guarantee
IESL uses commercially reasonable safeguards but no cloud service, network, application, server,
database or backup system can be guaranteed to be completely secure or continuously available.
Security controls may evolve in response to technology, threats, law, infrastructure changes
and third-party requirements.
Relationship with Applicable Terms
This Policy forms part of and should be read together with the Tez ERP Terms and Conditions and
the Customer's applicable order confirmation, invoice, proposal, SRS, Statement of Work or other
mutually approved written commercial document. In the event of an inconsistency relating to
product scope, licence entitlement, commercial entitlement, support, service level, hosting,
usage, data retention, liability, refund, termination or other contractual rights and obligations,
the Tez ERP Terms and Conditions and mutually agreed written commercial documents shall prevail
to the extent permitted by applicable law.