Home  ›  Compliance

Security & Compliance

Rediffmail Enterprise and Rediffmail Pro are independently audited against globally recognised standards for security, quality, and data protection. Here is a summary of our active certifications.

Applies to Rediffmail Enterprise Rediffmail Pro

Certifications Overview

6 active
SOC 2 Type II Report

An independent AICPA attestation covering the security, availability, and confidentiality of customer data.

Scope: Service organization controls
ISO/IEC 27001:2022

The international standard for information security management. Certifies a risk-based programme that protects the confidentiality, integrity, and availability of customer data.

Scope: Information security
ISO/IEC 20000-1:2018

ISO/IEC 20000-1 is the international standard for IT Service Management. It certifies that our services are planned, delivered, and continually improved through a structured, customer-focused Service Management System (SMS).

Scope: IT service management
ISO/IEC 27701:2019

ISO/IEC 27701 extends ISO/IEC 27001 to privacy management. It certifies that personal data is handled responsibly through an independently audited Privacy Information Management System (PIMS).

Scope: Privacy information management
ISO/IEC 27018:2025

ISO/IEC 27018 is the international code of practice for protecting personally identifiable information (PII) in public cloud services, certifying cloud-specific privacy controls.

Scope: Cloud PII protection
ISO/IEC 27035-1:2023

ISO/IEC 27035-1 is the international standard for information security incident management, certifying structured processes for detecting, responding to, and learning from security incidents.

Scope: Security incident management

Certification Details

Rediffmail Enterprise and Rediffmail Pro are committed to maintaining the highest standards of security and operational excellence. Our SOC 2 Type II Report certification demonstrates that our controls for protecting customer data have been independently audited over a defined period and found to be effective in accordance with the AICPA’s Trust Services Criteria.

Unlike a point-in-time assessment, a SOC 2 Type II Report audit evaluates both the design and the operational effectiveness of security controls, providing customers with additional assurance that these controls are consistently followed in practice.

What This Means for Our Customers

Our SOC 2 Type II Report certification provides assurance that:

  • Security controls are independently tested for effectiveness over time
  • Customer data is protected through well-defined security policies and procedures
  • Risks are continuously monitored and managed through established governance processes
  • Access to systems and information is managed using controlled access practices
  • Security incidents are addressed through documented response procedures
  • Operational processes are regularly reviewed to support ongoing compliance and continuous improvement

By maintaining SOC 2 Type II Report certification, Rediffmail Enterprise demonstrates its commitment to safeguarding customer information and delivering secure, reliable services through independently validated security and operational controls.

Applicable to Rediffmail Enterprise Rediffmail Pro
Report TypeType II
Attestation BodyAICPA®
Audit Period1 December 2025 – 31 May 2026
Report date15 June 2026
Next Report Due15 June 2027
SOC 2 Type II Report SOC 2 Type II Report