Security Governance & Service Levels

Digitech Scouts
Security & SLA.

How we protect the access and data you trust us with, how quickly we respond, and — just as importantly — exactly what we do and do not promise.

Version 1.0 Last Updated: October 2026 Least-Privilege Access Client-Owned Accounts
Least-Privilege Access

We request only the access a task needs, and remove it when the work ends.

You Own Your Accounts

Ad, analytics and hosting accounts stay in your name. We work as a user, never the owner.

HTTPS by Default

Every website we build and launch is served over HTTPS.

Honest Disclosure

If something goes wrong with your data or access, we tell you promptly and plainly.

Section 01

Overview

01

Enterprise Edge Security

Every website Digitech Scouts launches is served over HTTPS. Infrastructure protection such as firewalls and DDoS mitigation is provided by the hosting plan, and we advise on choosing one.

02

Security & Data Isolation

Client analytics data, ad credentials, and API tokens are accessed on a least-privilege basis, never shared between clients, and our access is removed when an engagement ends.

03

Continuous Uptime Guarantee

We prioritise uptime and reliability. In the rare event of unscheduled downtime, we work urgently to restore services and communicate transparently with our partners.

Section 02

Scope of This Document

This page explains how Digitech Scouts handles the access, credentials and data clients share with us, and the service levels we work to. Specific response times for your engagement are confirmed in your proposal; where the two differ, your proposal applies.

Section 03

Access & Credential Handling

Access to your accounts is the most sensitive thing you give us, so we keep it as narrow and as short-lived as possible.

01

User Access, Not Ownership

We ask to be added as a user or partner on your Google, Meta, hosting and analytics accounts, so ownership never leaves you.

02

Least Privilege

We request the lowest permission level that lets us do the agreed work.

03

No Credentials Over Insecure Channels

Please do not send passwords in plain email or chat. Where a login must be shared, we will agree a secure method with you.

04

Removal on Exit

When an engagement ends, we remove our access after handover and confirm it with you.

Section 04

Data Handling & Confidentiality

We use client data only to deliver the agreed service. We never sell it, and we do not share it beyond what delivery requires.

Core Pointers: How We Treat Your Data
  • Used only for the work you engaged us for
  • Never sold, rented or traded
  • Handled as described in our Privacy Policy
Section 05

Website Build Practices

For websites we build, we follow sensible security practices as standard:

01

HTTPS Everywhere

Sites are launched with HTTPS enabled.

02

Kept Up to Date

For WordPress builds, we use maintained themes and plugins, and keep them updated during any active maintenance engagement.

03

Minimal Plugins

We avoid unnecessary plugins and third-party scripts, which reduces the attack surface.

04

Hosting Provider Controls

Infrastructure-level protection (such as firewalls and DDoS mitigation) is provided by your hosting provider and depends on the plan you choose.

Section 06

Support Channels & Response Targets

These are the response targets we work to. A response means a human acknowledging and starting on your request — not necessarily resolving it, since resolution time depends on the issue.

01

How to Reach Us

Email info@digitechscouts.com or call / WhatsApp +91 90907 24725.

PriorityExampleTarget First Response
Critical Live website down, or an ad account suspended (Scout 360 AI & Scout Growth clients) Within 1 hour
Standard Content changes, campaign adjustments, reporting questions Next business day
Planned Work New pages, features or campaigns As scheduled in your proposal
Section 07

If Something Goes Wrong

If we become aware of an issue that affects your website, accounts or data, we will:

01

Tell You Promptly

Notify you as soon as we know, with what we know at that point.

02

Contain It

Take reasonable steps within our access to limit the impact, such as changing a credential or pausing a campaign.

03

Explain Plainly

Share what happened and what we are doing about it, in plain language.

Section 08

Backups & Continuity

For websites under an active maintenance engagement, we take a backup before making significant changes. Ongoing automated backups depend on your hosting plan; we will advise you on enabling them during setup.

Section 09

Third-Party Platforms

Much of our work runs on platforms we do not operate — Google, Meta, WordPress and hosting providers. Their security, uptime and availability are governed by their own terms, and are outside our control.

Section 10

Your Part in Security

Security is shared. We ask that you:

01

Enable Two-Factor Authentication

Turn on 2FA for your Google, Meta, hosting and domain accounts.

02

Keep Owner Access

Make sure someone in your business always holds owner-level access to every account.

03

Tell Us About Changes

Let us know when staff leave or access should change.

Section 11

What We Do Not Promise

We would rather be precise than impressive. Unless your signed agreement says otherwise:

01

No Uptime Guarantee

Website uptime depends on your hosting provider. We do not offer an uptime percentage guarantee.

02

No Third-Party Certification

Digitech Scouts does not currently hold a formal security certification such as ISO 27001 or SOC 2.

03

Targets, Not Guarantees

The response times above are targets we work to, not contractual guarantees.

Precise Over Impressive No Exaggerated Claims
Section 12

Report a Security Concern

To report a security concern, email info@digitechscouts.com with "Security" in the subject line. We review this page periodically; the date at the top shows when it last changed.

Related policies: Privacy Policy · Terms & Conditions · Cookie Policy