Desks live now · Pokhara info@kamshipglobal.com +977 9856078508

Home/Company/

Security and data handling

A summary of the controls we operate. We complete your security questionnaire and share the full overview on request, before you send us anything.

Physical

  • Client work happens only in our supervised Pokhara office, never from home
  • Controlled entry, visitor log and CCTV covering the work floor
  • Clean-desk policy, with personal phones and bags in lockers during shifts
  • Separate, access-controlled zones where a client requires segregation

Devices and network

  • Company-owned, centrally managed computers with full-disk encryption
  • USB storage, local downloads and printing disabled by policy and by configuration
  • Endpoint protection with centrally managed patching
  • Business firewall; personal webmail and file-sharing services blocked
  • No client data stored on local machines — work happens inside your systems

Access control

  • Named accounts only. We never share logins between staff
  • Multi-factor sign-in on every client system
  • Least-privilege permissions, agreed per engagement and reviewed quarterly
  • All access removed within 4 hours of any staff change
  • Client credentials held in a business password manager, never in documents or chat

People

  • Background checks including a police clearance report before hire
  • Written confidentiality obligations in every employment contract
  • Security and privacy training before system access, refreshed annually
  • Named team lead and QA reviewer per account, both known to you

Incidents and continuity

  • Documented incident response procedure with defined roles
  • Clients notified within 24 hours of a suspected breach affecting their data
  • Backup power and two independent internet providers
  • Trained backup staff so a single absence never stops the desk

Agreements

  • We sign your NDA before scoping begins
  • Data processing agreement with UK IDTA or EU Standard Contractual Clauses where needed
  • Defined data retention and a documented offboarding checklist
  • Your right to audit our controls, written into the agreement

Certification status

What we hold, and what we do not

We are working toward alignment with ISO/IEC 27001 and will say exactly that until we are certified. We are not certified today, and we will not imply otherwise on a page like this.

What we can do now is complete your security questionnaire in full, walk your team through our controls on a call, give you the right to audit them in the agreement, and start with a pilot small enough that the risk is proportionate to what you know about us.

Questions we are asked, answered plainly

Where is our data stored?

In your systems. Our staff work inside your TMS, portals and document stores through named accounts. We do not copy client data onto our machines, and local storage and downloads are disabled by configuration, not just by policy.

Can we audit you?

Yes. The right to audit our controls is written into our standard agreement, and we will host an inspection of the floor with reasonable notice.

What about UK and EU personal data?

We sign a data processing agreement incorporating the UK International Data Transfer Addendum or EU Standard Contractual Clauses before any personal data is shared, and we document the categories of data involved.

What happens when we end the engagement?

A documented offboarding checklist: access revoked within four hours, any client materials returned or destroyed to your instruction, and written confirmation from us that it has been done.

Who is liable if something goes wrong?

Liability is set out in the signed agreement, which your lawyer should review. We carry the obligations we agree to and we will not hide them in a website footnote.

Next step

Send us your security questionnaire.

We complete it in full before you commit to anything, and we will walk your IT or compliance team through the answers on a call.

General enquiriesinfo@kamshipglobal.com
Operations and partnershipsceo@kamshipglobal.com
Call or WhatsApp+977 9856078508
We replyWithin one business day, in your time zone