top of page
Illuminated Geometric Bridge

IT Infrastructure

At Wellnex, IT compliance and cybersecurity are a priority. We take pride in maintaining a secure, resilient, and continuously monitored technology environment designed to protect our clients, members, and their data.

 

Our IT architecture has been designed and implemented in accordance with high security protocols and recognised industry standards. Security is embedded into our infrastructure and development processes from the outset, with continuous monitoring and improvement to address emerging cyber threats.

Wellnex is integrated with a certified IT Cyber Risk Platform that continuously monitors our technology environment and provides an MCE Rating to assess and validate our overall security posture.

Pentest-Tools continuously monitors for application vulnerabilities, potential data leakage, and areas of non-conformity. Identified issues are prioritised and addressed promptly, with a target remediation timeframe of within 8 hours.

Our software development practices systematically take into consideration the OWASP Top 10, the globally recognised framework for identifying and mitigating the most critical web application security risks.

All traffic to and from Wellnex servers is protected using SSL/TLS encryption, helping safeguard data transmitted between users, applications, and our infrastructure.

SSL (Secure Sockets Layer) is a standard security technology used to establish an encrypted connection between a web server and a browser, helping protect information from unauthorised interception or access during transmission.

SSL Encryption

Typing on Keyboard

​​MTSC Certified

Wellnex’s infrastructure is hosted on Microsoft Azure, a cloud platform certified under Singapore’s Multi-Tier Cloud Security (MTCS SS 584) Level 3 standard for Cloud Service Providers (CSPs).

Microsoft Azure also maintains globally recognised certifications and security standards, including ISO/IEC 27001 for Information Security Management Systems and ISO/IEC 27018 for the protection of personally identifiable information (PII) in public cloud environments.

These certifications and standards provide an additional layer of assurance that our underlying cloud infrastructure operates within rigorous, internationally recognised security and data protection frameworks.

In-House Security Protocol

Data Access & Password Authentication

Data access is governed by strict role-based access controls which is reviewed and audited by independent bodies regularly. Private/Public keys with password protection are required to access to our servers.

Independent Pen test ​

Wellnex performs at least once a year a pen test with a third party that is mandated to evaluate the overall robustness, scalability and resilience of the platform. It includes, but is not exhaustive, the following:

SQL Flaws, XSS, Malicious File Execution, CSRF, Cryptographic Storage, URL Access.

Governance, Training & Authorisation

All employees are mandated to attend regular Data Protection and Cyber Security training to ensure security awareness and knowledge of latest security threats.

All employees pledged and signed a set of governance policies adhering to the strictest data security and IP confidentiality compliance.

DPTM Certification Number:  DPTM-00033-202008202008
Cyber Essentials Certification Number:  CEM-2023-012

bottom of page