How your data is secured

Learn about iECHO's data security protocols, cloud infrastructure, encryption standards, and privacy compliance framework.

We at ECHO take data security very seriously. All your data is secured and encrypted using best-in-class technology. Your encrypted data may be accessed only by authorized personnel from ECHO Institute and ECHO India, and is never shared with any third party. Read our Terms of Use and Privacy Policy for more information.

Your password is stored in an encrypted format. ECHO employees cannot view your password, and we will never ask you for your password or one-time passwords (six-digit code). In case you are contacted by an individual asking you for your iECHO password or OTP, please contact iECHO support immediately.

Secure cloud infrastructure

  • We use best-in-class server infrastructure technology from our partner AWS (Amazon Web Services).
  • We have implemented best practices in infrastructure security based on the recommendations of the Amazon Cloud Security team, including:
    • Strong access controls to sensitive infrastructure components,
    • Two-factor authentication,
    • Private VPCs,
    • Encrypted cloud storage, and
    • Regular system upgrades and security audits.

    For further technical details, please contact us at security@iecho.org.

Our system is periodically audited by an independent, third-party cybersecurity consulting firm.

State-of-the-art encryption and anonymization

  • All data transfer within ECHO systems is encrypted using the latest TLS 1.3 security protocols, and is never shared with any third party.
  • All reporting and aggregated analytics data is automatically cleaned, and all personally identifiable information is removed from ECHO’s internal reporting systems.

Secure-by-design: Robust User Authentication and Authorization

  • All users on iECHO have to authenticate themselves using either an email ID or a phone number, verified with a one-time password (OTP).
  • Two-factor authentication is implemented for sensitive accounts and where suspicious activity is detected.
  • iECHO implements role-based access control (RBAC) at an organization level. Data of one organization cannot be seen by a user in another organization. In addition, granular role assignments allow organization teams to choose between Owner, Admin, and Member roles.
  • This restricts unknown participants from entering the Zoom session and potentially disrupting ECHO operations (read more about Zoombombing).

Data Security & Data Privacy Framework

  • iECHO is compliant with global standards for data protection and data privacy. Please find detailed information about our legal compliance in our Privacy Notice.
  • Log management: We maintain de-identified system logs of all network activity in our systems for audit purposes.
  • Incident management: We follow the globally accepted, standard framework for cyber-incident response and management.

iECHO is not meant to store protected health information (PHI). Please do not store any patient information in the system, as per HIPAA.

If you have any queries around iECHO's data security, compliance, or any other legal or privacy concerns, write to us at privacy@iecho.org.