Skip to content

Security at Insaan Global

Trust,
built into the work.

When you hand us part of your operation, you trust us with your systems, your data and your customers. We protect that trust through everyday practices: who gets access, which devices they use, where your data lives, and how you stay in control.

Layers of protection around your dataFour rings around a center labeled Your data: client control and visibility on the outside, then people, then workstations and access, then data handling.YourdataYour control & visibilityPeopleWorkstations & accessData handling

Our approach

How we approach security

Security in an outsourced operation is decided in ordinary moments: when an account is created, when someone changes role, when a customer shares something sensitive, when a person leaves. So this page describes those moments and what we do in them.

Every client is different. Your industry, your customers and your own security team will shape the rules for your account. We agree those rules with you before go-live and build them into training, access and quality review.

Your security team is welcome to review any of this in detail, and we expect to be asked hard questions.

Our practices

The five areas our security practices cover

01

People

Who works on your account, and how they are trained.

  • Confidentiality agreements signed before anyone works on your account
  • Security awareness training for every team member, refreshed over time
  • Dedicated teams: the people on your account work only for you
  • Team Leads who reinforce the rules as part of daily coaching
02

Workstations & access

The devices your team uses and what each role can reach.

  • Company-managed, monitored workstations at our Amman hub
  • Role-based access with the least privilege each role needs
  • Regular access reviews, and removal when someone leaves your account
  • Clean-desk rules for sensitive work
03

Data handling

Where your data lives and how much of it we touch.

  • Work done inside your systems where possible, rather than in copies
  • Only the data a task needs, for as long as it needs it
  • Retention and deletion that follow your policy
  • Sensitive-work rules agreed with you before go-live
04

AI governance

Which AI tools are allowed, and who checks their output.

  • We agree with you which AI tools may be used with your data, and for what
  • People review AI output where it affects customers or decisions
  • AI quality scores are calibrated by human reviewers
  • Changes to how AI is used go through your approval
05

Client control & visibility

What you can see, and which changes need your approval.

  • Live visibility into performance and quality through NAS-AI
  • You own the accounts in your systems and can see who has access
  • Process and access changes proposed to you, then approved
  • A named Function Manager who answers for the team

Where your data lives

How our team reaches your data

Wherever the work allows, your customer data stays in your systems. Our team reaches it through named, role-based access from managed workstations, and does the work there.

Select any part of the diagram to see how it works.

Your environment

Data stays in your systems where possible

Wherever the work allows, our team works inside the tools you already own. Customer records, conversations and documents remain in your systems, under your retention settings and your logging.

  • You own the accounts and can see who has access
  • Your own audit logs keep working as they do today
  • Retention and deletion follow your policy

The access lifecycle

How we manage access from start to finish

Most access problems come from access that was never reviewed or never removed. So we manage it as a lifecycle, from a person’s first day on your account to their last.

  1. Step 1 · Onboard

    Before any access is granted

    A new team member signs confidentiality agreements, completes security awareness training and learns your account’s specific rules. Access is requested only once that is done.

    • Confidentiality agreement
    • Security training
    • Account rules
  2. Step 2 · Grant

    Least-privilege access, by role

    Access is set up for the role the person holds, with only the permissions that role needs. Roles and their permissions are agreed with you, and you can see every account in your own systems.

    • Role-based
    • Least privilege
    • Named accounts
  3. Step 3 · Review

    Checked on a regular rhythm

    We review who has access to what on a regular schedule, and whenever someone changes role. Anything no longer needed is removed. We can run these reviews together with your team.

    • Regular reviews
    • Role changes
    • Joint reviews on request
  4. Step 4 · Offboard

    Removed when it is no longer needed

    When someone leaves your account or the company, their access is removed promptly and their workstation is returned to a clean state. Confidentiality obligations continue after they leave.

    • Prompt removal
    • Device reset
    • Ongoing confidentiality
A row of company-managed workstations in the Insaan Global Amman hubAmman hub

On the floor

Physical security at our Amman hub

  • Managed devices

    Workstations are set up, managed and monitored by the company. Personal devices aren’t used for client work.

  • Clean desks

    Clean-desk rules apply to sensitive work, so customer information isn’t left out or copied onto paper.

  • Dedicated team rooms

    Client teams sit together in dedicated rooms at the Amman hub.

  • Rules you can add

    If your work needs stricter rules at the desk, we agree them with you and build them into training.

Shared responsibility

Who is responsible for what

Access to your systems
Insaan GlobalRequest, set up by role, review and remove access for our team
YouOwn the accounts, approve roles, see who has access
Workstations & the floor
Insaan GlobalManage and monitor devices, run clean-desk rules and training
YouTell us about any extra desk-level rules you need
Customer data
Insaan GlobalWork in your systems where possible, use only what the task needs
YouKeep your systems of record and set retention policy
AI tools
Insaan GlobalUse only the tools and uses you have approved
YouDecide which AI uses are allowed with your data
Incidents
Insaan GlobalContain, notify, investigate and fix
YouName contacts to be told, and join the investigation where needed
Reviews
Insaan GlobalShare how we work and answer your questions
YouReview our practices as often as you need

If something goes wrong

How we handle security incidents

Mistakes can happen in any operation. We aim to catch them early, tell you about them openly and fix the cause so they don’t recur. Notification terms are agreed in each client contract.

  1. 1

    Spot

    Anyone on the team can raise a concern, and Team Leads know to escalate quickly. Monitoring and quality review help surface issues early.

  2. 2

    Contain

    We act first to stop any harm from spreading, for example by pausing access or taking a workstation offline.

  3. 3

    Tell you

    We notify your named contacts in line with what we agreed in your contract, and keep you updated as we learn more.

  4. 4

    Investigate

    We work out what happened and why, and work with your team if your systems are involved.

  5. 5

    Fix & learn

    We fix the root cause, update procedures and training, and share what changed with you.

For your security team

Security reviews and vendor questionnaires

We invite your security and compliance teams to review how we work before you sign anything. We will complete your vendor security questionnaire, walk through our practices on a call, and talk through any requirements specific to your industry.

  • Your vendor security questionnaire, completed
  • A walkthrough call with your security team
  • Your requirements, agreed before go-live
  • Joint access reviews, if you want them

FAQ

Security questions

Does Insaan Global hold security certifications?

This page sets out the practices we follow on every account. We’re happy to walk your security team through them in detail, answer your questionnaire and discuss any specific requirements your business has.

Where is our data stored?

Wherever the work allows, your data stays in your own systems and our team works inside them through named, role-based accounts. Retention follows your policy. If a task needs data to move, we agree how with you first.

Will you complete our vendor security questionnaire?

Yes. Send it to us during your review and we will complete it and walk your security team through our answers.

How do you use AI with our data?

Only in the ways you approve. We agree with you which AI tools may be used, for which tasks, and people review AI output where it affects customers or decisions.

What happens if something goes wrong?

We contain it, tell your named contacts in line with our agreement, investigate the cause with you, fix it and update our procedures.

Can we add our own security requirements?

Yes. Many clients have specific rules for their industry or their customers. We agree them with you before go-live, build them into training and the quality scorecard, and check that they are followed.

Let your security team see how we work.

Tell us what your business needs to be comfortable. We will walk your team through our practices and agree the rules for your account before go-live.