CYBERVED AI PRIVATE LIMITED
ACCESS CONTROL & API SECURITY POLICY
POLICY NO. 16 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Policy Owner | Information Security / Technology / Operations |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Access & API Security Controlled Policy |
1. PURPOSE
This Policy establishes controls for user access, privileged access, authentication, application interfaces and APIs used by CYBERVED AI PRIVATE LIMITED to protect systems, customer information, transaction data, gift-card/voucher services and partner integrations.
2. OBJECTIVES
- Apply least-privilege and need-to-know access.
- Prevent unauthorised access to systems and data.
- Protect API credentials, tokens and integration secrets.
- Secure partner and internal API communications.
- Maintain access logs and accountability.
- Detect and respond to suspicious access activity.
3. SCOPE
This Policy applies to employees, contractors, administrators, applications, APIs, servers, cloud environments, databases, endpoints and third-party integrations used for Company operations.
4. ACCESS PRINCIPLES
- Least privilege
- Need-to-know
- Role-based access
- Segregation of duties
- Unique user identity
- Periodic review
- Prompt de-provisioning
5. USER ACCESS REQUEST
- Business owner identifies the requirement.
- Access level is defined according to role.
- Authorised approver reviews the request.
- IT/administration provisions access.
- Access is recorded and periodically reviewed.
6. USER ID & ACCOUNT MANAGEMENT
Users shall have unique accounts wherever technically feasible. Shared accounts shall be avoided and, where unavoidable, controlled and monitored.
7. AUTHENTICATION
- Appropriate authentication shall be required for protected systems.
- Multi-factor authentication should be enabled for privileged and sensitive access where feasible.
- Authentication secrets shall be protected from disclosure.
- Failed or suspicious authentication activity should be monitored.
8. PRIVILEGED ACCESS
Administrative and privileged access shall be restricted to authorised personnel, used only when required and subject to enhanced monitoring and periodic review.
9. JOINER / MOVER / LEAVER CONTROLS
Access shall be created, modified or revoked promptly when personnel join, change roles or leave the Company.
10. PERIODIC ACCESS REVIEW
Access to critical systems, customer data, production environments and privileged functions shall be reviewed periodically based on risk.
11. API SECURITY
- Use authenticated and authorised API access.
- Validate all input and request parameters.
- Apply appropriate rate limiting and abuse controls.
- Protect API keys, tokens and secrets.
- Use secure transport for sensitive communications.
- Log relevant security and transaction events.
- Return secure error messages without unnecessary sensitive information.
12. API AUTHENTICATION & AUTHORISATION
APIs shall verify the identity and permissions of calling applications/users and enforce access restrictions at the appropriate endpoint and data level.
13. API CREDENTIALS & SECRETS
API keys, client secrets, tokens, signing keys and similar credentials shall be securely generated, stored, transmitted and rotated according to risk.
14. API INPUT VALIDATION
API requests shall be validated for format, type, length, permitted values and authorisation context to reduce injection, manipulation and abuse risks.
15. RATE LIMITING & ABUSE PREVENTION
Critical or public-facing APIs shall use appropriate rate limits, throttling, monitoring or other controls to reduce automated abuse and denial-of-service risk.
16. API LOGGING & MONITORING
- Authentication failures
- Authorisation failures
- Unusual request volume
- Sensitive endpoint activity
- Administrative actions
- Material configuration changes
- Relevant error patterns
17. API VERSIONING & CHANGE CONTROL
Material API changes shall follow documented change management, compatibility and testing procedures. Deprecated interfaces shall be retired or restricted within appropriate timelines.
18. SECURE DEVELOPMENT
Applications and APIs shall be developed and tested using appropriate secure coding, code review, dependency management and security testing practices.
19. THIRD-PARTY API ACCESS
External partners shall receive only the access required for their approved integration. Partner credentials and access permissions shall be periodically reviewed.
20. PRODUCTION ACCESS
Production access shall be restricted, authorised and monitored. Development or test credentials shall not be reused in production unless specifically approved and secured.
21. DATABASE ACCESS
Direct database access shall be restricted to authorised personnel and services. Privileged database activity should be logged and monitored where appropriate.
22. REMOTE ACCESS
Remote administrative access shall use approved secure mechanisms and appropriate authentication. Unauthorised remote access is prohibited.
23. ACCESS INCIDENTS
Suspected credential compromise, unauthorised access, token leakage or API abuse shall be escalated under the Cyber Incident Response & Cyber Fraud Policy.
24. ACCESS REVOCATION
Access shall be revoked or suspended when no longer required, when credentials are compromised or when security/risk circumstances justify restriction.
25. EXCEPTIONS
Exceptions shall be documented, risk-assessed, time-bound where appropriate and approved by authorised management.
26. RECORD KEEPING
Access requests, approvals, access reviews, privileged activity, API credentials and material security events shall be retained according to applicable requirements.
27. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Technology / IT | Provisioning, authentication, API and technical controls | Technology Head |
| Information Security | Security standards, monitoring and incident escalation | Security Head |
| Operations | Business access requirements and approvals | Operations Head |
| Compliance / Legal | Policy and regulatory oversight | Compliance / Legal |
| HR / Administration | Joiner-mover-leaver notifications | Management |
| Users / Partners | Protect credentials and use access appropriately | Management / Security |
28. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in systems, APIs, partner integrations, access architecture, security threats or applicable requirements.
29. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Technology / Operations | |
| Reviewed By | Compliance / Risk / Legal | |
| Approved By | Director / Authorised Signatory |