e-suvidha

CYBERVED AI PRIVATE LIMITED

ACCESS CONTROL & API SECURITY POLICY

POLICY NO. 16 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Policy OwnerInformation Security / Technology / Operations
Review FrequencyAt least annually / event driven
ClassificationConfidential – Access & API Security Controlled Policy

1. PURPOSE

This Policy establishes controls for user access, privileged access, authentication, application interfaces and APIs used by CYBERVED AI PRIVATE LIMITED to protect systems, customer information, transaction data, gift-card/voucher services and partner integrations.

2. OBJECTIVES

  • Apply least-privilege and need-to-know access.
  • Prevent unauthorised access to systems and data.
  • Protect API credentials, tokens and integration secrets.
  • Secure partner and internal API communications.
  • Maintain access logs and accountability.
  • Detect and respond to suspicious access activity.

3. SCOPE

This Policy applies to employees, contractors, administrators, applications, APIs, servers, cloud environments, databases, endpoints and third-party integrations used for Company operations.

4. ACCESS PRINCIPLES

  • Least privilege
  • Need-to-know
  • Role-based access
  • Segregation of duties
  • Unique user identity
  • Periodic review
  • Prompt de-provisioning

5. USER ACCESS REQUEST

  1. Business owner identifies the requirement.
  2. Access level is defined according to role.
  3. Authorised approver reviews the request.
  4. IT/administration provisions access.
  5. Access is recorded and periodically reviewed.

6. USER ID & ACCOUNT MANAGEMENT

Users shall have unique accounts wherever technically feasible. Shared accounts shall be avoided and, where unavoidable, controlled and monitored.

7. AUTHENTICATION

  • Appropriate authentication shall be required for protected systems.
  • Multi-factor authentication should be enabled for privileged and sensitive access where feasible.
  • Authentication secrets shall be protected from disclosure.
  • Failed or suspicious authentication activity should be monitored.

8. PRIVILEGED ACCESS

Administrative and privileged access shall be restricted to authorised personnel, used only when required and subject to enhanced monitoring and periodic review.

9. JOINER / MOVER / LEAVER CONTROLS

Access shall be created, modified or revoked promptly when personnel join, change roles or leave the Company.

10. PERIODIC ACCESS REVIEW

Access to critical systems, customer data, production environments and privileged functions shall be reviewed periodically based on risk.

11. API SECURITY

  • Use authenticated and authorised API access.
  • Validate all input and request parameters.
  • Apply appropriate rate limiting and abuse controls.
  • Protect API keys, tokens and secrets.
  • Use secure transport for sensitive communications.
  • Log relevant security and transaction events.
  • Return secure error messages without unnecessary sensitive information.

12. API AUTHENTICATION & AUTHORISATION

APIs shall verify the identity and permissions of calling applications/users and enforce access restrictions at the appropriate endpoint and data level.

13. API CREDENTIALS & SECRETS

API keys, client secrets, tokens, signing keys and similar credentials shall be securely generated, stored, transmitted and rotated according to risk.

14. API INPUT VALIDATION

API requests shall be validated for format, type, length, permitted values and authorisation context to reduce injection, manipulation and abuse risks.

15. RATE LIMITING & ABUSE PREVENTION

Critical or public-facing APIs shall use appropriate rate limits, throttling, monitoring or other controls to reduce automated abuse and denial-of-service risk.

16. API LOGGING & MONITORING

  • Authentication failures
  • Authorisation failures
  • Unusual request volume
  • Sensitive endpoint activity
  • Administrative actions
  • Material configuration changes
  • Relevant error patterns

17. API VERSIONING & CHANGE CONTROL

Material API changes shall follow documented change management, compatibility and testing procedures. Deprecated interfaces shall be retired or restricted within appropriate timelines.

18. SECURE DEVELOPMENT

Applications and APIs shall be developed and tested using appropriate secure coding, code review, dependency management and security testing practices.

19. THIRD-PARTY API ACCESS

External partners shall receive only the access required for their approved integration. Partner credentials and access permissions shall be periodically reviewed.

20. PRODUCTION ACCESS

Production access shall be restricted, authorised and monitored. Development or test credentials shall not be reused in production unless specifically approved and secured.

21. DATABASE ACCESS

Direct database access shall be restricted to authorised personnel and services. Privileged database activity should be logged and monitored where appropriate.

22. REMOTE ACCESS

Remote administrative access shall use approved secure mechanisms and appropriate authentication. Unauthorised remote access is prohibited.

23. ACCESS INCIDENTS

Suspected credential compromise, unauthorised access, token leakage or API abuse shall be escalated under the Cyber Incident Response & Cyber Fraud Policy.

24. ACCESS REVOCATION

Access shall be revoked or suspended when no longer required, when credentials are compromised or when security/risk circumstances justify restriction.

25. EXCEPTIONS

Exceptions shall be documented, risk-assessed, time-bound where appropriate and approved by authorised management.

26. RECORD KEEPING

Access requests, approvals, access reviews, privileged activity, API credentials and material security events shall be retained according to applicable requirements.

27. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Technology / ITProvisioning, authentication, API and technical controlsTechnology Head
Information SecuritySecurity standards, monitoring and incident escalationSecurity Head
OperationsBusiness access requirements and approvalsOperations Head
Compliance / LegalPolicy and regulatory oversightCompliance / Legal
HR / AdministrationJoiner-mover-leaver notificationsManagement
Users / PartnersProtect credentials and use access appropriatelyManagement / Security

28. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in systems, APIs, partner integrations, access architecture, security threats or applicable requirements.

29. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByInformation Security / Technology / Operations
Reviewed ByCompliance / Risk / Legal
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – ACCESS & API SECURITY CONTROLLED POLICY