e-suvidha

CYBERVED AI PRIVATE LIMITED

INFORMATION SECURITY &
CYBER SECURITY POLICY

POLICY NO. 12VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Policy OwnerInformation Security / Technology / Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Information Security Controlled Policy

1. PURPOSE

This Policy establishes the information-security and cyber-security framework for protecting CYBERVED AI PRIVATE LIMITED's systems, applications, APIs, customer information, transaction data, voucher information and business operations against unauthorised access, misuse, alteration, disclosure, disruption and cyber threats.

2. OBJECTIVES

  • Protect confidentiality, integrity and availability of information.
  • Reduce cyber-security and technology risks.
  • Secure customer, payment, voucher and partner data.
  • Establish access, monitoring, vulnerability and incident controls.
  • Support secure operation of APIs and third-party integrations.
  • Promote security awareness and accountability.

3. SCOPE

This Policy applies to employees, contractors, systems, applications, cloud services, APIs, endpoints, networks, databases, third-party services and information assets used for Company operations.

4. INFORMATION SECURITY PRINCIPLES

  • Least privilege
  • Need-to-know access
  • Defence in depth
  • Secure-by-design
  • Risk-based controls
  • Logging and accountability
  • Data minimisation
  • Continuous improvement

5. INFORMATION ASSET MANAGEMENT

Material information assets shall be identified and assigned an owner. Where appropriate, assets shall be classified according to sensitivity, business criticality and regulatory/contractual requirements.

6. ACCESS CONTROL

Access shall be granted based on role and business need. Privileged access shall be restricted and reviewed periodically.

7. AUTHENTICATION

  • Strong authentication shall be used where appropriate.
  • Administrative and privileged accounts shall receive enhanced protection.
  • Shared credentials shall be avoided.
  • Credentials shall be stored and handled securely.

8. USER ACCESS LIFECYCLE

  1. Approve access request.
  2. Create access according to role.
  3. Review access periodically.
  4. Modify access upon role change.
  5. Promptly disable access on exit or when no longer required.

9. PASSWORD & CREDENTIAL SECURITY

Passwords, API keys, tokens, secrets and other authentication credentials shall be protected against disclosure and unauthorised reuse. Sensitive secrets shall not be stored in insecure locations.

10. API & APPLICATION SECURITY

Applications and APIs shall use appropriate authentication, authorisation, input validation, rate controls, secure error handling, logging and secure development practices.

11. DATA SECURITY

  • Sensitive data shall be protected during storage and transmission where appropriate.
  • Access to customer and transaction data shall be restricted.
  • Data exports shall be controlled.
  • Unauthorised copying or disclosure is prohibited.

12. NETWORK & ENDPOINT SECURITY

Networks, servers, workstations and other endpoints shall be protected through appropriate security configuration, patching, malware protection and monitoring measures.

13. VULNERABILITY MANAGEMENT

Security vulnerabilities shall be identified, risk-assessed and remediated according to severity and business impact. Critical issues shall receive prompt attention.

14. PATCH MANAGEMENT

Operating systems, applications, libraries and infrastructure shall be patched within risk-based timelines, subject to testing and operational requirements.

15. LOGGING & MONITORING

  • Authentication and access events
  • Administrative activity
  • Important transaction/system events
  • Security alerts
  • API and application errors
  • Material configuration changes

16. SECURITY INCIDENTS

Suspected or confirmed cyber-security incidents shall be escalated under the Cyber Incident Response & Cyber Fraud Policy.

17. INCIDENT EVIDENCE

Relevant logs, alerts, system records and other evidence shall be preserved to support investigation, remediation, partner coordination and applicable reporting.

18. BACKUP & RECOVERY

Critical information and systems shall be backed up according to business requirements. Backup access shall be restricted and recovery procedures periodically tested where appropriate.

19. CHANGE MANAGEMENT

Material changes to production systems, APIs, infrastructure and security controls shall follow documented change-management and approval procedures.

20. SECURE DEVELOPMENT

  • Code review where appropriate
  • Dependency and vulnerability management
  • Secure configuration
  • Input validation
  • Authentication and authorisation testing
  • Security testing before material production release

21. THIRD-PARTY SECURITY

Third parties handling sensitive data or critical technology shall be subject to appropriate security due diligence, contractual requirements and monitoring.

22. CLOUD / HOSTED SERVICES

Cloud and hosted environments shall use appropriate identity, access, configuration, logging, backup and security controls consistent with the risk of the service.

23. DATA RETENTION & DISPOSAL

Information shall be retained only for applicable legal, regulatory, contractual and business requirements and securely disposed of when no longer required, subject to preservation obligations.

24. EMPLOYEE SECURITY AWARENESS

Relevant personnel shall receive security awareness training covering phishing, credential protection, social engineering, data handling, incident reporting and acceptable use.

25. ACCEPTABLE USE

Company systems and information shall be used only for authorised business purposes. Security controls shall not be bypassed without documented authorisation.

26. REMOTE ACCESS

Remote access shall be restricted to approved users and systems and protected through appropriate authentication, secure connectivity and device controls.

27. PHYSICAL SECURITY

Physical access to offices, systems, devices and sensitive records shall be appropriately restricted and monitored according to risk.

28. SECURITY TESTING

Security controls may be assessed through vulnerability scanning, configuration reviews, access reviews, penetration testing or other appropriate assurance activities.

29. REGULATORY / PARTNER COORDINATION

Security matters affecting PPI, banking, payment or other regulated partners shall be escalated through agreed channels and handled according to applicable requirements.

30. EXCEPTIONS

Security exceptions shall be documented, risk-assessed, time-bound where appropriate and approved by authorised management.

31. RECORD KEEPING

Security records, access reviews, incidents, vulnerability findings, testing results, approvals and material changes shall be retained according to applicable requirements.

32. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ManagementSecurity governance and risk oversightDirector / Management
Information SecuritySecurity framework, monitoring and incidentsSecurity Head
Technology / ITInfrastructure, applications, patches and backupsTechnology Head
ComplianceRegulatory and policy oversightCompliance Head
OperationsOperational security controlsOperations Head
All PersonnelProtect credentials/data and report incidentsManagement / Security

33. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in systems, threats, products, partner arrangements, technology or applicable requirements.

34. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByInformation Security / Technology / Compliance
Reviewed ByRisk / Legal / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – INFORMATION SECURITY CONTROLLED POLICY

This document is confidential and intended for authorised use only.