CYBERVED AI PRIVATE LIMITED
INFORMATION SECURITY &
CYBER SECURITY POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Policy Owner | Information Security / Technology / Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Information Security Controlled Policy |
1. PURPOSE
This Policy establishes the information-security and cyber-security framework for protecting CYBERVED AI PRIVATE LIMITED's systems, applications, APIs, customer information, transaction data, voucher information and business operations against unauthorised access, misuse, alteration, disclosure, disruption and cyber threats.
2. OBJECTIVES
- Protect confidentiality, integrity and availability of information.
- Reduce cyber-security and technology risks.
- Secure customer, payment, voucher and partner data.
- Establish access, monitoring, vulnerability and incident controls.
- Support secure operation of APIs and third-party integrations.
- Promote security awareness and accountability.
3. SCOPE
This Policy applies to employees, contractors, systems, applications, cloud services, APIs, endpoints, networks, databases, third-party services and information assets used for Company operations.
4. INFORMATION SECURITY PRINCIPLES
- Least privilege
- Need-to-know access
- Defence in depth
- Secure-by-design
- Risk-based controls
- Logging and accountability
- Data minimisation
- Continuous improvement
5. INFORMATION ASSET MANAGEMENT
Material information assets shall be identified and assigned an owner. Where appropriate, assets shall be classified according to sensitivity, business criticality and regulatory/contractual requirements.
6. ACCESS CONTROL
Access shall be granted based on role and business need. Privileged access shall be restricted and reviewed periodically.
7. AUTHENTICATION
- Strong authentication shall be used where appropriate.
- Administrative and privileged accounts shall receive enhanced protection.
- Shared credentials shall be avoided.
- Credentials shall be stored and handled securely.
8. USER ACCESS LIFECYCLE
- Approve access request.
- Create access according to role.
- Review access periodically.
- Modify access upon role change.
- Promptly disable access on exit or when no longer required.
9. PASSWORD & CREDENTIAL SECURITY
Passwords, API keys, tokens, secrets and other authentication credentials shall be protected against disclosure and unauthorised reuse. Sensitive secrets shall not be stored in insecure locations.
10. API & APPLICATION SECURITY
Applications and APIs shall use appropriate authentication, authorisation, input validation, rate controls, secure error handling, logging and secure development practices.
11. DATA SECURITY
- Sensitive data shall be protected during storage and transmission where appropriate.
- Access to customer and transaction data shall be restricted.
- Data exports shall be controlled.
- Unauthorised copying or disclosure is prohibited.
12. NETWORK & ENDPOINT SECURITY
Networks, servers, workstations and other endpoints shall be protected through appropriate security configuration, patching, malware protection and monitoring measures.
13. VULNERABILITY MANAGEMENT
Security vulnerabilities shall be identified, risk-assessed and remediated according to severity and business impact. Critical issues shall receive prompt attention.
14. PATCH MANAGEMENT
Operating systems, applications, libraries and infrastructure shall be patched within risk-based timelines, subject to testing and operational requirements.
15. LOGGING & MONITORING
- Authentication and access events
- Administrative activity
- Important transaction/system events
- Security alerts
- API and application errors
- Material configuration changes
16. SECURITY INCIDENTS
Suspected or confirmed cyber-security incidents shall be escalated under the Cyber Incident Response & Cyber Fraud Policy.
17. INCIDENT EVIDENCE
Relevant logs, alerts, system records and other evidence shall be preserved to support investigation, remediation, partner coordination and applicable reporting.
18. BACKUP & RECOVERY
Critical information and systems shall be backed up according to business requirements. Backup access shall be restricted and recovery procedures periodically tested where appropriate.
19. CHANGE MANAGEMENT
Material changes to production systems, APIs, infrastructure and security controls shall follow documented change-management and approval procedures.
20. SECURE DEVELOPMENT
- Code review where appropriate
- Dependency and vulnerability management
- Secure configuration
- Input validation
- Authentication and authorisation testing
- Security testing before material production release
21. THIRD-PARTY SECURITY
Third parties handling sensitive data or critical technology shall be subject to appropriate security due diligence, contractual requirements and monitoring.
22. CLOUD / HOSTED SERVICES
Cloud and hosted environments shall use appropriate identity, access, configuration, logging, backup and security controls consistent with the risk of the service.
23. DATA RETENTION & DISPOSAL
Information shall be retained only for applicable legal, regulatory, contractual and business requirements and securely disposed of when no longer required, subject to preservation obligations.
24. EMPLOYEE SECURITY AWARENESS
Relevant personnel shall receive security awareness training covering phishing, credential protection, social engineering, data handling, incident reporting and acceptable use.
25. ACCEPTABLE USE
Company systems and information shall be used only for authorised business purposes. Security controls shall not be bypassed without documented authorisation.
26. REMOTE ACCESS
Remote access shall be restricted to approved users and systems and protected through appropriate authentication, secure connectivity and device controls.
27. PHYSICAL SECURITY
Physical access to offices, systems, devices and sensitive records shall be appropriately restricted and monitored according to risk.
28. SECURITY TESTING
Security controls may be assessed through vulnerability scanning, configuration reviews, access reviews, penetration testing or other appropriate assurance activities.
29. REGULATORY / PARTNER COORDINATION
Security matters affecting PPI, banking, payment or other regulated partners shall be escalated through agreed channels and handled according to applicable requirements.
30. EXCEPTIONS
Security exceptions shall be documented, risk-assessed, time-bound where appropriate and approved by authorised management.
31. RECORD KEEPING
Security records, access reviews, incidents, vulnerability findings, testing results, approvals and material changes shall be retained according to applicable requirements.
32. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Security governance and risk oversight | Director / Management |
| Information Security | Security framework, monitoring and incidents | Security Head |
| Technology / IT | Infrastructure, applications, patches and backups | Technology Head |
| Compliance | Regulatory and policy oversight | Compliance Head |
| Operations | Operational security controls | Operations Head |
| All Personnel | Protect credentials/data and report incidents | Management / Security |
33. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in systems, threats, products, partner arrangements, technology or applicable requirements.
34. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Technology / Compliance | |
| Reviewed By | Risk / Legal / Management | |
| Approved By | Director / Authorised Signatory |