Skip to content
DPDP
Draft outline·counsel review pending

Security Policy

How we protect the personal data entrusted to us — encryption, access control, monitoring, testing and incident response.

Sections
6Sections
Always
PublicAlways
Governing law
IndiaGoverning law

Draft outline — not yet legally binding. This page lists the sections this document must contain. The operative text needs your legal entity name, registered address and Grievance Officer details, and must be reviewed by counsel before publication. Send us those details and we will complete it.

1. Encryption

Data encrypted in transit and at rest, with key management practice described.

2. Access control

Role-based access, least privilege, and time-bound approvals for staff access to customer data.

3. Monitoring and logging

What is logged, how long logs are kept, and who reviews them.

4. Testing

Cadence of vulnerability scanning and independent penetration testing.

5. Incident response

Detection, containment, notification and post-incident review.

6. Business continuity

Backup, restore testing and recovery objectives.

Questions about this document? Write to [email protected].