Haripay INDIA PRIVATE LIMITED
INFORMATION SECURITY & CYBER SECURITY POLICY
POLICY NO. 12 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | Haripay INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | Haripay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Information Security / Technology / Compliance |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the information-security and cyber-security governance framework for protecting Haripay's systems, applications, APIs, customer information, transaction data, business records and technology services against unauthorised access, misuse, alteration, disclosure, disruption and other security threats.
2. OBJECTIVES
- Protect confidentiality, integrity and availability of information.
- Reduce cyber and information-security risk.
- Maintain secure systems and applications.
- Protect customer and transaction information.
- Support secure partner integrations.
- Detect and respond to security incidents.
- Meet applicable legal, contractual and regulatory requirements.
3. SCOPE
This Policy applies to employees, contractors, consultants, systems, applications, APIs, cloud services, endpoints, networks, databases, third-party services and other technology resources used for Haripay business activities.
4. INFORMATION SECURITY PRINCIPLES
- Need-to-know access
- Least privilege
- Secure-by-design
- Defence in depth
- Data minimisation
- Accountability and logging
- Regular review and improvement
5. INFORMATION CLASSIFICATION
- Public
- Internal
- Confidential
- Restricted / Sensitive
Information shall be classified according to business impact, sensitivity, legal requirements and risk. Access and handling controls shall reflect the classification.
6. ASSET MANAGEMENT
Technology and information assets shall be identified and maintained in an appropriate inventory. Ownership and responsibility shall be assigned for critical systems and data.
7. ACCESS CONTROL
Access shall be granted based on business need and least privilege. User access shall be approved, periodically reviewed and revoked when no longer required.
8. AUTHENTICATION
- Strong passwords where passwords are used
- Multi-factor authentication for appropriate privileged or sensitive access
- Secure credential storage
- No credential sharing
- Prompt revocation of compromised credentials
9. PRIVILEGED ACCESS
Administrative and privileged access shall be restricted, separately controlled where practicable, logged and periodically reviewed.
10. ENDPOINT & DEVICE SECURITY
- Approved devices and software
- Security updates
- Malware protection where appropriate
- Screen/device protection
- Restricted removable media
- Secure disposal
11. NETWORK SECURITY
Networks and infrastructure shall use appropriate segmentation, firewalls, secure configurations, encryption and monitoring based on risk.
12. APPLICATION SECURITY
- Secure development practices
- Code review where appropriate
- Vulnerability assessment/testing
- Input validation
- Secure error handling
- Dependency management
- Production access restriction
13. API SECURITY
APIs shall use appropriate authentication, authorisation, encryption, rate limiting, input validation, logging and monitoring. API credentials shall be protected and rotated according to risk.
14. DATA SECURITY
Confidential and sensitive information shall be protected against unauthorised access, disclosure, alteration and destruction using appropriate technical and organisational controls.
15. ENCRYPTION
Encryption shall be used for sensitive information in transit and, where appropriate based on risk and system design, at rest. Cryptographic keys shall be protected and access restricted.
16. LOGGING & MONITORING
- Authentication events
- Privileged activity
- Transaction/API activity where relevant
- Security alerts
- System errors
- Administrative changes
Logs shall be protected against unauthorised modification and retained according to applicable requirements.
17. VULNERABILITY MANAGEMENT
- Identify vulnerabilities.
- Assess severity and business impact.
- Prioritise remediation.
- Apply patches or compensating controls.
- Validate remediation.
- Record closure.
18. PATCH & CHANGE MANAGEMENT
Security and system changes shall be tested and approved through appropriate change-management procedures. Emergency changes shall be documented and reviewed after implementation.
19. BACKUP & RECOVERY
Critical information and systems shall have appropriate backup and recovery arrangements consistent with the Business Continuity & Disaster Recovery Policy.
20. CYBER INCIDENT MANAGEMENT
Suspected cyber incidents shall be reported and managed under the Cyber Incident Response & Cyber Fraud Policy. Evidence shall be preserved and relevant stakeholders escalated according to severity.
21. PHISHING & SOCIAL ENGINEERING
Personnel shall receive awareness guidance regarding phishing, malicious links, impersonation, credential theft, OTP scams and other social-engineering risks.
22. THIRD-PARTY SECURITY
Third parties with access to Haripay systems or information shall be subject to appropriate due diligence, contractual security requirements, access controls and monitoring under the Third-Party / Vendor Risk Management Policy.
23. CLOUD & HOSTING SECURITY
Cloud and hosting environments shall be configured according to security requirements, with appropriate identity controls, network restrictions, logging, backups and vulnerability management.
24. REMOTE ACCESS
Remote access to business systems shall use approved secure mechanisms and appropriate authentication. Access shall be restricted based on business need.
25. SECURE DISPOSAL
Devices, media and information shall be securely disposed of or sanitised when no longer required, taking account of information sensitivity and applicable retention obligations.
26. EMPLOYEE / USER RESPONSIBILITIES
- Protect credentials
- Use approved systems
- Report suspicious activity
- Do not install unauthorised software
- Follow access and data-handling procedures
- Complete required security training
27. SECURITY AWARENESS & TRAINING
Relevant personnel shall receive periodic information-security and cyber-security awareness training appropriate to their role.
28. SECURITY TESTING
Haripay may conduct vulnerability assessments, security reviews, configuration reviews, penetration testing or other testing appropriate to the risk and criticality of systems.
29. INCIDENT REPORTING
Security concerns shall be reported promptly through designated internal channels. Personnel shall not conceal suspected security incidents.
30. DATA PROTECTION
Personal and customer data shall be processed and retained according to applicable requirements and Haripay's Data Protection, Privacy & Retention Policy.
31. BUSINESS CONTINUITY
Critical technology services shall have continuity and recovery arrangements proportionate to their business impact and shall be covered by the Business Continuity & Disaster Recovery Policy.
32. AUDIT & COMPLIANCE
Security controls may be reviewed through internal assessments, partner audits, external assessments or other assurance activities. Identified deficiencies shall be tracked to remediation.
33. EXCEPTIONS
Security exceptions shall be documented, risk-assessed, time-bound where appropriate and approved by an authorised person. Exceptions shall not be used to bypass mandatory legal or contractual requirements.
34. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Technology / IT | Infrastructure, systems and security controls | Technology Head |
| Information Security | Security governance, monitoring and testing | Management |
| Compliance | Policy oversight and regulatory/partner requirements | Management |
| Operations | Business-process controls and incident coordination | Operations Head |
| HR / Administration | Joiner-mover-leaver and awareness coordination | Management |
| Third-Party Management | Vendor security requirements and monitoring | Compliance / Management |
| All Users | Follow security requirements and report incidents | Manager / Security |
35. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in technology, cyber risk, business operations, partner requirements or applicable law.
36. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Technology / Compliance | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
