Security Policy
Last Updated: September 7, 2026
This Security Policy outlines the technical, organizational, and administrative measures implemented by
AICORZEN-BRAYNEXA TECHNOLOGIES (OPC) PRIVATE LIMITED
(hereinafter referred to as "Company", "We", "Us", or
"Our") to protect the confidentiality, integrity, and availability of personal data,
sensitive information, and all digital assets under our control.
This Policy is designed to comply with:
- The Information Technology Act, 2000 (IT Act) and Section 43A thereof[reference:2];
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011[reference:3];
- The Digital Personal Data Protection Act, 2023 (DPDP Act)[reference:4];
- The Digital Personal Data Protection Rules, 2025 (DPDP Rules)[reference:5];
- Directions and guidelines issued by the Indian Computer Emergency Response Team (CERT-In)[reference:6].
This Policy applies to all employees, trainers, interns, contractors, vendors, and third-party service
providers who access, process, or handle any data or systems owned or operated by the Company.
1. Scope and Applicability
This Security Policy applies to:
- All personal data collected, processed, or stored by the Company, including data of students enrolled in Training Programs, internship applicants, website visitors, and employees;
- All computer systems, servers, networks, databases, websites, mobile applications, and cloud infrastructure owned, leased, or operated by the Company;
- All data processing activities conducted by third-party service providers on behalf of the Company (e.g., payment gateways, hosting providers, analytics services);
- All employees, contractors, interns, and volunteers of the Company who have access to Company systems or data.
2. Reasonable Security Safeguards
The Company implements "reasonable security safeguards" as required under Section 43A of the IT Act, 2000 and the DPDP Rules, 2025[reference:7][reference:8]. These safeguards include, at a minimum, the following measures[reference:9][reference:10]:
2.1 Encryption
- All personal data in transit is protected using Transport Layer Security (TLS) encryption (HTTPS) across all web-based services[reference:11];
- Personal data at rest (stored on servers, databases, or cloud storage) is encrypted using industry-standard encryption algorithms[reference:12];
- Sensitive data such as payment information and identification documents are encrypted using additional layers of protection[reference:13].
2.2 Access Control
- Access to personal data and Company systems is restricted on a "need-to-know" and "least-privilege" basis[reference:14];
- Role-based access controls (RBAC) are implemented to ensure that employees, trainers, and contractors have access only to the data necessary for their specific job functions;
- Multi-factor authentication (MFA) is required for access to administrative systems, databases, and sensitive data repositories[reference:15];
- Access rights are regularly reviewed and revoked promptly upon termination of employment or engagement.
2.3 Data Obfuscation and Masking
- Sensitive personal data (e.g., Aadhaar numbers, PAN, financial information) is obfuscated, masked, or tokenized wherever feasible[reference:16][reference:17];
- Production data is not used for testing or development purposes without appropriate anonymization.
2.4 Logging and Monitoring
- All system logs (including firewall logs, web server logs, access logs, database logs, and email logs) are retained in a secure and accessible format[reference:18];
- Logs are retained for a minimum period of 180 days as required by CERT-In directions[reference:19][reference:20];
- Logs are stored within India to comply with data localization requirements[reference:21];
- Continuous monitoring and alerting systems are in place to detect unauthorized access, anomalies, and potential security incidents[reference:22].
2.5 Periodic Audits and Vulnerability Assessments
- The Company conducts regular security audits and vulnerability assessments of its systems and infrastructure[reference:23];
- Penetration testing is performed periodically to identify and remediate security weaknesses;
- Audit findings are documented, tracked, and resolved within defined timelines[reference:24].
2.6 Physical Security
- Physical access to Company premises and server rooms is restricted through access control systems, surveillance, and visitor management protocols;
- All physical records containing personal data are stored in locked and access-controlled areas.
3. Data Retention and Erasure
The Company adheres to the following data retention and erasure practices in compliance with Section 8(7) of the DPDP Act, 2023[reference:25]:
- Personal data is retained only for as long as necessary to fulfill the purpose for which it was collected, or as required by applicable law[reference:26];
- Upon withdrawal of consent by the data principal, or once the purpose of processing is served, personal data is securely erased or anonymized, unless retention is legally required[reference:27];
- A data retention schedule is maintained and periodically reviewed to ensure compliance[reference:28];
- Data that is no longer required is securely deleted using industry-standard data destruction methods.
4. Incident Response and Breach Notification
The Company has established a comprehensive Incident Response Plan to detect, respond to, and recover from security incidents and personal data breaches[reference:29].
4.1 Incident Detection and Triage
- Security incidents are detected through continuous monitoring, alerting systems, and user reports[reference:30];
- All reported incidents are triaged and assessed for severity and potential impact on personal data[reference:31].
4.2 Reporting to CERT-In
- All cyber security incidents, including personal data breaches, are reported to the Indian Computer Emergency Response Team (CERT-In) within six (6) hours of detection[reference:32][reference:33];
- Reports are submitted via email to incident@cert-in.org.in or through the CERT-In incident reporting portal[reference:34];
- The Company maintains records of all incident reports and communications with CERT-In.
4.3 Breach Notification to Data Principals
- In the event of a personal data breach that is likely to result in significant harm to affected data principals, the Company shall notify the affected individuals without undue delay[reference:35];
- Notifications shall include details of the breach, the nature of data compromised, potential consequences, and recommended mitigation measures.
4.4 Post-Incident Analysis
- Following an incident, a thorough post-incident analysis is conducted to identify root causes, lessons learned, and corrective actions[reference:36];
- Findings are documented and used to improve security controls and incident response procedures.
5. Third-Party Security
The Company engages third-party service providers (e.g., payment gateways, hosting providers, analytics services) to support its operations. All such engagements are subject to:
- Due diligence to assess the security posture of the third party[reference:37];
- Written contracts that include data protection and security obligations, including the requirement to implement reasonable security safeguards[reference:38];
- Regular monitoring and periodic reviews of third-party compliance with security requirements.
6. Employee Training and Awareness
The Company recognizes that human factors are critical to security. Accordingly:
- All employees, trainers, and contractors undergo security awareness training upon joining and at regular intervals thereafter;
- Training covers topics such as data protection, phishing prevention, password hygiene, incident reporting, and secure handling of personal data;
- Employees are made aware of their obligations under this Security Policy and applicable laws.
7. Data Protection Officer and Grievance Redressal
In compliance with the DPDP Act, 2023 and the IT Act, 2000, the Company has designated a
Grievance Officer / Data Protection Officer to oversee data protection and security matters.
The officer can be contacted at:
Grievance Officer: [Name of the Grievance Officer / Data Protection Officer]
Email: [Your Official Grievance Email Address]
Phone: [Your Official Contact Number]
Any concerns, complaints, or inquiries regarding data security or this Security Policy should be directed
to the Grievance Officer. The Company endeavors to acknowledge all complaints within 24 hours and resolve
them within 30 days.
8. Compliance and Enforcement
Compliance with this Security Policy is mandatory for all employees, contractors, and third-party
service providers. Non-compliance may result in disciplinary action, termination of employment or
engagement, and legal proceedings as applicable under Indian law.
The Company reserves the right to update, modify, or amend this Security Policy at any time to reflect
changes in legal requirements, industry best practices, or operational needs. Any changes will be
posted on this page with an updated "Last Updated" date.
9. Contact Us
If you have any questions, concerns, or requests regarding this Security Policy or our data security
practices, please contact us at:
AICORZEN-BRAYNEXA-TECHNOLOGIES (OPC) PRIVATE LIMITED
Email: info@aicorzenbraynexa.com
Important Note: This Security Policy is a living document and is subject to periodic review and updating. All users, employees, and stakeholders are encouraged to review this Policy regularly to stay informed about our security practices and their obligations.
© 2026 AICORZEN-BRAYNEXA TECHNOLOGIES (OPC) PRIVATE LIMITED. All Rights Reserved.