Security Policy
Last updated: 23 August 2026
This Security Policy ('Policy') describes the information security practices and commitments of Atusha Ventures Private Limited (CIN: U46901UP2025PTC231921) and its portfolio ventures. We take the security of our systems, products, and the data entrusted to us by our customers and users seriously. This Policy outlines our security framework, the measures we implement to protect information assets, and our approach to security incident management. For information on how to report security vulnerabilities, please refer to our Responsible Disclosure Policy.
1. Security Governance
Atusha Ventures maintains a security governance framework that establishes accountability, policies, and procedures for information security across our organisation and portfolio ventures.
Security responsibilities are assigned to appropriate personnel within our organisation. We conduct periodic reviews of our security policies and practices to ensure they remain effective and aligned with current threats and best practices.
We maintain documented security policies and procedures that govern the handling of information assets, access controls, incident response, and other security-relevant activities.
2. Infrastructure Security
Our websites and SaaS products are hosted on reputable cloud infrastructure providers that maintain industry-standard security certifications and compliance programmes.
Network Security: We implement network security controls including firewalls, intrusion detection systems, and network segmentation to protect our infrastructure from unauthorised access and malicious activity.
Encryption in Transit: All data transmitted between your browser and our websites and applications is encrypted using TLS (Transport Layer Security) with strong cipher suites. We enforce HTTPS on all our web properties.
Encryption at Rest: Sensitive data stored in our systems is encrypted at rest using industry-standard encryption algorithms.
Access Controls: Access to our production systems is restricted to authorised personnel on a need-to-know basis. We implement multi-factor authentication for administrative access to critical systems.
Patch Management: We maintain a patch management programme to ensure that our systems and software are kept up to date with security patches and updates.
3. Application Security
We follow secure software development practices in the design, development, and deployment of our products and services.
Code Review: Our development process includes code review procedures designed to identify and remediate security vulnerabilities before deployment.
Dependency Management: We monitor our software dependencies for known vulnerabilities and update them promptly when security patches are available.
Input Validation: Our applications implement input validation and output encoding to protect against common web application vulnerabilities, including SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF).
Authentication and Authorisation: Our applications implement strong authentication mechanisms and role-based access controls to ensure that users can only access data and functionality appropriate to their role.
4. Data Security
We implement appropriate technical and organisational measures to protect personal and business data against unauthorised access, disclosure, alteration, or destruction.
Data Classification: We classify data according to its sensitivity and apply appropriate security controls based on classification.
Data Minimisation: We collect and retain only the data necessary for the purposes described in our Privacy Policy.
Data Backup: We maintain regular backups of critical data to ensure business continuity in the event of data loss or system failure.
Data Disposal: When data is no longer required, we securely delete or destroy it in accordance with our data retention policies.
5. Personnel Security
We implement personnel security measures to reduce the risk of insider threats and ensure that our team members handle information assets responsibly.
Background Checks: We conduct appropriate background checks on personnel with access to sensitive systems and data, in accordance with applicable law.
Security Training: We provide security awareness training to our personnel to ensure they understand their security responsibilities and can identify and respond to security threats.
Confidentiality Obligations: All personnel with access to sensitive information are subject to confidentiality obligations.
Access Revocation: We promptly revoke access to systems and data when personnel leave our organisation or change roles.
6. Third-Party Security
We assess the security practices of third-party service providers before engaging them to process data on our behalf.
We enter into data processing agreements with third-party processors that include appropriate security requirements.
We monitor our third-party relationships on an ongoing basis and review their security practices periodically.
7. Security Incident Management
We maintain a security incident response plan that defines the procedures for detecting, reporting, assessing, and responding to security incidents.
Detection and Reporting: We implement monitoring and alerting systems to detect potential security incidents. Personnel are trained to recognise and report security incidents promptly.
Assessment and Containment: Upon detection of a security incident, we assess its scope and impact and take immediate steps to contain the incident and prevent further damage.
Notification: In the event of a security incident that is likely to result in a risk to the rights and freedoms of individuals whose data we process, we will notify the affected individuals and relevant regulatory authorities as required by applicable law.
Post-Incident Review: Following a security incident, we conduct a post-incident review to identify the root cause and implement measures to prevent recurrence.
8. Business Continuity
We maintain business continuity and disaster recovery plans to ensure that our critical systems and services can be restored promptly in the event of a significant disruption.
We conduct periodic testing of our business continuity and disaster recovery plans to verify their effectiveness.
9. Compliance
We maintain compliance with applicable information security laws and regulations, including the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
We conduct periodic security assessments to evaluate the effectiveness of our security controls and identify areas for improvement.
10. Reporting Security Concerns
If you have a security concern about our systems or products, or if you believe you have discovered a security vulnerability, please refer to our Responsible Disclosure Policy for guidance on how to report it responsibly.
For general security enquiries, please contact us at: [email protected]
Atusha Ventures Private Limited, KHS-773, Bisrakh, Jalalpur, Bishrakh, Noida, Gautambuddha Nagar, Uttar Pradesh, 201306, India.
Atusha Ventures Private Limited · CIN: U46901UP2025PTC231921 · GSTIN: 09ABDCA6877C1ZI
KHS-773, Bisrakh, Jalalpur, Bishrakh, Noida, Gautambuddha Nagar, Uttar Pradesh, 201306, India