Authentication & Identity Governance
Effective: 2 September 2026 Last Updated: 2 September 2026

Account & Authentication Policy

This Account & Authentication Policy establishes the rules and practices governing ARZAQ INSIGHTS accounts and the authentication services used to access services within the ARZAQ INSIGHTS ecosystem.

Core Architectural Principle:
ARZAQ INSIGHTS provides a centralized account and authentication system that allows users to use a single ARZAQ account across participating products, while maintaining strict separation between central account services and product-specific operational data.

1. Purpose

The purpose of this policy is to establish a secure, consistent, and controlled authentication experience while maintaining a clear separation between central account services and product-specific operational data.

2. Scope

This policy applies to the central ARZAQ INSIGHTS account system, including:

Account registration & Account identity
Password & Phone OTP authentication
Two-factor & Authenticator apps
Passkeys (FIDO2/WebAuthn) & Magic links
Account recovery & Session management
Device/login activity & Security events
Account switching & Multi-account pool
Account deletion & Ecosystem access

This policy does not govern the internal authentication or authorization rules that an individual product may implement for its own product-specific functions.

3. Central Account Model

ARZAQ INSIGHTS operates a centralized account model. A user creates an ARZAQ account once and may use that account to authenticate with participating products without creating a separate authentication identity for every product.

4. Account Identity & Multi-Account Isolation

Each ARZAQ account represents a distinct account identity. A user may have multiple ARZAQ accounts and may sign into multiple accounts on the same device.

Accounts remain separate even when accessed from the same device. Information belonging to one ARZAQ account is not automatically merged with another ARZAQ account. Account switching allows users to move between separately authenticated accounts seamlessly without repeated logouts.

5. Account Registration

Users may create an ARZAQ account using supported registration flows. Information required includes: Name, Email address, Phone number, Gender, Recovery email address, and authentication credentials.

Users are responsible for providing accurate information. ARZAQ INSIGHTS may implement verification mechanisms to confirm ownership of an email address or phone number.

6. Authentication Methods

6.1 Email and Password
Authenticated via registered email and hashed password. Passwords are never stored in plain-text readable form.
6.2 Phone OTP
One-time temporary codes delivered to registered mobile numbers with strict time-to-live expiration.
6.3 Two-Factor Authentication (2FA)
Secondary verification factor required during login for enhanced identity protection.
6.4 Authenticator Applications
Time-based One-Time Password (TOTP) integration using standard authenticator apps.
6.5 Passkeys (FIDO2 / WebAuthn)
Hardware-backed biometric or security-key authentication without disclosing raw biometrics.
6.6 Magic Links
Secure, single-use, time-limited direct sign-in email links. Non-forwardable.

7. Authentication Security Controls

Security controls include cryptographic password hashing, 2FA, passkeys, secure session management, login monitoring, authentication logging, IP/device anomaly detection, and failed attempt rate limiting.

8. Password Requirements

Users must use unique passwords, avoid predictable strings, avoid reusing passwords across services, and immediately update credentials upon suspected compromise.

9. Two-Factor Authentication

Users should maintain control over their second-factor devices. If lost, the official account recovery process must be followed.

10. Passkey & Biometric Security

Privacy Guarantee:

ARZAQ INSIGHTS does not collect or store your underlying biometric data (fingerprint, Face ID, etc.). Biometric verification happens locally on your device hardware in accordance with FIDO2 / WebAuthn standards.

11. Account Recovery

Account recovery methods include verified recovery email, phone verification, and pre-configured factors. ARZAQ INSIGHTS may delay or deny recovery requests if ownership cannot be satisfactorily established.

12. Recovery Email

A recovery email is used for ownership verification, security alerts, and recovery communications. Users must ensure continuous control over their recovery email account.

13. Login and Security Records

We maintain records of login/logout history, successful and failed authentications, IP addresses, client devices, session durations, 2FA/Passkey events, and security setting modifications.

14. User Access to Account Activity

Users can view their active sessions, recent logins, device types, and download security logs directly from their Central ARZAQ Account dashboard.

15. Account Switching

Users can maintain an active multi-account pool on a single browser. Users must verify the active profile before initiating actions inside connected products.

16. Product Authentication & 17. Separation From Product Data

Authentication Does Not Equal Product Data Access:

ARZAQ INSIGHTS identifies and authenticates who the user is. Individual products determine product-specific roles (e.g. Admin, Manager, Member) and maintain their own databases.

18. Session Management

Central sessions include secure expiration, renewal tokens, remote logout, and session invalidation triggers upon password changes.

19. Suspicious or Unauthorized Activity

Upon detecting anomaly events (repeated failed attempts, credential stuffing, impossible travel logins), ARZAQ INSIGHTS may enforce re-authentication, challenge with 2FA, invalidate active sessions, or temporarily restrict authentication.

20. Account Security Responsibilities

Users are responsible for safeguarding credentials, devices, and OTP codes. Never share magic links or 2FA codes with third parties.

21. Compromised Accounts

Immediate Actions on Suspicion of Compromise:
1. Change password immediately via Central Account.
2. Revoke all active sessions under Security settings.
3. Contact support at support@arzaqinsights.com.

22. Security Changes & 23. Account Deletion

Users may initiate permanent deletion directly through the account dashboard. Deletion permanently revokes authentication tokens, subject to required financial/audit record retentions.

24. Multiple Accounts & 25. Authentication Availability

ARZAQ INSIGHTS aims for high availability across central authentication endpoints, but may occasionally undergo scheduled maintenance or emergency security mitigation.

26. Policy Updates & 27. Contact Information

ARZAQ INSIGHTS Legal & Security Office
D Block, New Ashok Nagar, Delhi 110096, India

28. Core Security Principle Summary

Centralized authentication does not mean centralized product data.

ARZAQ INSIGHTS manages identity and authentication. Participating platforms manage their own operational records and authorizations.