Data Security Policy
This Data Security Policy describes the security measures and practices used by ARZAQ INSIGHTS to protect information managed through its centralized account, authentication, identity, billing, and related services.
1. Purpose & 2. Scope
This policy details technical and organizational safeguards implemented to secure centralized accounts, authentication flows, Passkeys, audit logs, and commercial billing services.
Decoupled Architecture: Operational databases of individual ecosystem platforms reside within their respective isolated infrastructure and are governed by product-specific security controls.
3. Core Security Principles
4. Encryption Standards
4.1 In Transit: All network traffic between client browsers, APIs, and servers is enforced over HTTPS with TLS 1.3 / 1.2 encryption.
4.2 At Rest: Production databases and storage volumes are encrypted using AWS KMS hardware security modules.
5. Database Security & 6. Administrative Access
Central production databases reside in isolated private VPC subnets with no public internet ingress. Direct database connections require multi-factor SSH bastion authentication.
7. Cryptographic Password Security
Passwords are never stored in plaintext or reversible formats. Credentials are processed using adaptive salted bcrypt hashing algorithms.
8. Multi-Factor Authentication & 9. Passkeys (FIDO2)
ARZAQ INSIGHTS natively supports hardware-backed Passkeys (biometrics, TouchID, Windows Hello, YubiKey) and TOTP authenticator apps (Google Authenticator, Microsoft Authenticator) for unphishable authentication.
10. Magic Links & 11. Automated Login Defense
Intelligent rate-limiting, IP reputation checks, brute-force mitigation, and automated anomaly detection prevent credential stuffing and automated bot attacks.
12. Security Audit Logs & Monitoring
Comprehensive immutable audit logs record authentication attempts, Passkey registrations, 2FA challenges, password resets, and session revocations.
13. User Security Controls & 14. Session Management
Users can view active device sessions and trigger instant remote global logout across all connected browsers from the Central Account security hub.
15. AWS Infrastructure (Mumbai Region)
Central identity infrastructure is hosted in Amazon Web Services (AWS) data centers located in Mumbai, India (ap-south-1), adhering to SOC 1/2/3, ISO 27001, and PCI-DSS compliance frameworks.
16. Product Data Separation & 17. Internal Access Controls
Central authentication provides verified identity tokens to connected applications without granting central administrators visibility into internal application operational tables.
18. Billing & Payment Gateway Security
Payment transactions are processed directly by certified PCI-DSS Level 1 compliant partners: PayU, Razorpay, Cashfree, and PhonePe. Raw credit card data never touches ARZAQ web servers.
20. Backup Architecture
Production infrastructure evolutions and future disaster recovery architectures are maintained under strict encrypted lifecycle controls.
21. Security Incident Response & 22. Compromised Accounts
Our incident response protocols isolate compromised credentials, invalidate active tokens, enforce password/Passkey rotations, and notify affected users in compliance with Indian regulatory mandates.
23. Shared User Responsibility
Users must maintain unique passwords, protect physical authenticator devices, enable 2FA/Passkeys, and avoid sharing one-time passcodes (OTPs).
26. Interconnected Policies
Read in conjunction with our Privacy Policy, Account & Authentication Policy, and Data Retention & Deletion Policy.