Technical & Organizational Safeguards
Version: 1.0 Effective: 2 September 2026 Last Updated: 2 September 2026

Data Security Policy

This Data Security Policy describes the security measures and practices used by ARZAQ INSIGHTS to protect information managed through its centralized account, authentication, identity, billing, and related services.

Core Security Principle:
ARZAQ INSIGHTS protects central identity, authentication credentials, and billing infrastructure, while individual products remain independently responsible for securing their own operational data. Central authentication does not grant administrators access to every user's product data.

1. Purpose & 2. Scope

This policy details technical and organizational safeguards implemented to secure centralized accounts, authentication flows, Passkeys, audit logs, and commercial billing services.

Decoupled Architecture: Operational databases of individual ecosystem platforms reside within their respective isolated infrastructure and are governed by product-specific security controls.

3. Core Security Principles

3.1 Restricted Access
Production environments are accessible only to verified, authorized system administrators.
3.2 Least Necessary Privilege
Administrative permissions are restricted to the bare minimum required for system maintenance.
3.3 End-to-End Encryption
Data is secured in transit via modern TLS and encrypted at rest across cloud storage.
3.4 Authentication Safeguards
Passwordless Passkeys (FIDO2/WebAuthn), bcrypt hashing, and hardware MFA protect account access.

4. Encryption Standards

4.1 In Transit: All network traffic between client browsers, APIs, and servers is enforced over HTTPS with TLS 1.3 / 1.2 encryption.

4.2 At Rest: Production databases and storage volumes are encrypted using AWS KMS hardware security modules.

5. Database Security & 6. Administrative Access

Central production databases reside in isolated private VPC subnets with no public internet ingress. Direct database connections require multi-factor SSH bastion authentication.

7. Cryptographic Password Security

Passwords are never stored in plaintext or reversible formats. Credentials are processed using adaptive salted bcrypt hashing algorithms.

8. Multi-Factor Authentication & 9. Passkeys (FIDO2)

ARZAQ INSIGHTS natively supports hardware-backed Passkeys (biometrics, TouchID, Windows Hello, YubiKey) and TOTP authenticator apps (Google Authenticator, Microsoft Authenticator) for unphishable authentication.

10. Magic Links & 11. Automated Login Defense

Intelligent rate-limiting, IP reputation checks, brute-force mitigation, and automated anomaly detection prevent credential stuffing and automated bot attacks.

12. Security Audit Logs & Monitoring

Comprehensive immutable audit logs record authentication attempts, Passkey registrations, 2FA challenges, password resets, and session revocations.

13. User Security Controls & 14. Session Management

Users can view active device sessions and trigger instant remote global logout across all connected browsers from the Central Account security hub.

15. AWS Infrastructure (Mumbai Region)

Central identity infrastructure is hosted in Amazon Web Services (AWS) data centers located in Mumbai, India (ap-south-1), adhering to SOC 1/2/3, ISO 27001, and PCI-DSS compliance frameworks.

16. Product Data Separation & 17. Internal Access Controls

Zero Unrestricted Access:

Central authentication provides verified identity tokens to connected applications without granting central administrators visibility into internal application operational tables.

18. Billing & Payment Gateway Security

Payment transactions are processed directly by certified PCI-DSS Level 1 compliant partners: PayU, Razorpay, Cashfree, and PhonePe. Raw credit card data never touches ARZAQ web servers.

20. Backup Architecture

Production infrastructure evolutions and future disaster recovery architectures are maintained under strict encrypted lifecycle controls.

21. Security Incident Response & 22. Compromised Accounts

Our incident response protocols isolate compromised credentials, invalidate active tokens, enforce password/Passkey rotations, and notify affected users in compliance with Indian regulatory mandates.

23. Shared User Responsibility

Users must maintain unique passwords, protect physical authenticator devices, enable 2FA/Passkeys, and avoid sharing one-time passcodes (OTPs).

26. Interconnected Policies

27. Security Incident Reporting & Contact

Information Security Team
ARZAQ INSIGHTS, D Block, New Ashok Nagar, Delhi 110096, India
* Never transmit plaintext passwords or payment card details via email.

28. Core Security Principle Summary

ARZAQ INSIGHTS secures centralized identity, authentication, and billing infrastructure, while individual products remain responsible for safeguarding their own application data.