StampMitraStampMitra Developers
Legal & Policy Documentation

Cyber Security Policy

Platform: Stamp Mitra | Operator: Bani Global Industries LLP (India) | Effective Date: 22/04/2026

1. Objective and Scope

1.1 This Cyber Security Policy (“Policy”) establishes the framework adopted by Bani Global Industries LLP (“Company”) to safeguard the confidentiality, integrity, and availability of its systems, infrastructure, and user data associated with the Stamp Mitra platform (“Platform”).

1.2 This Policy applies to all digital systems, applications, databases, Users, and third-party service providers.

1.3 The Company adopts a risk-based security approach consistent with applicable Indian laws and industry practices.

2. Security Governance and Framework

2.1 The Company implements administrative, technical, and organizational safeguards to protect data and systems.

2.2 Security governance includes defined access control policies, internal monitoring, risk assessment, and periodic updates.

3. Technical Security Controls

3.1 The Company implements measures including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Role-based access control (RBAC)
  • Secure authentication (OTP-based)
  • Continuous logging, monitoring, and anomaly detection
  • Firewalls and system hardening
  • Secure coding practices and regular vulnerability assessments

4. Access Control and Authentication

4.1 Access is restricted to authorized personnel. Authentication controls include OTP verification for Users and strict credential management.

4.2 Unauthorized access attempts may result in immediate restriction or blocking.

5. Data Protection Measures

5.1 The Company safeguards personal data, transactional data, and audit records.

5.2 Data is handled in accordance with the Company’s Privacy Policy and applicable law.

6. User Responsibilities

Users shall maintain confidentiality of OTPs, use secure networks, and report any suspected breaches immediately to customercare@stampmitra.in.

7. Incident Response

The Company maintains procedures for detection, containment, investigation, and recovery. Services may be temporarily suspended to mitigate threats.

8. Third-Party Risk Management

The Company undertakes reasonable due diligence of partners like payment gateways and eSign providers but is not liable for failures beyond its control.

9. Monitoring and Audit

User activity and system access are logged for security monitoring, fraud detection, and compliance purposes.

10. Business Continuity

Reasonable procedures for data backup, system restoration, and recovery are maintained.

11. Prohibited Activities

Users shall not introduce malware, exploit vulnerabilities, or interference with Platform functionality. Violations may result in legal action.

12. Limitation of Liability

No system is 100% secure. The Company is not liable for breaches caused by user negligence or external cyber attacks beyond reasonable control.

By accessing or using the Platform, the User acknowledges and agrees to this Cyber Security Policy.