Cyber Security Policy
Platform: Stamp Mitra | Operator: Bani Global Industries LLP (India) | Effective Date: 22/04/2026
1. Objective and Scope
1.1 This Cyber Security Policy (“Policy”) establishes the framework adopted by Bani Global Industries LLP (“Company”) to safeguard the confidentiality, integrity, and availability of its systems, infrastructure, and user data associated with the Stamp Mitra platform (“Platform”).
1.2 This Policy applies to all digital systems, applications, databases, Users, and third-party service providers.
1.3 The Company adopts a risk-based security approach consistent with applicable Indian laws and industry practices.
2. Security Governance and Framework
2.1 The Company implements administrative, technical, and organizational safeguards to protect data and systems.
2.2 Security governance includes defined access control policies, internal monitoring, risk assessment, and periodic updates.
3. Technical Security Controls
3.1 The Company implements measures including:
- Encryption of data in transit (TLS/SSL) and at rest
- Role-based access control (RBAC)
- Secure authentication (OTP-based)
- Continuous logging, monitoring, and anomaly detection
- Firewalls and system hardening
- Secure coding practices and regular vulnerability assessments
4. Access Control and Authentication
4.1 Access is restricted to authorized personnel. Authentication controls include OTP verification for Users and strict credential management.
4.2 Unauthorized access attempts may result in immediate restriction or blocking.
5. Data Protection Measures
5.1 The Company safeguards personal data, transactional data, and audit records.
5.2 Data is handled in accordance with the Company’s Privacy Policy and applicable law.
6. User Responsibilities
Users shall maintain confidentiality of OTPs, use secure networks, and report any suspected breaches immediately to customercare@stampmitra.in.
7. Incident Response
The Company maintains procedures for detection, containment, investigation, and recovery. Services may be temporarily suspended to mitigate threats.
8. Third-Party Risk Management
The Company undertakes reasonable due diligence of partners like payment gateways and eSign providers but is not liable for failures beyond its control.
9. Monitoring and Audit
User activity and system access are logged for security monitoring, fraud detection, and compliance purposes.
10. Business Continuity
Reasonable procedures for data backup, system restoration, and recovery are maintained.
11. Prohibited Activities
Users shall not introduce malware, exploit vulnerabilities, or interference with Platform functionality. Violations may result in legal action.
12. Limitation of Liability
No system is 100% secure. The Company is not liable for breaches caused by user negligence or external cyber attacks beyond reasonable control.