Legal
Information Security Statement
This statement describes, in principle, the organisational and technical measures RupeeBiz applies to protect the platform and the data entrusted to it.
Last updated:
Purpose and status of this statement
RupeeBiz processes transaction data on behalf of business partners. This statement explains our approach to protecting that data and the systems it passes through.
It is a description of intent and practice, expressed in principle. It is not a certification, an audit report or a warranty. Specific certifications and independent attestations are not claimed here; where such a certification is obtained and independently verified, it will be published separately and dated. Contractual security commitments, if any, are those set out in the executed agreement with the Partner.
Governance
Security responsibilities are assigned within the organisation, with a named owner accountable for information-security policy, incident handling and periodic review. Policies are reviewed at planned intervals and after any significant incident or material change to the platform.
Access control
- Access to production systems is limited to personnel whose role requires it, and is granted on a least-privilege basis.
- Individual accounts are used; shared logins are avoided.
- Administrative access requires additional authentication.
- Access rights are reviewed periodically and revoked promptly when a role changes or an engagement ends.
- Partner API credentials are issued per entity and can be rotated or revoked on request or on suspicion of compromise.
Encryption and data protection
- Traffic between partner systems, end-user browsers and RupeeBiz endpoints is protected using TLS.
- Credentials and secrets are stored in a protected form and are not written to application logs.
- Sensitive identifiers are masked in support tooling and in operational displays where full values are not required.
- We do not accept or store payment card numbers, banking credentials, passwords or one-time passwords through our APIs.
Platform and network security
- Production, staging and sandbox environments are separated, and sandbox does not process live customer data.
- Network exposure is limited to the services that must be reachable, protected by firewalling and transport security.
- Rate limiting and abuse controls protect the APIs from excessive or malicious traffic.
- Systems and dependencies are patched on a risk-prioritised basis, with urgent fixes applied out of cycle.
Secure development and change management
- Changes are version-controlled, peer-reviewed and tested before release.
- Access to source repositories and deployment pipelines is restricted to authorised personnel.
- Secrets are held in a secret store, not in code.
- Breaking changes to partner-facing interfaces follow the notice practice described in the Developer Terms.
Logging and monitoring
Platform activity, API traffic, authentication events and administrative actions are logged. Logs support service monitoring, fraud detection, troubleshooting and investigation of incidents, and are retained for a defined period before disposal.
Incident response
Our incident-handling approach follows a consistent sequence:
- Detect and record — the event is logged and assigned an owner.
- Contain — access is restricted, credentials rotated and affected components isolated as required.
- Assess — scope, cause and any data involvement are established.
- Notify — affected partners are informed without undue delay, and authorities are notified where the law requires it.
- Remediate and review — the cause is fixed and a review is carried out to prevent recurrence.
Partners should report suspected security issues to sales@rupeebiz.com as described in the Acceptable Use Policy.
Backups and continuity
Transactional records are backed up so that they can be restored after a failure, and restoration is tested periodically. Availability of the transactional services also depends on telecom operators, utilities, billers and intermediaries whose systems are outside our control; we monitor those connections and communicate disruption to partners.
Vendor management
Third parties that host, support or process data on our behalf are engaged under written terms that require appropriate confidentiality and security, limit their use of data to the services provided to us, and are reviewed periodically. We do not name individual vendors in this statement; the categories of processors used can be requested at sales@rupeebiz.com.
People and training
- Employees and contractors are bound by confidentiality obligations.
- Security expectations, including credential handling and phishing awareness, are communicated during induction and reinforced periodically.
- Access is provisioned on joining and revoked as part of the exit process.
The partner’s role
Security is shared. Partners are responsible for protecting their own credentials, securing their platform and customer-facing flows, sending only the data required for a transaction, and reporting suspected compromise promptly. The obligations set out in the Developer Terms apply.
Review of this statement
This statement is reviewed periodically and updated as our practices evolve. The "last updated" date at the top of the page shows when it was last revised.
Contact
TRUEHOST IT SERVICES PVT LTD. (operating the RupeeBiz platform)
Office No. 1007A, Newa Bhakti Knowledge City, IT-06, Airoli Knowledge City, TTC Industrial Area, Airoli, Navi Mumbai, Maharashtra 400708, India
Email: sales@rupeebiz.com
Phone: +91 95 2222 1213