Skip to Content

Information Security Policy

Last Updated: September 1, 2026

1. Purpose

Andabhurji Global Solutions is committed to protecting the confidentiality, integrity, availability, authenticity, and lawful processing of information entrusted to us by customers, partners, suppliers, employees, contractors, users, and other stakeholders.

This Information Security Policy describes the general principles, safeguards, responsibilities, and procedures used to manage information security risks across our software implementation, software development, consulting, design, marketplace, cloud, e-commerce, support, and digital services operations.

This policy is intended to:

  • Protect information from unauthorized access, disclosure, alteration, destruction, loss, or misuse

  • Support the secure delivery and operation of our services

  • Reduce the likelihood and impact of security incidents

  • Establish security responsibilities for personnel and customers

  • Promote compliance with applicable contractual, legal, regulatory, and privacy obligations

  • Support business continuity, disaster recovery, and operational resilience

  • Encourage continuous improvement of our security practices

This policy provides general information about our security approach. Specific security commitments may be established through applicable contracts, statements of work, data processing agreements, service agreements, or other written arrangements.

2. Scope

This policy applies to information, systems, services, facilities, and personnel associated with Andabhurji Global Solutions, including:

  • Websites, portals, applications, and digital platforms operated by us

  • Customer implementation and configuration projects

  • Custom software development and integrations

  • Cloud-hosted systems and infrastructure

  • Development, testing, staging, and production environments

  • Customer support and service management activities

  • Creative, design, branding, and digital production services

  • Marketplace, e-commerce, and print-on-demand operations

  • Internal business systems and administrative tools

  • Company-owned or managed devices

  • Remote work environments

  • Employees, contractors, consultants, temporary personnel, and authorized service providers

  • Third-party platforms and vendors used to provide or support our services

The policy applies to information in any form, including electronic records, databases, source code, credentials, documents, communications, customer content, personal data, financial information, business information, and physical records.

3. Information Security Objectives

Our information security program is designed to support the following objectives:

3.1 Confidentiality

Information should be accessible only to authorized individuals, systems, and service providers with a legitimate business or contractual need.

3.2 Integrity

Information and systems should be protected against unauthorized modification, corruption, manipulation, or destruction.

3.3 Availability

Systems and information should remain available and usable for authorized purposes, subject to maintenance, outages, third-party dependencies, and other operational limitations.

3.4 Authenticity

We seek to verify the identity and authority of users, systems, vendors, and other parties before granting access to protected resources.

3.5 Accountability

Security-relevant activities should be attributable to authorized users, systems, or processes where reasonably practicable.

3.6 Privacy

Personal information should be collected, used, stored, disclosed, and retained in accordance with applicable privacy laws, contractual obligations, and our Privacy Policy.

3.7 Resilience

We seek to maintain reasonable capabilities to prevent, respond to, recover from, and learn from security incidents and service disruptions.

4. Security Governance and Risk Management

We use a risk-based approach to information security. Security measures may vary depending on:

  • The nature and sensitivity of the information

  • The type of service being provided

  • The potential impact of unauthorized access or loss

  • Applicable legal and contractual requirements

  • The technical environment

  • The likelihood and severity of identified threats

  • The cost, feasibility, and effectiveness of available safeguards

Security risks may be identified through operational reviews, project planning, vendor assessments, vulnerability reports, incident investigations, customer requirements, and changes to systems or services.

Where appropriate, identified risks may be:

  • Mitigated through technical or organizational safeguards

  • Transferred through contractual arrangements or insurance

  • Avoided by changing a process or service

  • Accepted by an authorized decision-maker based on documented considerations

5. Information Classification

Information may be classified according to its sensitivity, business value, legal requirements, and potential impact if compromised.

Typical classifications may include:

5.1 Public Information

Information approved for public disclosure, such as published website content, public marketing materials, or publicly available service descriptions.

5.2 Internal Information

Information intended for internal business use that is not generally available to the public.

5.3 Confidential Information

Information that could cause business, financial, legal, operational, or reputational harm if improperly disclosed.

5.4 Restricted Information

Highly sensitive information requiring enhanced protection, such as credentials, security information, personal data, payment-related information, proprietary source code, or confidential customer information.

Personnel and service providers are expected to handle information according to its classification and applicable contractual requirements.

6. Access Control

Access to systems and information is managed according to business need, role, authorization, and risk.

Our access control practices may include:

  • Assigning access based on job responsibilities

  • Applying the principle of least privilege

  • Limiting administrative access

  • Using individual accounts rather than shared credentials where practicable

  • Requiring authentication before access is granted

  • Reviewing access rights periodically or when responsibilities change

  • Removing or modifying access when personnel leave or change roles

  • Restricting access to production systems

  • Separating development, testing, staging, and production environments where appropriate

  • Using additional authentication controls for sensitive systems

Personnel must not attempt to access systems, accounts, data, or facilities without proper authorization.

7. Authentication and Credential Security

We seek to protect authentication information through reasonable safeguards, which may include:

  • Password complexity requirements

  • Secure password storage

  • Multi-factor authentication where available and appropriate

  • Account lockout or rate-limiting controls

  • Session timeout mechanisms

  • Credential rotation for sensitive accounts

  • Secure handling of API keys, tokens, certificates, and secrets

  • Restrictions on sharing credentials

  • Monitoring for suspicious authentication activity

Personnel must not disclose passwords, authentication tokens, private keys, or other credentials to unauthorized persons. Suspected credential compromise must be reported promptly.

Customers are responsible for protecting credentials associated with their accounts, users, integrations, and administrative access.

8. Data Protection

We seek to protect information throughout its lifecycle, including collection, use, transmission, storage, sharing, archiving, and deletion.

Depending on the nature of the information and service, safeguards may include:

  • Encryption during transmission

  • Encryption at rest where appropriate

  • Access restrictions

  • Secure storage configurations

  • Data minimization

  • Pseudonymization or anonymization where appropriate

  • Secure deletion procedures

  • Backup protection

  • Retention controls

  • Restrictions on downloading or copying sensitive information

No security measure can eliminate all risks. Customers should avoid submitting information that is unnecessary for the requested service.

9. Network and Infrastructure Security

We may use reasonable infrastructure and network security controls, including:

  • Firewalls and access filtering

  • Network segmentation

  • Secure configuration standards

  • Intrusion detection or monitoring tools

  • Traffic monitoring

  • Secure remote access methods

  • Protection against malicious software

  • Cloud security controls

  • Restrictions on exposed services and ports

  • Administrative access controls

  • Security updates and configuration reviews

The specific controls used may vary depending on the service, hosting provider, technology stack, project requirements, and risk profile.

10. Application and Software Security

For software development, implementation, and integration activities, we seek to incorporate security throughout the development and delivery lifecycle.

Security practices may include:

  • Requirements-based security reviews

  • Secure coding practices

  • Code review where appropriate

  • Dependency and package management

  • Input validation

  • Output encoding

  • Authentication and authorization controls

  • Protection against common application vulnerabilities

  • Secure handling of errors and logs

  • Testing in non-production environments

  • Controlled deployment procedures

  • Separation of development and production access

  • Review of third-party libraries and integrations

  • Remediation of identified vulnerabilities based on risk

Customers are responsible for providing accurate requirements, approving configurations, testing deliverables, and promptly reporting suspected defects or vulnerabilities.

11. Vulnerability and Patch Management

We seek to identify and address vulnerabilities in systems and services based on their severity, exploitability, exposure, business impact, and available remediation options.

Vulnerability management may include:

  • Monitoring relevant security advisories

  • Applying security patches and updates

  • Updating software dependencies

  • Reviewing cloud and platform configurations

  • Conducting vulnerability assessments where appropriate

  • Prioritizing critical and high-risk issues

  • Temporarily applying compensating controls when immediate patching is not possible

  • Documenting remediation activities where appropriate

Patch timing may be affected by testing requirements, vendor availability, system dependencies, customer approval, maintenance windows, and service continuity considerations.

12. Logging, Monitoring, and Auditability

Where appropriate and technically feasible, we may maintain logs and monitoring records relating to:

  • Authentication events

  • Administrative actions

  • System changes

  • Security alerts

  • Application activity

  • Service availability

  • Error conditions

  • Data access or transfer events

Logs may be used for security monitoring, troubleshooting, service improvement, compliance, incident investigation, and operational support.

Access to logs is restricted according to business need. Log retention may vary based on system capabilities, legal requirements, contractual obligations, storage limitations, and operational needs.

13. Backup and Recovery

We seek to maintain reasonable backup and recovery practices for systems and information that are important to business operations or service delivery.

Backup practices may include:

  • Scheduled backups

  • Protection of backup credentials

  • Access restrictions

  • Storage in separate environments

  • Backup integrity checks

  • Recovery testing where appropriate

  • Retention schedules

  • Protection against accidental deletion or unauthorized alteration

Backups may not be available for every system, customer environment, project, or type of information. Customers should maintain independent copies of important content and data where appropriate.

14. Business Continuity and Disaster Recovery

We seek to maintain reasonable plans and procedures to respond to events that may affect service availability or business operations, including:

  • Cybersecurity incidents

  • Hardware or software failures

  • Cloud or hosting disruptions

  • Natural disasters

  • Utility failures

  • Loss of personnel

  • Supply-chain or vendor disruptions

  • Accidental deletion or corruption

  • Other significant operational events

Recovery objectives may vary by service and may be subject to specific contractual commitments. Recovery efforts will be prioritized based on business impact, customer obligations, system dependencies, available resources, and the nature of the event.

15. Security Incident Management

A security incident may include:

  • Unauthorized access to systems or information

  • Suspected credential compromise

  • Malware or ransomware activity

  • Accidental disclosure of confidential information

  • Loss or theft of a device containing protected information

  • Unauthorized alteration or destruction of data

  • Significant service disruption caused by a security event

  • Exploitation of a vulnerability

  • Improper use of systems or information

Our incident response activities may include:

  1. Identifying and recording the suspected incident

  2. Assessing its scope, severity, and potential impact

  3. Containing or limiting the incident

  4. Preserving relevant evidence and records

  5. Removing the cause where reasonably practicable

  6. Restoring affected systems or services

  7. Notifying affected parties where required

  8. Conducting a post-incident review

  9. Implementing corrective or preventive measures

Notifications will be made in accordance with applicable law, contractual obligations, and the nature of the incident. We may not disclose information that would compromise an investigation, create additional security risks, or violate legal restrictions.

16. Security Incident Reporting

Personnel, customers, and authorized users should promptly report suspected security incidents, vulnerabilities, phishing attempts, unauthorized access, data exposure, or other security concerns.

Reports should include, where available:

  • Date and time of the event

  • Systems, accounts, or services involved

  • Description of what occurred

  • Relevant screenshots, messages, logs, or evidence

  • Steps already taken

  • Contact information for follow-up

Reports may be submitted to:

andabhurji.corp@outlook.com

email@andabhurjiglobal.com

Individuals should not publicly disclose suspected vulnerabilities before allowing a reasonable opportunity for investigation and remediation.

17. Personnel Security and Awareness

We seek to ensure that personnel with access to systems or confidential information understand their security responsibilities.

Measures may include:

  • Confidentiality obligations

  • Security and privacy awareness guidance

  • Role-based training

  • Acceptable use requirements

  • Secure handling procedures

  • Reporting obligations

  • Access restrictions

  • Disciplinary or contractual consequences for misuse

Personnel must protect company and customer information during and after their engagement with Andabhurji Global Solutions.

18. Device and Endpoint Security

Company-managed or authorized devices may be subject to reasonable security requirements, including:

  • Password or screen-lock protection

  • Operating system and software updates

  • Malware protection

  • Encryption where appropriate

  • Secure configuration

  • Restrictions on unauthorized software

  • Remote access controls

  • Secure disposal or re-use procedures

  • Reporting of lost or stolen devices

Personnel should avoid accessing confidential information through unsecured, shared, public, or compromised devices.

19. Physical Security

Where applicable, reasonable physical safeguards may be used to protect facilities, equipment, records, and infrastructure.

These safeguards may include:

  • Controlled access to work areas

  • Visitor management

  • Secure storage of sensitive records

  • Protection against theft or unauthorized removal

  • Environmental protections

  • Secure disposal of physical documents and media

  • Restrictions on access to infrastructure locations

Because some services may rely on third-party cloud, hosting, data center, or platform providers, physical security may also be governed by those providers’ controls and policies.

20. Third-Party and Vendor Security

We may use third-party providers for hosting, cloud infrastructure, payment processing, communications, analytics, software tools, development services, support, fulfillment, and other business functions.

Where appropriate, third-party risk management may include:

  • Reviewing the provider’s services and security practices

  • Assessing the sensitivity of information shared

  • Establishing contractual confidentiality and security obligations

  • Limiting vendor access

  • Monitoring service performance

  • Reviewing material changes to vendor services

  • Requiring incident notification where contractually applicable

  • Replacing or restricting providers when risks are unacceptable

Third-party providers remain responsible for the security of their own systems and services.

21. Data Retention and Secure Disposal

Information should be retained only for as long as reasonably necessary for business, legal, contractual, operational, security, or dispute-resolution purposes.

When information is no longer required, it may be:

  • Deleted

  • Anonymized

  • Aggregated

  • Archived with restricted access

  • Securely destroyed

  • Returned to the customer where applicable

Deletion may be subject to backup cycles, legal holds, technical limitations, contractual requirements, or third-party retention practices.

22. Customer Responsibilities

Customers play an important role in maintaining the security of their accounts, systems, data, and users.

Customers are responsible for:

  • Maintaining strong and unique passwords

  • Enabling multi-factor authentication where available

  • Protecting account credentials and access tokens

  • Managing authorized users and permissions

  • Removing access for former employees or contractors

  • Maintaining endpoint, device, and network security

  • Reviewing integrations and third-party permissions

  • Keeping customer-controlled software and systems updated

  • Providing accurate configuration and security requirements

  • Reviewing and approving project deliverables

  • Maintaining appropriate backups of customer-controlled content

  • Promptly reporting suspected incidents or vulnerabilities

  • Ensuring that submitted content is lawful and appropriately authorized

  • Avoiding the submission of unnecessary sensitive information

We are not responsible for security issues caused by customer systems, customer instructions, unauthorized customer access, unsupported modifications, compromised credentials, or third-party services controlled by the customer.

23. Security Testing and Assessments

Security testing, audits, penetration testing, vulnerability assessments, or compliance reviews may be conducted where appropriate, required by contract, or reasonably necessary based on risk.

Testing activities must be authorized in advance. Customers and third parties must not conduct scanning, penetration testing, denial-of-service testing, or other potentially disruptive activities against our systems without prior written permission.

24. Policy Exceptions

Exceptions to this policy may be permitted when necessary for legitimate business, technical, legal, or operational reasons.

Exceptions should be:

  • Documented where appropriate

  • Reviewed for security impact

  • Approved by an authorized person

  • Limited in scope and duration

  • Subject to compensating controls where feasible

25. Compliance and Enforcement

Failure to comply with this policy may result in:

  • Access restrictions

  • Suspension of accounts or services

  • Corrective action

  • Contractual remedies

  • Disciplinary measures

  • Legal action

  • Reporting to appropriate authorities where required

We may investigate suspected violations and take reasonable steps to protect systems, information, customers, personnel, and third parties.

26. Limitations and No Absolute Security Guarantee

We implement safeguards that we believe are reasonable and appropriate for the nature of our services and the risks involved. However, no system, network, application, device, transmission method, or storage environment can be guaranteed to be completely secure.

Security risks may arise from:

  • Human error

  • Sophisticated cyberattacks

  • Zero-day vulnerabilities

  • Third-party failures

  • Cloud or hosting outages

  • Internet limitations

  • Customer configuration errors

  • Compromised credentials

  • Malware

  • Physical events

  • Unforeseen technical or operational circumstances

Accordingly, we do not guarantee that our services will be uninterrupted, error-free, immune from vulnerabilities, or completely protected against unauthorized access.

27. Policy Updates

We may update this Information Security Policy periodically to reflect changes in:

  • Technology

  • Services

  • Security threats

  • Legal or regulatory requirements

  • Industry practices

  • Business operations

  • Customer or contractual requirements

The updated version will be posted or otherwise communicated through appropriate channels. The “Last Updated” date indicates when the policy was most recently revised.

28. Contact Information

Questions about this Information Security Policy, security practices, vulnerability reports, or suspected security incidents may be directed to:

andabhurji.corp@outlook.com

email@andabhurjiglobal.com