Information Security Policy
Last Updated: September 1, 2026
1. Purpose
Andabhurji Global Solutions is committed to protecting the confidentiality, integrity, availability, authenticity, and lawful processing of information entrusted to us by customers, partners, suppliers, employees, contractors, users, and other stakeholders.
This Information Security Policy describes the general principles, safeguards, responsibilities, and procedures used to manage information security risks across our software implementation, software development, consulting, design, marketplace, cloud, e-commerce, support, and digital services operations.
This policy is intended to:
Protect information from unauthorized access, disclosure, alteration, destruction, loss, or misuse
Support the secure delivery and operation of our services
Reduce the likelihood and impact of security incidents
Establish security responsibilities for personnel and customers
Promote compliance with applicable contractual, legal, regulatory, and privacy obligations
Support business continuity, disaster recovery, and operational resilience
Encourage continuous improvement of our security practices
This policy provides general information about our security approach. Specific security commitments may be established through applicable contracts, statements of work, data processing agreements, service agreements, or other written arrangements.
2. Scope
This policy applies to information, systems, services, facilities, and personnel associated with Andabhurji Global Solutions, including:
Websites, portals, applications, and digital platforms operated by us
Customer implementation and configuration projects
Custom software development and integrations
Cloud-hosted systems and infrastructure
Development, testing, staging, and production environments
Customer support and service management activities
Creative, design, branding, and digital production services
Marketplace, e-commerce, and print-on-demand operations
Internal business systems and administrative tools
Company-owned or managed devices
Remote work environments
Employees, contractors, consultants, temporary personnel, and authorized service providers
Third-party platforms and vendors used to provide or support our services
The policy applies to information in any form, including electronic records, databases, source code, credentials, documents, communications, customer content, personal data, financial information, business information, and physical records.
3. Information Security Objectives
Our information security program is designed to support the following objectives:
3.1 Confidentiality
Information should be accessible only to authorized individuals, systems, and service providers with a legitimate business or contractual need.
3.2 Integrity
Information and systems should be protected against unauthorized modification, corruption, manipulation, or destruction.
3.3 Availability
Systems and information should remain available and usable for authorized purposes, subject to maintenance, outages, third-party dependencies, and other operational limitations.
3.4 Authenticity
We seek to verify the identity and authority of users, systems, vendors, and other parties before granting access to protected resources.
3.5 Accountability
Security-relevant activities should be attributable to authorized users, systems, or processes where reasonably practicable.
3.6 Privacy
Personal information should be collected, used, stored, disclosed, and retained in accordance with applicable privacy laws, contractual obligations, and our Privacy Policy.
3.7 Resilience
We seek to maintain reasonable capabilities to prevent, respond to, recover from, and learn from security incidents and service disruptions.
4. Security Governance and Risk Management
We use a risk-based approach to information security. Security measures may vary depending on:
The nature and sensitivity of the information
The type of service being provided
The potential impact of unauthorized access or loss
Applicable legal and contractual requirements
The technical environment
The likelihood and severity of identified threats
The cost, feasibility, and effectiveness of available safeguards
Security risks may be identified through operational reviews, project planning, vendor assessments, vulnerability reports, incident investigations, customer requirements, and changes to systems or services.
Where appropriate, identified risks may be:
Mitigated through technical or organizational safeguards
Transferred through contractual arrangements or insurance
Avoided by changing a process or service
Accepted by an authorized decision-maker based on documented considerations
5. Information Classification
Information may be classified according to its sensitivity, business value, legal requirements, and potential impact if compromised.
Typical classifications may include:
5.1 Public Information
Information approved for public disclosure, such as published website content, public marketing materials, or publicly available service descriptions.
5.2 Internal Information
Information intended for internal business use that is not generally available to the public.
5.3 Confidential Information
Information that could cause business, financial, legal, operational, or reputational harm if improperly disclosed.
5.4 Restricted Information
Highly sensitive information requiring enhanced protection, such as credentials, security information, personal data, payment-related information, proprietary source code, or confidential customer information.
Personnel and service providers are expected to handle information according to its classification and applicable contractual requirements.
6. Access Control
Access to systems and information is managed according to business need, role, authorization, and risk.
Our access control practices may include:
Assigning access based on job responsibilities
Applying the principle of least privilege
Limiting administrative access
Using individual accounts rather than shared credentials where practicable
Requiring authentication before access is granted
Reviewing access rights periodically or when responsibilities change
Removing or modifying access when personnel leave or change roles
Restricting access to production systems
Separating development, testing, staging, and production environments where appropriate
Using additional authentication controls for sensitive systems
Personnel must not attempt to access systems, accounts, data, or facilities without proper authorization.
7. Authentication and Credential Security
We seek to protect authentication information through reasonable safeguards, which may include:
Password complexity requirements
Secure password storage
Multi-factor authentication where available and appropriate
Account lockout or rate-limiting controls
Session timeout mechanisms
Credential rotation for sensitive accounts
Secure handling of API keys, tokens, certificates, and secrets
Restrictions on sharing credentials
Monitoring for suspicious authentication activity
Personnel must not disclose passwords, authentication tokens, private keys, or other credentials to unauthorized persons. Suspected credential compromise must be reported promptly.
Customers are responsible for protecting credentials associated with their accounts, users, integrations, and administrative access.
8. Data Protection
We seek to protect information throughout its lifecycle, including collection, use, transmission, storage, sharing, archiving, and deletion.
Depending on the nature of the information and service, safeguards may include:
Encryption during transmission
Encryption at rest where appropriate
Access restrictions
Secure storage configurations
Data minimization
Pseudonymization or anonymization where appropriate
Secure deletion procedures
Backup protection
Retention controls
Restrictions on downloading or copying sensitive information
No security measure can eliminate all risks. Customers should avoid submitting information that is unnecessary for the requested service.
9. Network and Infrastructure Security
We may use reasonable infrastructure and network security controls, including:
Firewalls and access filtering
Network segmentation
Secure configuration standards
Intrusion detection or monitoring tools
Traffic monitoring
Secure remote access methods
Protection against malicious software
Cloud security controls
Restrictions on exposed services and ports
Administrative access controls
Security updates and configuration reviews
The specific controls used may vary depending on the service, hosting provider, technology stack, project requirements, and risk profile.
10. Application and Software Security
For software development, implementation, and integration activities, we seek to incorporate security throughout the development and delivery lifecycle.
Security practices may include:
Requirements-based security reviews
Secure coding practices
Code review where appropriate
Dependency and package management
Input validation
Output encoding
Authentication and authorization controls
Protection against common application vulnerabilities
Secure handling of errors and logs
Testing in non-production environments
Controlled deployment procedures
Separation of development and production access
Review of third-party libraries and integrations
Remediation of identified vulnerabilities based on risk
Customers are responsible for providing accurate requirements, approving configurations, testing deliverables, and promptly reporting suspected defects or vulnerabilities.
11. Vulnerability and Patch Management
We seek to identify and address vulnerabilities in systems and services based on their severity, exploitability, exposure, business impact, and available remediation options.
Vulnerability management may include:
Monitoring relevant security advisories
Applying security patches and updates
Updating software dependencies
Reviewing cloud and platform configurations
Conducting vulnerability assessments where appropriate
Prioritizing critical and high-risk issues
Temporarily applying compensating controls when immediate patching is not possible
Documenting remediation activities where appropriate
Patch timing may be affected by testing requirements, vendor availability, system dependencies, customer approval, maintenance windows, and service continuity considerations.
12. Logging, Monitoring, and Auditability
Where appropriate and technically feasible, we may maintain logs and monitoring records relating to:
Authentication events
Administrative actions
System changes
Security alerts
Application activity
Service availability
Error conditions
Data access or transfer events
Logs may be used for security monitoring, troubleshooting, service improvement, compliance, incident investigation, and operational support.
Access to logs is restricted according to business need. Log retention may vary based on system capabilities, legal requirements, contractual obligations, storage limitations, and operational needs.
13. Backup and Recovery
We seek to maintain reasonable backup and recovery practices for systems and information that are important to business operations or service delivery.
Backup practices may include:
Scheduled backups
Protection of backup credentials
Access restrictions
Storage in separate environments
Backup integrity checks
Recovery testing where appropriate
Retention schedules
Protection against accidental deletion or unauthorized alteration
Backups may not be available for every system, customer environment, project, or type of information. Customers should maintain independent copies of important content and data where appropriate.
14. Business Continuity and Disaster Recovery
We seek to maintain reasonable plans and procedures to respond to events that may affect service availability or business operations, including:
Cybersecurity incidents
Hardware or software failures
Cloud or hosting disruptions
Natural disasters
Utility failures
Loss of personnel
Supply-chain or vendor disruptions
Accidental deletion or corruption
Other significant operational events
Recovery objectives may vary by service and may be subject to specific contractual commitments. Recovery efforts will be prioritized based on business impact, customer obligations, system dependencies, available resources, and the nature of the event.
15. Security Incident Management
A security incident may include:
Unauthorized access to systems or information
Suspected credential compromise
Malware or ransomware activity
Accidental disclosure of confidential information
Loss or theft of a device containing protected information
Unauthorized alteration or destruction of data
Significant service disruption caused by a security event
Exploitation of a vulnerability
Improper use of systems or information
Our incident response activities may include:
Identifying and recording the suspected incident
Assessing its scope, severity, and potential impact
Containing or limiting the incident
Preserving relevant evidence and records
Removing the cause where reasonably practicable
Restoring affected systems or services
Notifying affected parties where required
Conducting a post-incident review
Implementing corrective or preventive measures
Notifications will be made in accordance with applicable law, contractual obligations, and the nature of the incident. We may not disclose information that would compromise an investigation, create additional security risks, or violate legal restrictions.
16. Security Incident Reporting
Personnel, customers, and authorized users should promptly report suspected security incidents, vulnerabilities, phishing attempts, unauthorized access, data exposure, or other security concerns.
Reports should include, where available:
Date and time of the event
Systems, accounts, or services involved
Description of what occurred
Relevant screenshots, messages, logs, or evidence
Steps already taken
Contact information for follow-up
Reports may be submitted to:
Individuals should not publicly disclose suspected vulnerabilities before allowing a reasonable opportunity for investigation and remediation.
17. Personnel Security and Awareness
We seek to ensure that personnel with access to systems or confidential information understand their security responsibilities.
Measures may include:
Confidentiality obligations
Security and privacy awareness guidance
Role-based training
Acceptable use requirements
Secure handling procedures
Reporting obligations
Access restrictions
Disciplinary or contractual consequences for misuse
Personnel must protect company and customer information during and after their engagement with Andabhurji Global Solutions.
18. Device and Endpoint Security
Company-managed or authorized devices may be subject to reasonable security requirements, including:
Password or screen-lock protection
Operating system and software updates
Malware protection
Encryption where appropriate
Secure configuration
Restrictions on unauthorized software
Remote access controls
Secure disposal or re-use procedures
Reporting of lost or stolen devices
Personnel should avoid accessing confidential information through unsecured, shared, public, or compromised devices.
19. Physical Security
Where applicable, reasonable physical safeguards may be used to protect facilities, equipment, records, and infrastructure.
These safeguards may include:
Controlled access to work areas
Visitor management
Secure storage of sensitive records
Protection against theft or unauthorized removal
Environmental protections
Secure disposal of physical documents and media
Restrictions on access to infrastructure locations
Because some services may rely on third-party cloud, hosting, data center, or platform providers, physical security may also be governed by those providers’ controls and policies.
20. Third-Party and Vendor Security
We may use third-party providers for hosting, cloud infrastructure, payment processing, communications, analytics, software tools, development services, support, fulfillment, and other business functions.
Where appropriate, third-party risk management may include:
Reviewing the provider’s services and security practices
Assessing the sensitivity of information shared
Establishing contractual confidentiality and security obligations
Limiting vendor access
Monitoring service performance
Reviewing material changes to vendor services
Requiring incident notification where contractually applicable
Replacing or restricting providers when risks are unacceptable
Third-party providers remain responsible for the security of their own systems and services.
21. Data Retention and Secure Disposal
Information should be retained only for as long as reasonably necessary for business, legal, contractual, operational, security, or dispute-resolution purposes.
When information is no longer required, it may be:
Deleted
Anonymized
Aggregated
Archived with restricted access
Securely destroyed
Returned to the customer where applicable
Deletion may be subject to backup cycles, legal holds, technical limitations, contractual requirements, or third-party retention practices.
22. Customer Responsibilities
Customers play an important role in maintaining the security of their accounts, systems, data, and users.
Customers are responsible for:
Maintaining strong and unique passwords
Enabling multi-factor authentication where available
Protecting account credentials and access tokens
Managing authorized users and permissions
Removing access for former employees or contractors
Maintaining endpoint, device, and network security
Reviewing integrations and third-party permissions
Keeping customer-controlled software and systems updated
Providing accurate configuration and security requirements
Reviewing and approving project deliverables
Maintaining appropriate backups of customer-controlled content
Promptly reporting suspected incidents or vulnerabilities
Ensuring that submitted content is lawful and appropriately authorized
Avoiding the submission of unnecessary sensitive information
We are not responsible for security issues caused by customer systems, customer instructions, unauthorized customer access, unsupported modifications, compromised credentials, or third-party services controlled by the customer.
23. Security Testing and Assessments
Security testing, audits, penetration testing, vulnerability assessments, or compliance reviews may be conducted where appropriate, required by contract, or reasonably necessary based on risk.
Testing activities must be authorized in advance. Customers and third parties must not conduct scanning, penetration testing, denial-of-service testing, or other potentially disruptive activities against our systems without prior written permission.
24. Policy Exceptions
Exceptions to this policy may be permitted when necessary for legitimate business, technical, legal, or operational reasons.
Exceptions should be:
Documented where appropriate
Reviewed for security impact
Approved by an authorized person
Limited in scope and duration
Subject to compensating controls where feasible
25. Compliance and Enforcement
Failure to comply with this policy may result in:
Access restrictions
Suspension of accounts or services
Corrective action
Contractual remedies
Disciplinary measures
Legal action
Reporting to appropriate authorities where required
We may investigate suspected violations and take reasonable steps to protect systems, information, customers, personnel, and third parties.
26. Limitations and No Absolute Security Guarantee
We implement safeguards that we believe are reasonable and appropriate for the nature of our services and the risks involved. However, no system, network, application, device, transmission method, or storage environment can be guaranteed to be completely secure.
Security risks may arise from:
Human error
Sophisticated cyberattacks
Zero-day vulnerabilities
Third-party failures
Cloud or hosting outages
Internet limitations
Customer configuration errors
Compromised credentials
Malware
Physical events
Unforeseen technical or operational circumstances
Accordingly, we do not guarantee that our services will be uninterrupted, error-free, immune from vulnerabilities, or completely protected against unauthorized access.
27. Policy Updates
We may update this Information Security Policy periodically to reflect changes in:
Technology
Services
Security threats
Legal or regulatory requirements
Industry practices
Business operations
Customer or contractual requirements
The updated version will be posted or otherwise communicated through appropriate channels. The “Last Updated” date indicates when the policy was most recently revised.
28. Contact Information
Questions about this Information Security Policy, security practices, vulnerability reports, or suspected security incidents may be directed to: