RanaPay

RANAPAY INDIA PRIVATE LIMITED

INFORMATION SECURITY & CYBER SECURITY POLICY

POLICY NO. 12 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerInformation Security / Technology / Compliance
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the information-security and cyber-security governance framework for protecting RanaPay's systems, applications, APIs, customer information, transaction data, business records and technology services against unauthorised access, misuse, alteration, disclosure, disruption and other security threats.

2. OBJECTIVES

  • Protect confidentiality, integrity and availability of information.
  • Reduce cyber and information-security risk.
  • Maintain secure systems and applications.
  • Protect customer and transaction information.
  • Support secure partner integrations.
  • Detect and respond to security incidents.
  • Meet applicable legal, contractual and regulatory requirements.

3. SCOPE

This Policy applies to employees, contractors, consultants, systems, applications, APIs, cloud services, endpoints, networks, databases, third-party services and other technology resources used for RanaPay business activities.

4. INFORMATION SECURITY PRINCIPLES

  • Need-to-know access
  • Least privilege
  • Secure-by-design
  • Defence in depth
  • Data minimisation
  • Accountability and logging
  • Regular review and improvement

5. INFORMATION CLASSIFICATION

  • Public
  • Internal
  • Confidential
  • Restricted / Sensitive

Information shall be classified according to business impact, sensitivity, legal requirements and risk. Access and handling controls shall reflect the classification.

6. ASSET MANAGEMENT

Technology and information assets shall be identified and maintained in an appropriate inventory. Ownership and responsibility shall be assigned for critical systems and data.

7. ACCESS CONTROL

Access shall be granted based on business need and least privilege. User access shall be approved, periodically reviewed and revoked when no longer required.

8. AUTHENTICATION

  • Strong passwords where passwords are used
  • Multi-factor authentication for appropriate privileged or sensitive access
  • Secure credential storage
  • No credential sharing
  • Prompt revocation of compromised credentials

9. PRIVILEGED ACCESS

Administrative and privileged access shall be restricted, separately controlled where practicable, logged and periodically reviewed.

10. ENDPOINT & DEVICE SECURITY

  • Approved devices and software
  • Security updates
  • Malware protection where appropriate
  • Screen/device protection
  • Restricted removable media
  • Secure disposal

11. NETWORK SECURITY

Networks and infrastructure shall use appropriate segmentation, firewalls, secure configurations, encryption and monitoring based on risk.

12. APPLICATION SECURITY

  • Secure development practices
  • Code review where appropriate
  • Vulnerability assessment/testing
  • Input validation
  • Secure error handling
  • Dependency management
  • Production access restriction

13. API SECURITY

APIs shall use appropriate authentication, authorisation, encryption, rate limiting, input validation, logging and monitoring. API credentials shall be protected and rotated according to risk.

14. DATA SECURITY

Confidential and sensitive information shall be protected against unauthorised access, disclosure, alteration and destruction using appropriate technical and organisational controls.

15. ENCRYPTION

Encryption shall be used for sensitive information in transit and, where appropriate based on risk and system design, at rest. Cryptographic keys shall be protected and access restricted.

16. LOGGING & MONITORING

  • Authentication events
  • Privileged activity
  • Transaction/API activity where relevant
  • Security alerts
  • System errors
  • Administrative changes

Logs shall be protected against unauthorised modification and retained according to applicable requirements.

17. VULNERABILITY MANAGEMENT

  1. Identify vulnerabilities.
  2. Assess severity and business impact.
  3. Prioritise remediation.
  4. Apply patches or compensating controls.
  5. Validate remediation.
  6. Record closure.

18. PATCH & CHANGE MANAGEMENT

Security and system changes shall be tested and approved through appropriate change-management procedures. Emergency changes shall be documented and reviewed after implementation.

19. BACKUP & RECOVERY

Critical information and systems shall have appropriate backup and recovery arrangements consistent with the Business Continuity & Disaster Recovery Policy.

20. CYBER INCIDENT MANAGEMENT

Suspected cyber incidents shall be reported and managed under the Cyber Incident Response & Cyber Fraud Policy. Evidence shall be preserved and relevant stakeholders escalated according to severity.

21. PHISHING & SOCIAL ENGINEERING

Personnel shall receive awareness guidance regarding phishing, malicious links, impersonation, credential theft, OTP scams and other social-engineering risks.

22. THIRD-PARTY SECURITY

Third parties with access to RanaPay systems or information shall be subject to appropriate due diligence, contractual security requirements, access controls and monitoring under the Third-Party / Vendor Risk Management Policy.

23. CLOUD & HOSTING SECURITY

Cloud and hosting environments shall be configured according to security requirements, with appropriate identity controls, network restrictions, logging, backups and vulnerability management.

24. REMOTE ACCESS

Remote access to business systems shall use approved secure mechanisms and appropriate authentication. Access shall be restricted based on business need.

25. SECURE DISPOSAL

Devices, media and information shall be securely disposed of or sanitised when no longer required, taking account of information sensitivity and applicable retention obligations.

26. EMPLOYEE / USER RESPONSIBILITIES

  • Protect credentials
  • Use approved systems
  • Report suspicious activity
  • Do not install unauthorised software
  • Follow access and data-handling procedures
  • Complete required security training

27. SECURITY AWARENESS & TRAINING

Relevant personnel shall receive periodic information-security and cyber-security awareness training appropriate to their role.

28. SECURITY TESTING

RanaPay may conduct vulnerability assessments, security reviews, configuration reviews, penetration testing or other testing appropriate to the risk and criticality of systems.

29. INCIDENT REPORTING

Security concerns shall be reported promptly through designated internal channels. Personnel shall not conceal suspected security incidents.

30. DATA PROTECTION

Personal and customer data shall be processed and retained according to applicable requirements and RanaPay's Data Protection, Privacy & Retention Policy.

31. BUSINESS CONTINUITY

Critical technology services shall have continuity and recovery arrangements proportionate to their business impact and shall be covered by the Business Continuity & Disaster Recovery Policy.

32. AUDIT & COMPLIANCE

Security controls may be reviewed through internal assessments, partner audits, external assessments or other assurance activities. Identified deficiencies shall be tracked to remediation.

33. EXCEPTIONS

Security exceptions shall be documented, risk-assessed, time-bound where appropriate and approved by an authorised person. Exceptions shall not be used to bypass mandatory legal or contractual requirements.

34. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Technology / ITInfrastructure, systems and security controlsTechnology Head
Information SecuritySecurity governance, monitoring and testingManagement
CompliancePolicy oversight and regulatory/partner requirementsManagement
OperationsBusiness-process controls and incident coordinationOperations Head
HR / AdministrationJoiner-mover-leaver and awareness coordinationManagement
Third-Party ManagementVendor security requirements and monitoringCompliance / Management
All UsersFollow security requirements and report incidentsManager / Security

35. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in technology, cyber risk, business operations, partner requirements or applicable law.

36. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByInformation Security / Technology / Compliance
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

RANAPAY INDIA PRIVATE LIMITED