Information Security & Cyber Security Policy
Operating Company & Security Office
Legal Name: SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
CIN: U72900UP2021PTC152896
GSTIN: 09ABGCS9381Q2Z6
Website: www.studiomitra.in
General Support: info.studiomitra@gmail.com
Security & Compliance: compliance@safalpay.com
Incident Helpline: +91 9918784000
Registered & Business Address: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Core Information Security Pillars
Multi-tier virtual private clouds, KMS key management, AES-256 storage encryption, and strict TLS 1.3 transit security.
Zero shared accounts, mandatory multi-factor authentication for administrators, and role-based permissions.
Continuous log retention (CERT-In 180 days), periodic penetration testing, and rapid incident response protocols.
1. Purpose
This Information Security & Cyber Security Policy establishes the principles, controls, responsibilities and security practices adopted by SAFALPAY INDIA PRIVATE LIMITED under the brand name StudioMitra (“StudioMitra”, “Company”, “we”, “us” or “our”) to protect information, systems, applications, accounts and digital services used to operate the StudioMitra Website and photography studio management software.
The objective of this Policy is to protect the confidentiality, integrity and availability of information and technology resources; reduce the risk of unauthorized access, cyber attacks, fraud, data loss and service disruption; and establish a consistent security framework for employees, contractors, vendors, business users and authorized users.
2. Scope
This Policy applies to StudioMitra's Website, SaaS/software platform, applications, databases, APIs, cloud infrastructure, administrative systems, business systems, user accounts, support systems, development environments, production environments, endpoints, networks and third-party services used to provide StudioMitra services.
It applies to all employees, directors, contractors, consultants, interns, administrators, developers, support personnel, vendors and other persons who are authorized to access Company systems or information.
It also applies to information handled through StudioMitra, including account information, business information, booking records, customer information, event information, invoices, payment-status information, photographs, videos, galleries, technical logs and support communications, subject to the Privacy Policy and applicable law.
3. Company Information
Legal Name: SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
CIN: U72900UP2021PTC152896
GSTIN: 09ABGCS9381Q2Z6
Registered/Business Address: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Website: www.studiomitra.in
General Support: info.studiomitra@gmail.com
Website Registered Email: info.safalpay@gmail.com
Compliance Email: compliance@safalpay.com
Helpline: +91 9918784000
4. Information Security Objectives
- Protect confidential and personal information against unauthorized access or disclosure.
- Maintain integrity and accuracy of customer, booking, business and system information.
- Maintain availability and resilience of critical systems and services.
- Prevent, detect and respond to cyber security incidents.
- Reduce the risk of account compromise, data theft, malware, phishing, fraud and unauthorized system access.
- Ensure security responsibilities are assigned and understood across teams.
- Promote security awareness among personnel and relevant users.
- Maintain appropriate records, logs, backups and evidence for security and operational purposes.
5. Security Principles
- Confidentiality: Information is accessible only to authorized persons and systems.
- Integrity: Information and systems are protected against unauthorized alteration or destruction.
- Availability: Critical systems and information are maintained and recoverable when required.
- Least Privilege: Users receive only the access necessary for their assigned responsibilities.
- Need-to-Know: Confidential information is shared only where legitimate business or legal need exists.
- Defense in Depth: Multiple administrative, technical and physical controls are layered where appropriate.
- Secure by Design: Security considerations are incorporated into product development and system changes.
- Accountability: Access and security-sensitive actions must be attributable to authorized individual identities.
6. Information Classification
Information is classified according to sensitivity and business impact into four standardized categories:
7. Access Control
- Access to systems and information must be authorized, documented where appropriate and reviewed periodically.
- Unique user IDs must be used instead of shared accounts wherever technically feasible.
- Access should be granted according to role and business need.
- Privileged or administrative access should be strictly restricted to authorized personnel.
- Access should be removed or modified promptly when an employee or contractor changes role or leaves the organization.
- Privileged accounts should be separately controlled from ordinary user accounts where feasible.
- Access to production systems should be restricted, isolated, and continuously monitored.
- Periodic access reviews should be performed for critical systems and production consoles.
8. Password and Authentication Security
- Users must maintain strong, unique passwords for Company and studio accounts.
- Passwords must not be shared or stored in plaintext or insecure locations.
- Multi-factor authentication (MFA) must be enabled for privileged, administrative and other sensitive accounts where available.
- Default passwords and credentials must be changed before systems are placed into operational use.
- Compromised or suspected credentials must be reset promptly.
- OTP, PIN, CVV, API secrets, private keys and authentication credentials must not be disclosed to unauthorized persons.
9. Privileged Access Management
Administrative access to servers, databases, cloud consoles, security systems, APIs and other sensitive infrastructure must be strictly limited to authorized personnel using separate privileged credentials, comprehensive audit logging, and periodic access recertification.
10. Data Security
StudioMitra shall apply reasonable safeguards to protect information handled through its systems. Depending on the nature of the information and technical architecture, controls may include access restrictions, encryption, secure storage, secure transmission, logging, backups and monitoring. Sensitive information should not be copied, downloaded, exported or shared unless there is a legitimate business, legal or operational requirement.
11. Personal Data and Privacy
Personal information shall be handled in accordance with StudioMitra's Privacy Policy and applicable data-protection requirements.
Where photography studios or photographers upload customer information, bookings, event details, photographs or videos, the relevant business/user is responsible for having the permissions and lawful basis required for such processing. StudioMitra will process such information according to the applicable service arrangement, instructions and law.
12. Photographs, Videos and Media Security
- StudioMitra processes photographs, videos, galleries and event-related media as part of its software functionality.
- Access to media must be restricted according to account permissions and PIN configurations.
- Users should not share private client gallery links or credentials with unauthorized persons.
- Media is stored and transmitted using hardened storage architectures and TLS encryption.
- Users must ensure they possess the necessary rights and permissions to upload or share client media.
- Suspected unauthorized access, deletion, alteration or disclosure of media must be reported promptly.
13. Network Security
Critical network infrastructure is protected using multi-tier Virtual Private Clouds (VPCs), strict ingress/egress firewall rules, Web Application Firewalls (WAF), and network segmentation. Administrative interfaces are never exposed directly to the public internet. Remote administrative connections require secure authentication and encrypted tunnels.
14. Application Security
StudioMitra software is developed and maintained following OWASP Top 10 standards. Input validation, context-aware output encoding, CSRF protection, secure cookie flags, and parameterized database queries are strictly enforced. Production credentials and API secrets are never committed to source control repositories.
15. API Security
- APIs must enforce cryptographic authentication and granular token authorization.
- API credentials, tokens and secrets must be protected and rotated periodically.
- Rate limiting, throttling and bot mitigation controls are applied to prevent volumetric abuse.
- API access and anomalous payloads are logged and monitored in real time.
- Deprecated endpoints are decommissioned and removed according to deprecation schedules.
16. Secure Software Development Lifecycle (SSDLC)
Security requirements are evaluated during feature design. Development, testing, and production environments are strictly isolated. Production databases are never duplicated into development workstations unless anonymized and cryptographically sanitized. Automated static analysis (SAST) is integrated into deployment pipelines.
17. Vulnerability Management
StudioMitra proactively identifies, assesses, and remediates security vulnerabilities affecting applications, infrastructure, dependencies, and container images. High-risk vulnerabilities receive priority SLA remediation.
18. Patch Management
Operating systems, runtime engines, container base images, libraries, and security tools are maintained with the latest security updates. Critical zero-day patches are evaluated and applied on an expedited schedule.
19. Endpoint Security
Company-managed workstations must enforce full-disk encryption, active screen locks, supported operating systems, and managed endpoint detection. Unapproved software or pirated tools are strictly forbidden.
20. Email, Phishing and Social Engineering
Users must independently verify unexpected requests for credentials, OTPs, wire transfers, or remote access software. StudioMitra staff will never solicit confidential passwords or banking OTPs. Suspected phishing emails should be forwarded immediately to our security desk.
21. Malware and Ransomware Protection
Security alerts indicating malicious binaries or anomalous encryption behaviors trigger immediate endpoint isolation. Backups are cryptographically immutablized and air-gapped where feasible to prevent lateral ransomware tampering.
22. Logging and Monitoring
Security and operational logs are collected across infrastructure components including authentication events, administrative actions, security alerts, and anomalous transactions.
In compliance with CERT-In directions, ICT system logs are securely retained for a rolling period of 180 days within Indian jurisdiction.
23. Backup and Recovery
Critical business records and database states are backed up through continuous transaction logging and daily automated snapshots. Backups are encrypted and subjected to periodic restoration drills.
Users should also maintain independent copies of irreplaceable photography assets as outlined in our Data Protection & Backup Policy.
24. Business Continuity and Disaster Recovery
StudioMitra maintains operational continuity arrangements for severe service disruptions, hardware failures, and cloud regional outages. Recovery priorities are structured around data integrity, customer deliverables, and security compliance.
25. Cyber Security Incident Response Framework
Security incidents are handled through our formal incident response protocol:
- Identify and log the incident;
- Assess severity, impacted assets and data scope;
- Execute containment (session revocations, token invalidations, IP bans);
- Preserve digital evidence adhering to chain of custody;
- Investigate root cause and attack vectors;
- Remediate vulnerabilities and sanitize affected systems;
- Recover services utilizing trusted configurations;
- Notify affected stakeholders and statutory authorities where required; and
- Conduct post-incident review and implement corrective controls.
26. Incident Reporting
Employees, contractors, studios, and clients should report any suspected account takeover, credential exposure, data leakage, malicious activity, or unauthorized gallery access immediately.
27. Security Incident Contact Desk
For cybersecurity incidents, suspected fraud, or data breaches, report immediately through our dedicated channels:
Security & Compliance Email:
compliance@safalpay.com
General Support Email:
info.studiomitra@gmail.com
Emergency Incident Helpline:
+91 9918784000
Operating Entity:
SAFALPAY INDIA PRIVATE LIMITED
Please include timestamp, affected account/service, IP addresses, and screenshots. Never include cleartext passwords or banking OTPs.
28. Law-Enforcement Cooperation
Where an incident involves suspected criminal activity, StudioMitra cooperates with competent law enforcement, CERT-In, and judicial authorities in accordance with the Information Technology Act 2000 and applicable Indian statutes.
29. Third-Party / Vendor Security
Third-party technology partners undergo risk-based security due diligence. Agreements mandate confidentiality, data protection, and prompt incident notification obligations. Vendor permissions are reviewed and revoked when no longer necessary.
30. Cloud Security
Cloud infrastructure configurations adhere to CIS benchmarks. Cloud root credentials are isolated with physical hardware keys, privileged IAM roles enforce temporary session tokens, and automated posture analyzers continuously check for misconfigurations.
31. Data Encryption
All data in transit is encrypted using TLS 1.3 with strong cipher suites. Sensitive data at rest (database records, media vaults, backups) is encrypted using AES-256 with rotating Key Management Service (KMS) master keys.
32. Data Retention and Secure Disposal
Data is retained only as long as necessary for operational, contractual, statutory, or security purposes. Retired storage volumes and decommissioned assets are cryptographically sanitized or destroyed in accordance with NIST SP 800-88 guidelines.
33. Physical Security
Physical access to Company facilities, data cabinets, and operational offices is restricted to authorized personnel with controlled visitor escorts and badge verification.
34. Remote Work and Remote Access
Remote engineering access requires authenticated VPN tunnels, endpoint posture validation, session timeouts, and encrypted connections. Unencrypted public Wi-Fi networks must not be used without security safeguards.
35. Mobile Device Security
Mobile devices accessing Company systems must maintain biometric or PIN screen locks, supported OS firmware, and remote wipe capabilities in the event of device theft or loss.
36. Employee Security Awareness
Team members participate in continuous security education, including simulated phishing drills, credential hygiene, social engineering defense, and incident reporting procedures.
37. Acceptable Use
Company systems are provided strictly for legitimate studio business operations. Unauthorized vulnerability scanning, penetration testing without written approval, malware distribution, or accessing other users' accounts is strictly prohibited.
38. User Account Security
Users are responsible for safeguarding login passwords and multi-factor authentication tokens. StudioMitra reserves the right to lock or challenge accounts exhibiting anomalous access velocities.
39. Security of Photography Customer Data
Photography studios must restrict staff access to end-client personal records, wedding shoot coordinates, and hi-res image downloads on a strict need-to-know basis. Private gallery PINs should be shared securely with clients.
40. Payment and Transaction Security
All financial transactions are tokenized and processed via certified PCI-DSS Level 1 compliant payment aggregators. StudioMitra never captures or persists raw card numbers, CVVs, or bank netbanking passwords.
41. Fraud Prevention
Automated risk scoring monitors for repeated payment failures, mismatched billing indicators, card testing patterns, and suspicious credential stuffing attacks.
42. Change Management
Material code and infrastructure changes undergo peer code review, staging validation, automated regression checks, and formal signoff prior to production deployment.
43. Security Testing
StudioMitra conducts regular vulnerability assessments, dependency auditing, and independent third-party penetration testing to identify and remediate potential security risks.
44. Third-Party Software and Open-Source Components
Open-source software libraries are tracked via software bill of materials (SBOM) and monitored continuously against the National Vulnerability Database (NVD).
45. Information Sharing
Confidential information is disclosed only to authorized parties under non-disclosure agreements or lawful statutory orders. Public security disclosures are handled exclusively by authorized Company spokespersons.
46. Incident Evidence and Forensics
Forensic artefacts, memory dumps, access logs, and disk snapshots are preserved with cryptographic hashes to ensure admissibility during legal proceedings or regulatory audits.
47. Security Audit and Review
Internal audits review access entitlements, firewall rules, encryption compliance, and vendor risk profiles at regular intervals.
48. Risk Management
Information security risks are evaluated across likelihood and impact dimensions, documented in our corporate risk register, and managed through mitigation or formal risk acceptance.
49. Policy Violations
Violations of this Policy may result in access suspension, contract termination, or appropriate legal action under applicable Indian civil and criminal laws.
50. Exceptions
Any operational exception to security controls must be documented, risk-assessed, approved in writing by the Compliance Officer, and subjected to a defined expiration window.
51. Policy Governance
The Security & Compliance Team of SAFALPAY INDIA PRIVATE LIMITED oversees this Policy and collaborates with engineering and operations teams to enforce standards.
52. Regulatory and Legal Compliance
StudioMitra adheres to applicable provisions of the Information Technology Act 2000, CERT-In Directions 2022, and the Digital Personal Data Protection (DPDP) Act 2023.
53. Relationship With Other Policies
This Policy should be read alongside the StudioMitra Privacy Policy, Terms & Conditions, Refund & Cancellation Policy, Chargeback & Cyber Fraud Policy, and Data Protection & Backup Policy.
54. Policy Review and Updates
This Policy is reviewed periodically and whenever substantial infrastructure, legal, or threat-landscape modifications occur. Updated versions are published on www.studiomitra.in.
55. Effective Date and Version
Effective Date: 19 September 2026
Version: 1.0
Policy Owner: SAFALPAY INDIA PRIVATE LIMITED / StudioMitra
56. Important Implementation Note
This document establishes the official Information Security & Cyber Security policy framework of StudioMitra, supported by operational procedure documents, incident registers, backup drill records, and vendor due-diligence logs.
57. Contact Details
SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Website: www.studiomitra.in
General Email: info.studiomitra@gmail.com
Website Registered Email: info.safalpay@gmail.com
Compliance / Cyber Security Email: compliance@safalpay.com
Phone: +91 9918784000