Back to Home

Information Security & Cyber Security Policy

Brand: StudioMitraEntity: SAFALPAY INDIA PRIVATE LIMITEDEffective Date: 19 September 2026Version: 1.0

Operating Company & Security Office

Legal Name: SAFALPAY INDIA PRIVATE LIMITED

Brand: StudioMitra

CIN: U72900UP2021PTC152896

GSTIN: 09ABGCS9381Q2Z6

Website: www.studiomitra.in

General Support: info.studiomitra@gmail.com

Security & Compliance: compliance@safalpay.com

Incident Helpline: +91 9918784000

Registered & Business Address: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India

Core Information Security Pillars

Defense-in-Depth

Multi-tier virtual private clouds, KMS key management, AES-256 storage encryption, and strict TLS 1.3 transit security.

Least Privilege Access

Zero shared accounts, mandatory multi-factor authentication for administrators, and role-based permissions.

Resilience & Auditing

Continuous log retention (CERT-In 180 days), periodic penetration testing, and rapid incident response protocols.

1. Purpose

This Information Security & Cyber Security Policy establishes the principles, controls, responsibilities and security practices adopted by SAFALPAY INDIA PRIVATE LIMITED under the brand name StudioMitra (“StudioMitra”, “Company”, “we”, “us” or “our”) to protect information, systems, applications, accounts and digital services used to operate the StudioMitra Website and photography studio management software.

The objective of this Policy is to protect the confidentiality, integrity and availability of information and technology resources; reduce the risk of unauthorized access, cyber attacks, fraud, data loss and service disruption; and establish a consistent security framework for employees, contractors, vendors, business users and authorized users.

2. Scope

This Policy applies to StudioMitra's Website, SaaS/software platform, applications, databases, APIs, cloud infrastructure, administrative systems, business systems, user accounts, support systems, development environments, production environments, endpoints, networks and third-party services used to provide StudioMitra services.

It applies to all employees, directors, contractors, consultants, interns, administrators, developers, support personnel, vendors and other persons who are authorized to access Company systems or information.

It also applies to information handled through StudioMitra, including account information, business information, booking records, customer information, event information, invoices, payment-status information, photographs, videos, galleries, technical logs and support communications, subject to the Privacy Policy and applicable law.

3. Company Information

Legal Name: SAFALPAY INDIA PRIVATE LIMITED

Brand: StudioMitra

CIN: U72900UP2021PTC152896

GSTIN: 09ABGCS9381Q2Z6

Registered/Business Address: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India

Website: www.studiomitra.in

General Support: info.studiomitra@gmail.com

Website Registered Email: info.safalpay@gmail.com

Compliance Email: compliance@safalpay.com

Helpline: +91 9918784000

4. Information Security Objectives

  • Protect confidential and personal information against unauthorized access or disclosure.
  • Maintain integrity and accuracy of customer, booking, business and system information.
  • Maintain availability and resilience of critical systems and services.
  • Prevent, detect and respond to cyber security incidents.
  • Reduce the risk of account compromise, data theft, malware, phishing, fraud and unauthorized system access.
  • Ensure security responsibilities are assigned and understood across teams.
  • Promote security awareness among personnel and relevant users.
  • Maintain appropriate records, logs, backups and evidence for security and operational purposes.

5. Security Principles

  • Confidentiality: Information is accessible only to authorized persons and systems.
  • Integrity: Information and systems are protected against unauthorized alteration or destruction.
  • Availability: Critical systems and information are maintained and recoverable when required.
  • Least Privilege: Users receive only the access necessary for their assigned responsibilities.
  • Need-to-Know: Confidential information is shared only where legitimate business or legal need exists.
  • Defense in Depth: Multiple administrative, technical and physical controls are layered where appropriate.
  • Secure by Design: Security considerations are incorporated into product development and system changes.
  • Accountability: Access and security-sensitive actions must be attributable to authorized individual identities.

6. Information Classification

Information is classified according to sensitivity and business impact into four standardized categories:

PublicInformation intended for public disclosure, such as published marketing website content and public studio profiles.
InternalRoutine operational business information that is not intended for public disclosure.
ConfidentialBusiness records, customer directories, shoot schedules, operational data, or technical documents that could cause commercial or reputational harm if improperly disclosed.
Restricted / SensitiveHighly sensitive personal data, authentication tokens, KMS secrets, financial credentials, contract signatures, or incident reports requiring enhanced encryption and isolated access controls.

7. Access Control

  • Access to systems and information must be authorized, documented where appropriate and reviewed periodically.
  • Unique user IDs must be used instead of shared accounts wherever technically feasible.
  • Access should be granted according to role and business need.
  • Privileged or administrative access should be strictly restricted to authorized personnel.
  • Access should be removed or modified promptly when an employee or contractor changes role or leaves the organization.
  • Privileged accounts should be separately controlled from ordinary user accounts where feasible.
  • Access to production systems should be restricted, isolated, and continuously monitored.
  • Periodic access reviews should be performed for critical systems and production consoles.

8. Password and Authentication Security

  • Users must maintain strong, unique passwords for Company and studio accounts.
  • Passwords must not be shared or stored in plaintext or insecure locations.
  • Multi-factor authentication (MFA) must be enabled for privileged, administrative and other sensitive accounts where available.
  • Default passwords and credentials must be changed before systems are placed into operational use.
  • Compromised or suspected credentials must be reset promptly.
  • OTP, PIN, CVV, API secrets, private keys and authentication credentials must not be disclosed to unauthorized persons.

9. Privileged Access Management

Administrative access to servers, databases, cloud consoles, security systems, APIs and other sensitive infrastructure must be strictly limited to authorized personnel using separate privileged credentials, comprehensive audit logging, and periodic access recertification.

10. Data Security

StudioMitra shall apply reasonable safeguards to protect information handled through its systems. Depending on the nature of the information and technical architecture, controls may include access restrictions, encryption, secure storage, secure transmission, logging, backups and monitoring. Sensitive information should not be copied, downloaded, exported or shared unless there is a legitimate business, legal or operational requirement.

11. Personal Data and Privacy

Personal information shall be handled in accordance with StudioMitra's Privacy Policy and applicable data-protection requirements.

Where photography studios or photographers upload customer information, bookings, event details, photographs or videos, the relevant business/user is responsible for having the permissions and lawful basis required for such processing. StudioMitra will process such information according to the applicable service arrangement, instructions and law.

12. Photographs, Videos and Media Security

  • StudioMitra processes photographs, videos, galleries and event-related media as part of its software functionality.
  • Access to media must be restricted according to account permissions and PIN configurations.
  • Users should not share private client gallery links or credentials with unauthorized persons.
  • Media is stored and transmitted using hardened storage architectures and TLS encryption.
  • Users must ensure they possess the necessary rights and permissions to upload or share client media.
  • Suspected unauthorized access, deletion, alteration or disclosure of media must be reported promptly.

13. Network Security

Critical network infrastructure is protected using multi-tier Virtual Private Clouds (VPCs), strict ingress/egress firewall rules, Web Application Firewalls (WAF), and network segmentation. Administrative interfaces are never exposed directly to the public internet. Remote administrative connections require secure authentication and encrypted tunnels.

14. Application Security

StudioMitra software is developed and maintained following OWASP Top 10 standards. Input validation, context-aware output encoding, CSRF protection, secure cookie flags, and parameterized database queries are strictly enforced. Production credentials and API secrets are never committed to source control repositories.

15. API Security

  • APIs must enforce cryptographic authentication and granular token authorization.
  • API credentials, tokens and secrets must be protected and rotated periodically.
  • Rate limiting, throttling and bot mitigation controls are applied to prevent volumetric abuse.
  • API access and anomalous payloads are logged and monitored in real time.
  • Deprecated endpoints are decommissioned and removed according to deprecation schedules.

16. Secure Software Development Lifecycle (SSDLC)

Security requirements are evaluated during feature design. Development, testing, and production environments are strictly isolated. Production databases are never duplicated into development workstations unless anonymized and cryptographically sanitized. Automated static analysis (SAST) is integrated into deployment pipelines.

17. Vulnerability Management

StudioMitra proactively identifies, assesses, and remediates security vulnerabilities affecting applications, infrastructure, dependencies, and container images. High-risk vulnerabilities receive priority SLA remediation.

18. Patch Management

Operating systems, runtime engines, container base images, libraries, and security tools are maintained with the latest security updates. Critical zero-day patches are evaluated and applied on an expedited schedule.

19. Endpoint Security

Company-managed workstations must enforce full-disk encryption, active screen locks, supported operating systems, and managed endpoint detection. Unapproved software or pirated tools are strictly forbidden.

20. Email, Phishing and Social Engineering

Users must independently verify unexpected requests for credentials, OTPs, wire transfers, or remote access software. StudioMitra staff will never solicit confidential passwords or banking OTPs. Suspected phishing emails should be forwarded immediately to our security desk.

21. Malware and Ransomware Protection

Security alerts indicating malicious binaries or anomalous encryption behaviors trigger immediate endpoint isolation. Backups are cryptographically immutablized and air-gapped where feasible to prevent lateral ransomware tampering.

22. Logging and Monitoring

Security and operational logs are collected across infrastructure components including authentication events, administrative actions, security alerts, and anomalous transactions.

In compliance with CERT-In directions, ICT system logs are securely retained for a rolling period of 180 days within Indian jurisdiction.

23. Backup and Recovery

Critical business records and database states are backed up through continuous transaction logging and daily automated snapshots. Backups are encrypted and subjected to periodic restoration drills.

Users should also maintain independent copies of irreplaceable photography assets as outlined in our Data Protection & Backup Policy.

24. Business Continuity and Disaster Recovery

StudioMitra maintains operational continuity arrangements for severe service disruptions, hardware failures, and cloud regional outages. Recovery priorities are structured around data integrity, customer deliverables, and security compliance.

25. Cyber Security Incident Response Framework

Security incidents are handled through our formal incident response protocol:

  1. Identify and log the incident;
  2. Assess severity, impacted assets and data scope;
  3. Execute containment (session revocations, token invalidations, IP bans);
  4. Preserve digital evidence adhering to chain of custody;
  5. Investigate root cause and attack vectors;
  6. Remediate vulnerabilities and sanitize affected systems;
  7. Recover services utilizing trusted configurations;
  8. Notify affected stakeholders and statutory authorities where required; and
  9. Conduct post-incident review and implement corrective controls.

26. Incident Reporting

Employees, contractors, studios, and clients should report any suspected account takeover, credential exposure, data leakage, malicious activity, or unauthorized gallery access immediately.

27. Security Incident Contact Desk

For cybersecurity incidents, suspected fraud, or data breaches, report immediately through our dedicated channels:

Security & Compliance Email:
compliance@safalpay.com

General Support Email:
info.studiomitra@gmail.com

Emergency Incident Helpline:
+91 9918784000

Operating Entity:
SAFALPAY INDIA PRIVATE LIMITED

Please include timestamp, affected account/service, IP addresses, and screenshots. Never include cleartext passwords or banking OTPs.

28. Law-Enforcement Cooperation

Where an incident involves suspected criminal activity, StudioMitra cooperates with competent law enforcement, CERT-In, and judicial authorities in accordance with the Information Technology Act 2000 and applicable Indian statutes.

29. Third-Party / Vendor Security

Third-party technology partners undergo risk-based security due diligence. Agreements mandate confidentiality, data protection, and prompt incident notification obligations. Vendor permissions are reviewed and revoked when no longer necessary.

30. Cloud Security

Cloud infrastructure configurations adhere to CIS benchmarks. Cloud root credentials are isolated with physical hardware keys, privileged IAM roles enforce temporary session tokens, and automated posture analyzers continuously check for misconfigurations.

31. Data Encryption

All data in transit is encrypted using TLS 1.3 with strong cipher suites. Sensitive data at rest (database records, media vaults, backups) is encrypted using AES-256 with rotating Key Management Service (KMS) master keys.

32. Data Retention and Secure Disposal

Data is retained only as long as necessary for operational, contractual, statutory, or security purposes. Retired storage volumes and decommissioned assets are cryptographically sanitized or destroyed in accordance with NIST SP 800-88 guidelines.

33. Physical Security

Physical access to Company facilities, data cabinets, and operational offices is restricted to authorized personnel with controlled visitor escorts and badge verification.

34. Remote Work and Remote Access

Remote engineering access requires authenticated VPN tunnels, endpoint posture validation, session timeouts, and encrypted connections. Unencrypted public Wi-Fi networks must not be used without security safeguards.

35. Mobile Device Security

Mobile devices accessing Company systems must maintain biometric or PIN screen locks, supported OS firmware, and remote wipe capabilities in the event of device theft or loss.

36. Employee Security Awareness

Team members participate in continuous security education, including simulated phishing drills, credential hygiene, social engineering defense, and incident reporting procedures.

37. Acceptable Use

Company systems are provided strictly for legitimate studio business operations. Unauthorized vulnerability scanning, penetration testing without written approval, malware distribution, or accessing other users' accounts is strictly prohibited.

38. User Account Security

Users are responsible for safeguarding login passwords and multi-factor authentication tokens. StudioMitra reserves the right to lock or challenge accounts exhibiting anomalous access velocities.

39. Security of Photography Customer Data

Photography studios must restrict staff access to end-client personal records, wedding shoot coordinates, and hi-res image downloads on a strict need-to-know basis. Private gallery PINs should be shared securely with clients.

40. Payment and Transaction Security

All financial transactions are tokenized and processed via certified PCI-DSS Level 1 compliant payment aggregators. StudioMitra never captures or persists raw card numbers, CVVs, or bank netbanking passwords.

41. Fraud Prevention

Automated risk scoring monitors for repeated payment failures, mismatched billing indicators, card testing patterns, and suspicious credential stuffing attacks.

42. Change Management

Material code and infrastructure changes undergo peer code review, staging validation, automated regression checks, and formal signoff prior to production deployment.

43. Security Testing

StudioMitra conducts regular vulnerability assessments, dependency auditing, and independent third-party penetration testing to identify and remediate potential security risks.

44. Third-Party Software and Open-Source Components

Open-source software libraries are tracked via software bill of materials (SBOM) and monitored continuously against the National Vulnerability Database (NVD).

45. Information Sharing

Confidential information is disclosed only to authorized parties under non-disclosure agreements or lawful statutory orders. Public security disclosures are handled exclusively by authorized Company spokespersons.

46. Incident Evidence and Forensics

Forensic artefacts, memory dumps, access logs, and disk snapshots are preserved with cryptographic hashes to ensure admissibility during legal proceedings or regulatory audits.

47. Security Audit and Review

Internal audits review access entitlements, firewall rules, encryption compliance, and vendor risk profiles at regular intervals.

48. Risk Management

Information security risks are evaluated across likelihood and impact dimensions, documented in our corporate risk register, and managed through mitigation or formal risk acceptance.

49. Policy Violations

Violations of this Policy may result in access suspension, contract termination, or appropriate legal action under applicable Indian civil and criminal laws.

50. Exceptions

Any operational exception to security controls must be documented, risk-assessed, approved in writing by the Compliance Officer, and subjected to a defined expiration window.

51. Policy Governance

The Security & Compliance Team of SAFALPAY INDIA PRIVATE LIMITED oversees this Policy and collaborates with engineering and operations teams to enforce standards.

52. Regulatory and Legal Compliance

StudioMitra adheres to applicable provisions of the Information Technology Act 2000, CERT-In Directions 2022, and the Digital Personal Data Protection (DPDP) Act 2023.

53. Relationship With Other Policies

This Policy should be read alongside the StudioMitra Privacy Policy, Terms & Conditions, Refund & Cancellation Policy, Chargeback & Cyber Fraud Policy, and Data Protection & Backup Policy.

54. Policy Review and Updates

This Policy is reviewed periodically and whenever substantial infrastructure, legal, or threat-landscape modifications occur. Updated versions are published on www.studiomitra.in.

55. Effective Date and Version

Effective Date: 19 September 2026

Version: 1.0

Policy Owner: SAFALPAY INDIA PRIVATE LIMITED / StudioMitra

56. Important Implementation Note

This document establishes the official Information Security & Cyber Security policy framework of StudioMitra, supported by operational procedure documents, incident registers, backup drill records, and vendor due-diligence logs.

57. Contact Details

SAFALPAY INDIA PRIVATE LIMITED

Brand: StudioMitra

D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India

Website: www.studiomitra.in

General Email: info.studiomitra@gmail.com

Website Registered Email: info.safalpay@gmail.com

Compliance / Cyber Security Email: compliance@safalpay.com

Phone: +91 9918784000

© 2026 SAFALPAY INDIA PRIVATE LIMITED. All Rights Reserved.Brand: StudioMitra