Information Security Policy

PREAMBLE

ZED LEAFIN PRIVATE LIMITED ("Company") is a Non-Banking Financial Company (NBFC) registered with the Reserve Bank of India (RBI). The Company recognizes that Information Technology (IT) and digital channels are integral to its business operations, and that the confidentiality, integrity, and availability of its information systems and data are critical to maintaining customer trust, regulatory compliance, and business continuity.

This Information Security and Cyber Security Policy ('Policy') has been framed in accordance with the RBI's Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, the RBI Circular on 'Information Technology Framework for the NBFC Sector', and other applicable guidelines issued by RBI from time to time. This Policy has been approved by the Board of Directors of the Company ('Board').

OBJECTIVE

The objective of this Policy is to:

  • Establish a comprehensive framework for the governance and management of information security and cyber security risks.

  • Protect the confidentiality, integrity, and availability of the Company's information assets, IT systems, and customer data.

  • Ensure compliance with applicable RBI guidelines and other statutory/regulatory requirements relating to IT and cyber security.

  • Establish mechanisms for identification, assessment, monitoring, and mitigation of cyber security risks.

  • Put in place an effective incident response and cyber crisis management mechanism.

  • Ensure business continuity of critical IT systems and services.

SCOPE AND APPLICABILITY

This Policy applies to all employees, contractors, vendors, service providers, and third parties who have access to the Company's IT systems, networks, applications, and data. It covers all information assets owned, leased, or managed by the Company, including hardware, software, networks, data (in physical and electronic form), and third-party/cloud-hosted systems used in connection with the Company's business.

IT GOVERNANCE STRUCTURE

Board and IT Strategy Committee

The Board shall have the ultimate responsibility and accountability for information security and cyber security. Where applicable based on the Company's scale of operations, an IT Strategy Committee shall be constituted by the Board to review and approve the IT strategy, information security policies, and to oversee IT-related risks, in accordance with RBI's IT Governance guidelines

Chief Information Security Officer (CISO) / IT Officer

The Company shall designate a senior official responsible for information security/cyber security (functioning as, or equivalent to, a Chief Information Security Officer), who shall be responsible for articulating and implementing the information security and cyber security policy of the Company, and reporting periodically to the Board/senior management on the cyber security posture of the Company.

IT Steering Committee

An IT Steering Committee comprising senior management shall be responsible for the implementation of the IT strategy approved by the Board/IT Strategy Committee, monitoring IT project execution, and ensuring alignment of IT initiatives with business objectives.

INFORMATION SECURITY RISK MANAGEMENT

The Company shall carry out periodic Information Security Risk Assessments to identify, assess, and prioritize risks to its information assets, and shall implement appropriate controls to mitigate identified risks to an acceptable level. Risk assessments shall be conducted at least annually, and on the introduction of any new product, technology, or significant change to the Company's IT infrastructure.

ACCESS CONTROL

  • Access to the Company's IT systems, applications, and data shall be granted strictly on a 'need-to-know' and 'least privilege' basis.

  • User access shall be provisioned, modified, and revoked through a documented and approved process, with periodic review of access rights.

  • Privileged/administrative access shall be strictly controlled, logged, and monitored.

  • Multi-factor authentication shall be implemented for access to critical systems, remote access, and customer-facing digital applications, wherever feasible.

  • Access credentials (passwords, tokens, OTPs) shall not be shared and shall be protected in accordance with the Company's password/authentication policy.

DATA SECURITY AND DATA PROTECTION

  • Customer data and other sensitive information shall be classified based on sensitivity and criticality, and handled in accordance with the Company's data classification and handling standards.

  • Sensitive Personal Data and Financial Information shall be encrypted, both in transit and at rest, using industry-standard encryption protocols.

  • Data backups shall be taken periodically and stored securely, including offsite/cloud backups, to ensure recoverability in the event of data loss.

  • The Company shall comply with its Privacy Policy and applicable data protection laws in the collection, storage, processing, and sharing of personal data.

NETWORK AND INFRASTRUCTURE SECURITY

  • The Company shall deploy appropriate perimeter security controls, including firewalls, intrusion detection/prevention systems, and anti-malware solutions, to protect its network infrastructure.

  • Network segmentation shall be implemented to isolate critical systems from general user networks and external-facing systems.

  • Regular vulnerability assessments and penetration testing (VAPT) shall be conducted on critical IT systems and applications, including customer-facing applications, at least annually or as prescribed by RBI.

  • Patch management processes shall be implemented to ensure timely application of security patches and updates to operating systems, applications, and network devices.

APPLICATION AND SOFTWARE SECURITY

All applications, including mobile applications and digital lending platforms used by the Company, shall be developed/procured, tested, and deployed following secure coding practices and shall undergo security testing (including VAPT) prior to deployment and periodically thereafter. Digital Lending Applications (DLAs), where used, shall comply with RBI's guidelines on Digital Lending, including data minimization, storage limitation, and customer consent requirements.

. THIRD PARTY AND VENDOR RISK MANAGEMENT

Where the Company outsources any IT function, cloud hosting, or other services involving access to its information systems or customer data, it shall conduct due diligence on the service provider's security practices, incorporate appropriate security and confidentiality clauses in the outsourcing agreement, and periodically monitor and audit the service provider's compliance with the Company's information security requirements, in accordance with RBI's guidelines on outsourcing of financial services and IT outsourcing.

. CYBER SECURITY INCIDENT RESPONSE

  • The Company shall maintain a documented Incident Response Plan to detect, respond to, contain, and recover from cyber security incidents in a timely manner.

  • All employees and third parties shall be required to report any suspected or actual security incident immediately to the designated Information Security Officer/CISO.

  • The Company shall report unusual cyber security incidents (whether successful or attempted) to the RBI within the timelines prescribed under applicable RBI guidelines, and to other regulatory/law enforcement authorities as required under law, including reporting to the Indian Computer Emergency Response Team (CERT-In) in accordance with applicable directions.

  • A root cause analysis shall be conducted for significant incidents, and corrective/preventive actions shall be implemented and tracked to closure.

CYBER CRISIS MANAGEMENT PLAN

The Company shall put in place a Board-approved Cyber Crisis Management Plan (CCMP) addressing the four aspects of Detection, Response, Recovery, and Containment with respect to cyber threats and incidents. The CCMP shall be periodically tested through cyber drills/simulations and reviewed and updated based on evolving threat landscape and lessons learnt from incidents.

.

BUSINESS CONTINUITY AND DISASTER RECOVERY

The Company shall maintain a Business Continuity Plan (BCP) and Disaster Recovery (DR) plan for its critical IT systems and applications, to ensure continuity of critical business operations and minimize downtime in the event of a disruption, disaster, or cyber incident. The BCP/DR plan shall be tested periodically, and the results of such testing shall be reported to senior management/the Board.

EMPLOYEE AWARENESS AND TRAINING

The Company shall conduct periodic information security and cyber security awareness training for all employees, including training on phishing, social engineering, safe use of email and internet, password hygiene, and reporting of security incidents. New employees shall undergo security awareness training as part of their induction.

AUDIT AND COMPLIANCE

The Company's information security controls and IT systems shall be subject to periodic Information Systems (IS) Audit, conducted by an independent internal or external auditor with requisite expertise, in accordance with RBI's guidelines on IS Audit. The findings of the IS Audit shall be placed before the Audit Committee/Board, and corrective action plans shall be tracked to closure.

REGULATORY REPORTING

The Company shall comply with all applicable reporting requirements prescribed by RBI relating to IT and cyber security, including submission of periodic returns, reporting of cyber incidents, and any other disclosures required under RBI's guidelines on IT Governance and Cyber Security Framework for the NBFC sector.

POLICY REVIEW

This Policy shall be reviewed by the Board or the IT Strategy Committee (as applicable) at least annually, or more frequently as required, to ensure it remains aligned with the evolving cyber threat landscape, technological developments, and applicable RBI guidelines and other regulatory requirements. Any amendments to this Policy shall be approved by the Board.

ZED LEAFIN Pvt.Ltd. prides itself on a perfect understanding of the customer. Each products or service is tailor-made to perfectly suit customer needs. It is this guiding philosophy of putting people first that has brought the company closer to the grassroots, and made it the preferred choice for all the financing requirements among customers.

REFUND & CANCELLATION POLICY

Any additional payment made by You shall be refunded back within 30 days pursuant to the reconciliation of the accounts by Zed Finance. There will be no cancellation of the service once You have received the loan amount in Your bank account.

Contact Details

J-7/12-C Rajouri Garden New Delhi 110027
+91-124-4294325
+91-11-49876929
contactus@zedfinance.com