Legal
Security
Last Updated: May 28, 2026 · Effective Date: June 1, 2026
1. Our Security Commitment
Algorithec is committed to protecting your data and information from unauthorized access, disclosure, alteration, and destruction. We implement industry-standard security measures and continuously improve our security posture.
Our principles:
- Protecting user data as our highest priority
- Regular security audits and testing
- Employee training on security
- Transparency about breaches
- Compliance with security standards
- Continuous improvement mindset
2. Data Encryption
In Transit (Data Moving)
- All connections use HTTPS with TLS 1.2 or higher
- 256-bit encryption minimum
- Secure certificate from a trusted provider
- Automatic HTTPS redirect
- No unencrypted data transmission
- All APIs use HTTPS only — no HTTP endpoints available
- Certificate pinning on mobile apps
- Token-based authentication and rate limiting
At Rest (Data Stored)
- AES-256 encryption for all data at rest
- Encryption keys stored in a secure key vault; separate key per database
- Regular key rotation (annually)
- No plaintext passwords stored
- Encrypted file systems, backups, and archives
- Payment information, government IDs, phone numbers, and addresses encrypted separately
3. Access Controls
Authentication
- Email and strong password required; passwords hashed with bcrypt or scrypt with salt
- Minimum 8 characters; mixed case and numbers recommended
- No password reuse; password change every 90 days recommended
- Multi-Factor Authentication (MFA): TOTP, SMS/Email OTP — optional for users, enabled by default for admin
- Session tokens are secure and random; session timeout after 30 minutes of inactivity
- Sessions invalidated on password change
Authorization
- Role-based access control: Admin, Support, Data Analyst, Finance, Engineer — no cross-role access
- Principle of least privilege — employees have minimum necessary access tied to job function
- Regular access reviews; immediate revocation upon termination
- Limited access to personal data; anonymized data used for analytics
- No production data in development environments
4. Employee & Vendor Security
- Background checks: Criminal background, employment history verification, reference checks, education verification, and credit check for financial roles.
- Confidentiality agreements: All employees sign NDAs covering company and user data. Violations result in termination and potential legal action. The non-disclosure clause survives employment.
- Security training: Security training for all employees, annual refresher training, phishing awareness, data handling procedures, incident response training, and password security training.
- Vendor management: Security questionnaire required; SOC 2 or ISO 27001 certification required; penetration testing performed; regular security audits; contractual security requirements; immediate suspension for breaches.
5. Infrastructure Security
Network Security
- Firewalls (hardware and software), intrusion detection and prevention systems
- DDoS protection, WAF (Web Application Firewall)
- VPN for remote access, network segmentation, isolated test environments
Server & Cloud Security
- Regular OS patching; security updates applied immediately
- Minimal services running; hardened configurations; regular vulnerability scanning
- AWS/Google Cloud used with security best practices, security groups, API authentication, encryption, monitoring, and DDoS protection
Database Security
- Encrypted connections only; authentication required
- SQL injection prevention, data validation
- Principle of least privilege; no production access from development
- Backup encryption and disaster recovery plan
6. Application Security
Development Practices
Secure coding training; mandatory code reviews with peer review before deployment; no hardcoded secrets; dependency scanning; SAST and DAST (Static and Dynamic Application Security Testing).
Vulnerability Management
Regular penetration testing (quarterly), bug bounty program, responsible disclosure process, vulnerability tracking system, and public disclosure after fix.
API Security
Authentication required on all endpoints; rate limiting; input validation; SQL injection, XSS, and CSRF protection; secure headers; API versioning.
Mobile App Security
App signing with certificate; secure storage of tokens; certificate pinning; obfuscation of sensitive code; permission minimization; no unintended data leaks; regular app updates.
7. Monitoring & Logging
- Security logging: All access, changes, and failures logged. Logs retained a minimum of 90 days, encrypted and archived. Centralized log management with tamper detection.
- Real-time monitoring: 24/7 security monitoring with automated alert systems, anomaly detection, suspicious activity flags, and an incident response team on alert.
- Audit trails: User login/logout, data access, data modification, deletion events, and admin actions are all logged. Trails cannot be altered.
8. Incident Response
Security incidents include unauthorized access, data breaches, system compromise, malware infections, DDoS or ransomware attacks, and any suspicious activity.
Our response plan:
- First hour: Isolate affected systems, stop ongoing attacks, preserve evidence, assess severity, activate incident team, begin containment.
- First 24 hours: Complete investigation, determine scope, identify affected users, assess data exposure, begin remediation, prepare notifications.
- 1–7 days: Complete remediation, fix vulnerabilities, restore systems, verify security, send notifications, document lessons learned.
- 1–4 weeks: Complete root cause analysis, implement preventive measures, update security policies, conduct training, report to authorities if required.
9. Data Breach Notification
Notification Timeline
We notify affected individuals within 72 hours maximum of discovery. Earlier notification (within 24 hours) is made when practical. We notify regulators as required by applicable law (DPDP Act for Indian citizens; GDPR supervisory authority for EU residents).
Notification Method
In order of preference: email notification, SMS notification, phone call, in-app notification, mail (if other methods unavailable), or public notice (for mass breach affecting 1,000+ individuals).
Notification Content
Notifications will include: what happened, when it occurred, what data was affected, who was affected, steps to protect yourself, our contact information, remediation steps we are taking, and how to file a complaint.
Your Rights After a Breach
- Know what data was breached and when
- Guidance on how to protect yourself
- Free credit monitoring (24–36 months, if applicable)
- ID theft protection services
- Fraud alerts with credit bureaus
- Phone support for questions
- Right to request data deletion
- Right to file regulatory complaints and pursue legal remedies
10. Security Standards & Assessments
We aim to comply with:
- ISO 27001 (or equivalent)
- SOC 2 Type II
- OWASP Top 10
- PCI DSS (for payment data)
- NIST Cybersecurity Framework
- Indian Standards (IS 15408)
Regular assessments include:
- Annual security audit and annual compliance audit
- Quarterly penetration tests
- Third-party security review
- Bug bounty findings and vendor assessments
11. Your Security Responsibilities
You should:
- Use strong, unique passwords and enable multi-factor authentication
- Keep device software updated
- Use secure WiFi (avoid public networks for sensitive transactions)
- Log out when done; monitor your account for unusual activity
- Report suspicious activity immediately
- Keep your email and contact information secure and up to date
You must not:
- Share your password or login credentials
- Give credentials to support — we will never ask for your password
- Click suspicious links or download from untrusted sources
- Disable security features or ignore security warnings
- Store passwords insecurely
12. Contact for Security Concerns
Unit 101, Oxford Towers, 139/88,
Hal Old Airport RD, H.A.L II Stage,
Bangalore North, Bangalore – 560008,
Karnataka, India
© 2026 ALGORITHEC PRIVATE LIMITED. All Rights Reserved.
Last Updated: May 28, 2026 · Next Review: May 28, 2027