Information Security Policy
Effective Date: 24 July 2026
1. Introduction
This Information Security Policy sets out how PROCEKA TechSol Private Limited (“PROCEKA”, “we”, “us”) governs the security of information relating to our clients, our business, and our Website. This is a governance policy describing our principles and commitments, not a technical implementation manual, and it should be read alongside our Privacy Policy, AI Usage & Responsible AI Policy, Service Engagement Terms & Conditions, and Data Retention Policy.
2. Purpose
The purpose of this Policy is to establish clear governance principles for protecting the confidentiality, integrity, and availability of information at PROCEKA, and to communicate our approach to information security to clients, professionals, and other stakeholders.
3. Scope
This Policy applies to information handled by PROCEKA in connection with the Website, client engagements, and internal operations, and to any future digital services, including a client portal, professional portal, marketplace, AI assistant, SaaS platform, document management system, or mobile application.
4. Definitions
“Information Security” means the protection of information from unauthorised access, use, disclosure, disruption, modification, or destruction. “Confidentiality” means ensuring information is accessible only to those authorised to access it. “Integrity” means safeguarding the accuracy and completeness of information. “Availability” means ensuring authorised users can access information when needed.
5. Information Security Objectives
PROCEKA aims to: protect the confidentiality of client and business information; maintain the integrity of information throughout its lifecycle; support reasonable availability of systems and information for legitimate business purposes; minimise cyber security risks through reasonable, proportionate controls; and continuously improve our security posture as our business and the threat landscape evolve. No organisation can guarantee complete protection against all cyber threats, and PROCEKA does not claim otherwise.
6. Governance Structure
Responsibility for information security governance at PROCEKA rests with company management, who oversee the principles set out in this Policy and their practical application across the organisation, escalating significant security matters for management decision as appropriate.
7. Roles & Responsibilities
All PROCEKA personnel are responsible for following this Policy and applicable security practices in their day-to-day work. Management is responsible for ensuring this Policy remains current and for allocating reasonable resources to information security. Personnel handling particularly sensitive client information bear a heightened responsibility for care in handling it.
8. Information Classification
PROCEKA treats information according to its sensitivity: general business information intended for public use (such as Website content); internal information not intended for public disclosure; and confidential information, including client data and sensitive business or financial information, which receives the highest level of protection.
9. Confidential Information
Confidential information, including client financial, tax, and compliance data, is handled with particular care, accessed only by personnel who need it for the relevant engagement, and protected in accordance with the confidentiality obligations described in our Service Engagement Terms & Conditions.
10. Client Information
Client information is collected, used, and protected in accordance with our Privacy Policy and Service Engagement Terms & Conditions, and access is limited to personnel involved in delivering the relevant service.
11. Personal Information
Personal information, whether relating to clients, prospective clients, or Website visitors, is handled in accordance with our Privacy Policy and applicable data protection law, including the Digital Personal Data Protection Act, 2023.
12. Business Information
PROCEKA’s own internal business information, including financial records, strategic plans, and internal communications, is protected using access controls proportionate to its sensitivity, consistent with the principles in this Policy.
13. Physical Security
Where PROCEKA maintains physical premises or records, reasonable physical security measures are applied, appropriate to the nature of the premises and the sensitivity of information stored there.
14. Digital Security
PROCEKA applies reasonable technical measures to protect its digital systems, including the Website, which operates over an encrypted (HTTPS) connection, and uses security tools such as Wordfence to help protect against unauthorised access and malicious activity.
15. Password Management
Where systems require passwords, personnel are expected to use reasonably strong, unique passwords and to avoid sharing credentials. If client-facing Accounts are introduced in future, users will be expected to follow equivalent practices, as described in our Acceptable Use Policy.
16. Authentication
Access to systems containing confidential or client information is restricted to authenticated, authorised personnel. As PROCEKA introduces additional digital systems in future, we will apply authentication controls appropriate to the sensitivity of the information involved.
17. Access Control
Access to client and confidential information is granted based on legitimate business need, and is reviewed periodically to help ensure access remains appropriate as roles and engagements change.
18. Least Privilege Principle
We aim to grant personnel and systems the minimum level of access necessary to perform their function, rather than broad access by default, reducing the potential impact of any single compromised account or system.
19. Device Security
Personnel accessing client or confidential information are expected to use devices with reasonable security measures in place, such as up-to-date software and screen locking, and to exercise particular care when accessing such information on portable devices.
20. Email Security
Email communications, including those sent through our Fluent SMTP-based mail delivery, are handled with reasonable care. Personnel and clients are encouraged to avoid transmitting highly sensitive information via standard email where a more secure channel has been made available, consistent with our Privacy Policy.
21. Cloud Services
Where PROCEKA uses cloud-based services, including Website hosting, we select providers with reasonable care, considering their security practices and reputation, while recognising that cloud service security is shared between PROCEKA and the provider in accordance with the provider’s own model.
22. Backup Strategy
The Website is backed up using UpdraftPlus to support recovery in the event of data loss or a technical incident. Backup practices are reviewed periodically to help ensure they remain adequate as the Website evolves.
23. Data Encryption
The Website operates over an encrypted (HTTPS) connection. Where reasonably practicable, particularly sensitive information is protected using appropriate encryption or equivalent safeguards, both in transit and, where applicable, at rest.
24. Secure Communications
We aim to use secure channels for communicating sensitive information, and will confirm an appropriate secure method with you directly where a specific engagement requires it, rather than relying solely on standard, unencrypted channels.
25. Secure Development
Changes to the Website are made with reasonable care for security, including keeping the WordPress platform, theme, and plugins reasonably current, and applying available security patches within a reasonable time of their release.
26. AI Security Considerations
Where AI tools are used, as described in our AI Usage & Responsible AI Policy, we consider security risks specific to AI systems, including prompt injection, data leakage, and third-party AI provider practices, before adoption for use involving confidential information.
27. Third-Party Service Providers
PROCEKA engages third-party service providers, including for hosting, payment processing (PayU), email delivery, and website security, and expects these providers to maintain reasonable security practices appropriate to the service they provide.
28. Vendor Risk Management
Before engaging a significant third-party service provider that will handle client or confidential information, we consider the provider’s reputation, security practices, and terms of service, to the extent reasonably available to us as a business of our size.
29. Security Awareness
PROCEKA personnel are expected to remain alert to common security risks, including phishing, social engineering, and suspicious communications, and to report anything unusual promptly rather than act on it.
30. Incident Reporting
Suspected security incidents, whether identified by personnel, clients, or external parties, should be reported promptly using the contact details in Section 39, so that we can investigate and respond appropriately.
31. Security Incident Response
In the event of a suspected or confirmed security incident, PROCEKA will take reasonable steps to investigate, contain, and address the incident, and will notify affected individuals and relevant regulatory authorities where required under applicable law, including the Digital Personal Data Protection Act, 2023, consistent with Section 36 of our Privacy Policy.
32. Business Continuity
We aim to maintain the ability to continue essential business operations in the event of a disruption, including through practices such as regular Website backups and, as our business grows, more formal business continuity planning proportionate to our scale.
33. Disaster Recovery
In the event of a significant technical failure or data loss affecting the Website, we would work to restore service using available backups and, where necessary, our hosting provider’s recovery capabilities, within a reasonable time given the circumstances.
34. Logging & Monitoring
We use reasonable monitoring tools, including our website security plugin, to help detect suspicious activity affecting the Website, and review such information as part of maintaining ongoing security.
35. Audit & Review
We periodically review our information security practices to confirm they remain appropriate for our current business and the information we handle, and to identify areas for improvement.
36. Continuous Improvement
Information security at PROCEKA is treated as an ongoing responsibility rather than a fixed state. We expect our practices to evolve as our services, technology, and the broader threat landscape change over time.
37. Policy Exceptions
Any exception to this Policy must be approved by company management and documented, with a reasonable justification and, where practicable, compensating measures to manage the associated risk.
38. Policy Review
This Policy is reviewed periodically and updated as necessary to reflect changes in our business, technology, and applicable law. The “Effective Date” below indicates when this Policy was last revised.
39. Contact Information
PROCEKA TechSol Private Limited
Rajabandha, Ghatgaon, Keonjhar, Odisha, India
Email: info@proceka.com
Phone: +91 91785 66135
40. Effective Date
This Information Security Policy is effective as of 24 July 2026.