FinOrbit Finance Private Limited (“FinOrbit”, “Company”, “we”, “us”, or “our”) is committed to maintaining the security, confidentiality, integrity, and availability of its applications, websites, digital platforms, APIs, databases, and supporting technology infrastructure.
This Application Security Policy describes the security principles and practices adopted by FinOrbit to protect its applications and the information processed through them.
The purpose of this Policy is to establish security controls and practices designed to:
Support compliance with applicable laws, regulations, contractual requirements, and industry security practices.
This Policy applies to applications, websites, APIs, databases, cloud infrastructure, development environments, production systems, administrative panels, and other technology components operated or managed by FinOrbit.
It applies to:
FinOrbit follows security principles including:
Security controls may be implemented according to the nature, sensitivity, risk, and criticality of the relevant application or service.
FinOrbit implements appropriate authentication and access controls to prevent unauthorised access.
Depending on the application, security controls may include:
Users are responsible for protecting their passwords, OTPs, authentication credentials, API credentials, and other security information.
Credentials must not be shared with unauthorised persons.
Access to administrative panels, production systems, databases, cloud infrastructure, and other privileged systems is restricted to authorised personnel.
Administrative access is granted based on job responsibilities and business requirements.
Where appropriate, FinOrbit may use:
When an individual's role changes or access is no longer required, access may be modified or revoked.
FinOrbit takes reasonable measures to protect personal, financial, authentication, application, and other sensitive information processed through its systems.
Security measures may include:
Sensitive information should not be stored in application logs, source code, URLs, screenshots, or other locations where unnecessary exposure may occur.
Where FinOrbit provides or consumes APIs, reasonable security controls may be implemented, including:
API credentials, secret keys, client secrets, tokens, and similar authentication information must be treated as confidential.
Production credentials must not be unnecessarily exposed in frontend code, public repositories, client-side applications, browser URLs, or publicly accessible files.
FinOrbit aims to incorporate security throughout the software development lifecycle.
Development practices may include:
Security vulnerabilities identified during development or testing should be assessed and addressed according to their severity and risk.
Applications should validate user and system inputs before processing them.
Reasonable measures may be implemented to protect against common application-security risks, including:
Passwords and authentication credentials must be protected using appropriate security mechanisms.
FinOrbit will not intentionally store user passwords in plain text.
Where passwords are used, appropriate cryptographic hashing and secure credential-management practices should be implemented.
API keys, database credentials, cloud credentials, signing keys, and other secrets should be stored using appropriate secret-management mechanisms and should not be hard-coded into publicly accessible source code.
Applications may use secure session-management controls including:
Security-relevant activities may be logged and monitored to support:
Sensitive information such as passwords, authentication secrets, full payment credentials, or other confidential information should not be unnecessarily recorded in logs.
FinOrbit may conduct security assessments and vulnerability management activities appropriate to the risk profile of its applications.
These activities may include:
Identified vulnerabilities may be prioritised according to severity, exploitability, business impact, and other relevant risk factors.
Critical or high-risk vulnerabilities should receive appropriate priority for remediation.
FinOrbit may use third-party technology providers, cloud providers, payment providers, communication providers, KYC providers, analytics services, lenders, financial institutions, and other service providers.
Where appropriate, third-party services may be assessed based on:
Third-party access should be limited to the information and systems reasonably required for the relevant service.
Where technically and operationally appropriate, FinOrbit may maintain separate environments for:
Where production data must be used for testing or troubleshooting, appropriate safeguards should be applied.
FinOrbit may maintain appropriate backup and recovery mechanisms for critical systems and information.
Backups may be protected through:
Business-critical systems may have documented recovery procedures appropriate to their importance and risk.
FinOrbit maintains processes for identifying, assessing, responding to, and recovering from security incidents.
Security incidents may include:
Where an incident is identified, FinOrbit may take appropriate steps including:
Making notifications to affected parties or authorities where required by applicable law or regulation.
Personnel with access to FinOrbit systems may be provided appropriate security guidance or training relating to:
Systems and applications should be configured using reasonable security practices.
Where appropriate, FinOrbit may implement:
Operating systems, frameworks, libraries, databases, applications, and other technology components may be reviewed and updated based on security risk and operational requirements.
Security patches addressing significant vulnerabilities should be prioritised according to their severity and potential impact.
Unsupported or obsolete technologies should be reviewed and replaced where reasonably necessary.
Users also have an important role in maintaining security.
Customers and authorised users should:
FinOrbit will not ask users to disclose passwords or confidential authentication credentials through unsolicited communications.
If you discover a potential security vulnerability affecting a FinOrbit website, application, API, or service, you are encouraged to report it responsibly.
Security reports should contain sufficient information to help us understand and reproduce the issue, including where possible:
Security issues should be reported to:
Please do not publicly disclose a vulnerability before FinOrbit has had a reasonable opportunity to investigate and address the issue.
Application security controls are implemented together with FinOrbit's Privacy Policy and applicable data-protection requirements.
Personal information is handled in accordance with the Company's Privacy Policy and applicable laws and regulations.
FinOrbit may review and update this Application Security Policy periodically to reflect:
For application-security concerns, suspected vulnerabilities, or security incidents, please contact:
FinOrbit Finance Private Limited
1009, Sakar 5, Nr-Natraj Cinema, Ashram Road, Ahmedabad, Gujarat, India – 380009
We are pleased to partner with EasyCred for technology and digital platform services.