Security programme
Encoreats aims to apply risk-based administrative, technical and organisational controls across identities, applications, cloud infrastructure, data stores, vendors and operations.
Core controls
- Least-privilege and role-based access.
- Multi-factor authentication for privileged access.
- Encryption in transit and appropriate encryption at rest.
- Secure development, review, dependency and vulnerability management.
- Central logging, monitoring, backups and recovery testing.
- Secrets management and separation of environments.
- Vendor due diligence and contractual data-security obligations.
CERT-In readiness
Applicable systems should use accurate time synchronisation, designate an incident point of contact, report specified cyber incidents within the prescribed six-hour period, and securely retain required ICT logs for a rolling period of 180 days within Indian jurisdiction.
Personal data incidents
The incident plan covers containment, investigation, evidence preservation, risk assessment, processor coordination, affected-person communication and notification to the competent authority where required.
Responsible disclosure
Security researchers should report suspected vulnerabilities to security@encoreats.info with reproduction steps and avoid privacy invasion, service disruption, data extraction, extortion or public disclosure before a reasonable remediation period.
User security
Use unique passwords, enable available MFA, keep devices updated, verify domains and never disclose OTPs, UPI PINs, banking passwords or CVVs.
Launch and legal-review notice
This is a structured operational draft for Encoreats and not a substitute for advice from a qualified Indian advocate, chartered accountant, data-protection professional, or other specialist. Before publication, replace all bracketed fields, confirm that every email inbox and response workflow is operational, and ensure the wording matches the actual product, payment, refund, data-retention, verification, event, and partner processes.
