Vahanse Enterprise Security Annexure & Questionnaire
Status: DRAFT — FOR LEGAL REVIEW — NOT FOR EXECUTION
Version: 0.9 - Counsel Review Draft
Draft date: 31 August 2026
Operator: Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512)
Brand: Vahanse
Head office: Vahanfin Solutions Pvt Ltd, Nabibux House, 3rd Floor, Vakola Bridge Road, Santacruz (E), Mumbai 400 055, Maharashtra, India
This document is a Vahanse-specific working draft prepared for Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512), which operates the Vahanse brand. It is not legal advice and must be reviewed, approved and adapted by qualified Indian counsel before publication, signature or reliance. Commercial values, support contacts, regulatory representations, security commitments, service levels and any customer-specific terms must be validated against actual operations and contracts.
Purpose: Internal/contractual security due-diligence schedule with evidence-based responses.
Audience: Enterprise procurement, security and technology teams
1. Instructions
For every question select IMPLEMENTED, PARTIAL, NOT IMPLEMENTED, NOT APPLICABLE or UNKNOWN, provide evidence/owner and do not answer “Yes” based on intention. Customer-specific answers must be reviewed by CTO/security owner before release.
2. Organization and Governance
- Is there an assigned security owner? [STATUS/EVIDENCE]
- Are security policies approved and reviewed periodically? [STATUS/EVIDENCE]
- Are employees/contractors subject to confidentiality obligations? [STATUS/EVIDENCE]
- Is security awareness training conducted? [STATUS/EVIDENCE]
3. Asset and Access Management
- Inventory of production systems and privileged accounts.
- Least-privilege role assignment.
- Privileged access approval/review.
- MFA scope for admin/cloud/source control.
- Joiner/mover/leaver process.
- API key/secret rotation and revocation.
4. Secure Development
- Source control and branch protections.
- Code review requirements.
- Dependency/vulnerability scanning.
- Secrets scanning.
- SAST/DAST where applicable.
- Penetration testing and remediation tracking.
- Change/production release approvals.
5. Infrastructure Security
- Hosting provider and regions.
- Network segmentation/firewalls/security groups.
- TLS configuration.
- Encryption at rest.
- Database access restrictions.
- Backup encryption.
- Patch management.
- Infrastructure-as-code/change audit where used.
6. Application and Tenant Security
- Authentication/session architecture.
- RBAC/tenant isolation.
- Authorization checks for vehicle/category/company scoping.
- Rate limiting/abuse controls.
- Audit logs.
- File upload malware/content controls where applicable.
- Input validation and API security.
7. Data Protection
- Data inventory/classification.
- Retention schedule.
- Deletion/export process.
- Production/test data separation.
- Masking of personal data in non-production.
- Subprocessor register.
- Cross-border processing review.
- DPDP readiness owner.
8. Logging and Monitoring
- Centralized logs.
- Security alerting.
- Authentication/admin event monitoring.
- API error/availability monitoring.
- Log retention and access control.
- Time synchronization.
9. Business Continuity and Disaster Recovery
- Backup frequency.
- Restore tests.
- Documented RPO.
- Documented RTO.
- DR plan.
- Single-region/single-provider dependencies.
- BCP exercise frequency.
10. Incident Response
- Incident response plan.
- Severity classification.
- Security contact/on-call.
- Forensic/log preservation.
- Customer notification workflow.
- Personal data breach assessment.
- Post-incident review.
11. Vendor Risk
- Security/privacy review before material vendors.
- Contractual confidentiality/DPA terms.
- Access restrictions for vendors.
- Periodic review.
- Offboarding and data deletion.
12. Physical and Personnel Security
- Office/device controls appropriate to work model.
- Company-device/MDM policy where applicable.
- Background checks where legally appropriate.
- Remote-work access controls.
- Removable media policy.
13. Compliance and Certifications
List only currently held certifications/independent reports with scope and expiry. If none, state “Not currently certified” rather than implying compliance. Planned certifications may be listed in a separate roadmap, not as an existing control.
14. Customer-Specific Security Requirements
[Data residency] [SSO/SAML] [IP allowlisting] [Dedicated environment] [Custom retention] [Customer-managed keys] [Pen-test evidence] – mark supported/not supported and commercial impact.
15. Evidence Register
Control | Status | Evidence Link/Document | Owner | Last Reviewed | Remediation Due. Maintain this register internally and disclose only appropriate evidence under NDA.
16. Contractual Security Commitments
Only controls explicitly marked “Contractual” in the signed Security Schedule/SOW are legally committed. Questionnaire responses should be accurate snapshots and not silently expand contractual warranties beyond the Agreement.