Vahanse Security Overview
Status: DRAFT — FOR LEGAL REVIEW — NOT FOR EXECUTION
Version: 0.9 - Counsel Review Draft
Draft date: 31 August 2026
Operator: Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512)
Brand: Vahanse
Head office: Vahanfin Solutions Pvt Ltd, Nabibux House, 3rd Floor, Vakola Bridge Road, Santacruz (E), Mumbai 400 055, Maharashtra, India
This document is a Vahanse-specific working draft prepared for Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512), which operates the Vahanse brand. It is not legal advice and must be reviewed, approved and adapted by qualified Indian counsel before publication, signature or reliance. Commercial values, support contacts, regulatory representations, security commitments, service levels and any customer-specific terms must be validated against actual operations and contracts.
Purpose: Public/enterprise-facing description of security principles, with no unverified certification claims.
Audience: Enterprise security, procurement, partners and customers
1. Security Principle
Vahanse is designed to support business-critical vehicle compliance workflows. Security controls should be implemented using least privilege, layered defenses, secure software practices, auditability and incident response appropriate to the sensitivity of account, vehicle, document and transaction data.
2. Important Publication Rule
This overview must describe only controls that are actually implemented. Before publication, each control below must be marked VERIFIED, PARTIAL or NOT IMPLEMENTED by the Vahanse technology/security owner. Do not publish future-state controls as current facts.
3. Identity and Access Management
- Role-based access control for supported business roles/tenants – verify implementation.
- Strong password/session controls – verify.
- MFA for privileged/enterprise users – verify scope.
- Joiner/mover/leaver process for internal privileged access – verify.
- API credential scoping/rotation – verify.
4. Data Protection
- TLS/encryption in transit – verify supported versions/configuration.
- Encryption at rest for databases/object storage – verify.
- Separation of tenant access and authorization checks – verify.
- Secrets stored outside source code – verify.
- Data retention/deletion controls – verify.
5. Application Security
- Secure development/review process – verify.
- Dependency and vulnerability monitoring – verify.
- Input validation and authorization testing – verify.
- Security testing/penetration testing schedule – verify and do not claim independent certification unless completed.
- Change management and production deployment controls – verify.
6. Logging and Monitoring
Vahanse should maintain application/security logs appropriate to investigation, support, API usage and audit. Exact log sources, retention and monitoring coverage should be documented in the internal security standard.
7. Infrastructure and Availability
Cloud/hosting providers, regions, backup configuration, RPO/RTO and failover must be validated against the actual deployment before publication or customer commitment.
8. Incident Response
Vahanse should maintain an incident classification, escalation, containment, recovery and communication process. Contractual/personal-data incident notification follows the MSA/DPA and applicable law.
9. Vendor and Subprocessor Risk
Material subprocessors and vendors with access to customer data should undergo proportionate security/privacy diligence and be bound by appropriate confidentiality/data-protection obligations.
10. Customer Responsibilities
Customers remain responsible for their users, credentials, devices, integrations, access configuration and downstream use of exported/API data.
11. Certifications
Do not claim ISO 27001, SOC 2, PCI DSS, DPDP certification, government certification, RBI/IRDAI authorization or similar status unless formally achieved and applicable. A roadmap may be shared separately if accurately labelled as planned.
12. Security Contact
Designated security reporting email: [security email to be confirmed]. Vahanse should establish a coordinated vulnerability disclosure process before publishing a security mailbox for researchers.