JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 09 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Information Security / Risk / Fraud / Compliance |
| Review Frequency | At least annually and after any material cyber-fraud incident or significant control change |
| Classification | Confidential – Cyber Fraud Prevention & Incident Response Policy |
This Policy establishes the Company's framework for preventing, detecting, investigating, containing and responding to cyber fraud and cyber-enabled financial abuse affecting customers, gift cards/vouchers, payment transactions, systems, employees, vendors or business operations.
This Policy applies to websites, applications, APIs, customer accounts, gift-card/voucher systems, payment integrations, employee systems, cloud infrastructure, vendors, partners, devices, transaction monitoring and related operational processes.
Management shall establish appropriate oversight, resources and accountability for cyber-fraud prevention. Information Security, Risk/Fraud, Technology, Operations, Compliance and relevant business owners shall coordinate based on incident type and severity.
Credentials, authentication factors and security secrets shall be protected. Suspicious login, credential-reset, device or account behaviour may trigger additional verification, temporary restrictions or investigation.
The Company shall use appropriate transaction and voucher monitoring controls, proportionate to its business model and partner arrangements, to identify unusual value, velocity, redemption, refund, account or payment behaviour.
Employees, contractors and relevant partners shall promptly report suspected cyber fraud, phishing, unauthorised access, suspicious transactions, data compromise or other security concerns through designated reporting channels.
Incidents shall be classified according to severity, customer impact, financial impact, data exposure, operational disruption, scope and legal or regulatory significance.
Depending on the incident, containment may include account restrictions, transaction holds, disabling compromised credentials, isolating systems, blocking malicious indicators, suspending affected integrations or coordinating with relevant partners.
Relevant logs, transaction records, account information, communications, system artefacts, device information and other evidence shall be preserved in a manner that supports investigation and applicable legal or law-enforcement processes.
Where an incident involves a bank, payment processor, PPI, merchant, technology provider or other partner, the Company shall coordinate with the relevant party for transaction tracing, blocking, reversal, investigation and other appropriate actions.
Where required or appropriate, the Company may coordinate with law-enforcement authorities, cybercrime authorities, regulators, payment partners or other competent bodies. Any required notifications shall be handled by authorised personnel.
External communications regarding material cyber-fraud incidents shall be controlled by authorised management and relevant Compliance/Legal personnel. Employees shall not make unauthorised public statements regarding incidents.
Material cyber-fraud incidents originating from or affecting a vendor or partner shall be managed under this Policy and the Third-Party / Vendor Risk Management Policy, including escalation, evidence preservation and remediation.
Affected services shall be restored only after appropriate security validation, removal or containment of the threat, data-integrity checks and approval by authorised personnel.
Material incidents shall undergo post-incident review to identify root causes, control weaknesses, customer impact, financial impact and corrective actions.
Incident reports, investigation records, evidence references, communications, decisions, transaction information, recovery records and corrective actions shall be retained according to applicable legal, regulatory and internal retention requirements.
Cyber-fraud investigations shall be treated as confidential. Access shall be limited to authorised personnel and information shall be shared only on a need-to-know basis or where disclosure is required or authorised.
The Company may conduct phishing simulations, tabletop exercises, incident-response drills, fraud-rule testing and other awareness or control exercises appropriate to its risk profile.
Exceptions shall be documented, risk-assessed and approved by authorised management. Exceptions shall not override mandatory legal, regulatory or contractual obligations.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Cyber-fraud governance, material incident decisions and resources | Director / Management |
| Information Security | Security monitoring, incident response and technical containment | Security Head |
| Risk / Fraud | Fraud monitoring, investigation and transaction controls | Risk/Fraud Head |
| Technology | System security, logs, remediation and recovery | Technology Head |
| Operations | Transaction/customer operations and incident coordination | Operations Head |
| Compliance / Legal | Regulatory, legal and law-enforcement coordination | Compliance/Legal Head |
| Finance | Financial impact, refunds, reversals and reconciliation | Finance Head |
| Customer Support | Customer reporting, communication and support | Support Head |
| Vendor Owner | Third-party incident coordination | Management |
This Policy shall be reviewed at least annually and following any material cyber-fraud incident, major technology change, significant partner change or material change in the Company's risk environment.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Risk / Fraud | |
| Reviewed By | Compliance / Legal / Technology / Operations | |
| Approved By | Director / Authorised Signatory |