Information Security Policy
Technical architecture, access controls, vulnerability management standards, and security controls protecting Arzenlabs systems and customer data.
1. Security Principles & Alignment Statement
Information security is foundational to the engineering operations of Arzenlabs ("Arzenlabs"). Our Information Security Management System ("ISMS") is designed around core principles of confidentiality, integrity, availability, and legibility.
Framework Alignment Statement: Arzenlabs structures its technical controls and governance procedures to align with ISO/IEC 27001:2022 standards and Indian CERT-In cybersecurity directions. Arzenlabs does not claim unobtained third-party certifications and maintains operational controls independently.
2. Access Control & Authentication Safeguards
- Least Privilege & RBAC: Administrative access to production systems, source repositories, and database instances is strictly limited based on Role-Based Access Control (RBAC) and least privilege requirements.
- Mandatory Multi-Factor Authentication (MFA): MFA using Hardware Security Keys (FIDO2/WebAuthn) or Time-based One-Time Passwords (TOTP) is enforced across all employee accounts and cloud consoles.
- Privileged Access Management: Administrative sessions utilize hardware-backed SSH key pairs and short-lived session tokens with full command logging.
3. Data Security & Encryption Standards
Encryption in Transit
All web traffic and API endpoints enforce Transport Layer Security (TLS 1.3) with strong cipher suites and HSTS preloading.
Encryption at Rest
Persistent databases, storage volumes, and backup archives are encrypted at rest using AES-256 cryptographic standards.
4. Vulnerability Management & Patching
We perform continuous automated dependency scanning, static code analysis, and infrastructure vulnerability audits. Critical security patches are applied to production servers within 24 hours of vendor disclosure.
5. Incident Response & Reporting
Arzenlabs maintains an active Security Incident Response Plan ("SIRP"). In the event of a confirmed security incident affecting customer data or core infrastructure, Arzenlabs will notify affected parties and statutory authorities (such as CERT-In) in accordance with applicable legal timelines.
6. Security Desk Contact
To contact the Arzenlabs Information Security team or report security concerns:
Arzenlabs seeks to comply with applicable data protection and privacy laws including the Digital Personal Data Protection Act (DPDP) 2023, Information Technology Act 2000, and applicable international privacy principles.