BharatOne logo

Security Policy

Security Policy – BharatOne Services and Affiliates Pvt. Ltd.

Last Updated: July 30, 2026

BharatOne Services and Affiliates Pvt. Ltd. ("BharatOne", "Company", "we", "our", or "us") is committed to maintaining appropriate administrative, technical, organizational, and physical security measures to protect the confidentiality, integrity, availability, and resilience of its digital platforms, systems, applications, APIs, operational infrastructure, merchant ecosystem, and customer information.

This Security Policy ("Policy") outlines the general security principles and operational practices adopted by BharatOne to support secure platform operations, responsible information handling, and protection against unauthorized access, misuse, fraud, and cybersecurity threats.

This Policy applies to customers, merchants, retailers, franchisees, agents, distributors, API users, business partners, employees, contractors, vendors, service providers, and all users interacting with BharatOne's Services.

1. Purpose

The purpose of this Policy is to:

  • Support secure and reliable platform operations.
  • Protect customer, merchant, and operational information from unauthorized access, disclosure, misuse, alteration, or destruction.
  • Maintain platform integrity, availability, and operational resilience.
  • Promote responsible information security practices.
  • Reduce risks associated with fraud, cyberattacks, unauthorized access, and operational disruptions.
  • Support compliance with applicable Indian laws, regulatory requirements, and industry best practices.

2. Security Principles

BharatOne's security framework is guided by the following principles:

  • Confidentiality of sensitive information.
  • Integrity of systems and transaction data.
  • Availability and resilience of critical services.
  • Role-based access control.
  • Accountability and auditability.
  • Least privilege access.
  • Risk-based security management.
  • Continuous monitoring and improvement.
  • Incident preparedness and response.
  • Compliance with applicable legal and regulatory obligations.

3. Security Measures

BharatOne may implement commercially reasonable administrative, technical, and organizational safeguards, including:

  • Strong authentication and access controls.
  • Role-based user access management.
  • Secure communication protocols.
  • Encryption of sensitive information during transmission and storage where appropriate.
  • Multi-factor authentication for privileged access where applicable.
  • API authentication and security controls.
  • Network and infrastructure security measures.
  • Continuous monitoring and audit logging.
  • Fraud detection and prevention mechanisms.
  • Malware protection and endpoint security.
  • Periodic vulnerability assessments and security reviews.
  • Secure software development practices.
  • Backup, disaster recovery, and business continuity procedures where applicable.

Security measures may be updated periodically in response to evolving technologies, emerging threats, operational requirements, regulatory developments, and partner security standards.

4. User Responsibilities

Users are responsible for:

  • Maintaining the confidentiality of usernames, passwords, PINs, and One-Time Passwords (OTPs).
  • Using secure devices, updated software, and trusted internet connections.
  • Preventing unauthorized access to their accounts.
  • Reviewing transactions before confirmation.
  • Promptly reporting suspicious activities, fraud, or security concerns.
  • Complying with BharatOne's Terms of Use and applicable laws.

Users should not:

  • Share authentication credentials with unauthorized persons.
  • Attempt unauthorized access to BharatOne systems.
  • Circumvent security controls.
  • Upload malicious software or harmful code.
  • Misuse BharatOne's Services or digital infrastructure.

5. Data Protection and Localization

BharatOne follows responsible operational practices to protect personal information, merchant data, transaction records, and operational information.

Where required by applicable law or regulatory direction, regulated customer and payment-related information is stored and processed within the geographical boundaries of India.

Information may be shared with authorized banking partners, payment service providers, government authorities, technology providers, or other authorized ecosystem participants only where:

  • Necessary for service delivery.
  • Required by law.
  • Required under contractual obligations.
  • Necessary for fraud prevention or security.
  • Required by competent regulatory authorities.

Additional information regarding privacy and information management is available in BharatOne's Privacy Policy and Data Protection & Localization Statement.

6. Monitoring and Risk Management

BharatOne may undertake reasonable monitoring activities to:

  • Detect suspicious or fraudulent activity.
  • Identify unauthorized access attempts.
  • Protect platform integrity.
  • Monitor operational health.
  • Investigate service disruptions.
  • Support regulatory compliance.
  • Improve platform reliability.

Monitoring activities may include:

  • Authentication monitoring.
  • System and application logging.
  • Transaction pattern analysis.
  • Device and network monitoring.
  • API usage monitoring.
  • Infrastructure performance monitoring.
  • Security event logging.

7. Third-Party Services and Infrastructure

BharatOne delivers various services through integrations with banks, payment aggregators, payment gateways, government departments, telecom operators, cloud infrastructure providers, API providers, identity verification agencies, and other technology partners.

While BharatOne endeavors to work with reputable service providers that maintain appropriate security standards, it cannot guarantee the continuous availability or security of third-party systems beyond its operational control.

8. Incident Response

BharatOne maintains incident response procedures designed to support:

  • Detection of security incidents.
  • Investigation of suspicious activities.
  • Containment of security events.
  • Mitigation of operational risks.
  • Recovery of affected systems.
  • Restoration of services where reasonably practicable.
  • Notification to relevant partners or authorities where required by applicable law.

Users are encouraged to immediately report suspected fraud, unauthorized account access, security vulnerabilities, or cybersecurity incidents through BharatOne's official support channels.

9. Limitation of Security Guarantees

Although BharatOne employs commercially reasonable security measures, no digital platform, network, software application, or electronic communication system can guarantee absolute security or uninterrupted availability.

Users acknowledge that:

  • Internet-based services involve inherent cybersecurity risks.
  • Technical failures, cyberattacks, or external disruptions may occur.
  • Users also play an essential role in protecting their own devices, credentials, and accounts.

10. Policy Updates

BharatOne may revise this Security Policy periodically to reflect:

  • Changes in technology.
  • Emerging cybersecurity threats.
  • Operational improvements.
  • Regulatory developments.
  • Industry best practices.
  • Partner security requirements.

The latest version of this Policy will be published on BharatOne's official website. Continued use of the Services after publication of any revised Policy constitutes acceptance of the updated version.

11. Contact Information

For security concerns, vulnerability reporting, fraud reporting, or information security matters, please contact:

12. Governing Law

This Security Policy shall be governed by and construed in accordance with the laws of India.

Any disputes arising out of or relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Hassan, Karnataka, unless otherwise required by applicable law.