Information Security Management
ISMS Framework | Effective: 20 July 2026

Information Security
Management System

Official statement of governance commitments by Vestigo Insurance Brokers Pvt. Ltd. to protect the Confidentiality, Integrity, and Availability of client and regulatory information assets.

IRDAI RegistrationNo. 1131 (Direct Broker (General & Life))
Registration Validity15 January 2026 to 14 January 2029

Corporate Identity

CIN: U66220GJ2025PTC166605

Vestigo Insurance Brokers Pvt. Ltd.

Corporate Office

SF 201, Status Complex, Opp. Amrapali Complex, Pani Tanki Road, Karelibaug, Vadodara - 390018, Gujarat, India

Security Desk

enquiry@vestigoinsurance.com

www.vestigoinsurance.com

Clause 01

01. Purpose

Information is central to insurance advisory, policy placement, servicing and claims. Vestigo is committed to protecting the confidentiality, integrity, availability and lawful use of information entrusted to it. This Information Security Management System (ISMS) Policy establishes the principles by which Vestigo manages information-security and cyber risks across people, processes, premises, technology and third parties.
Clause 02

02. Scope

This Policy applies to information in any form, including electronic records, emails, communications, documents, paper files, images, audio, credentials, system logs and backups. It applies to directors, employees, trainees, consultants, business partners, vendors and other persons who access Vestigo information or systems, to the extent relevant to their role or contract.
Clause 03

03. Policy Objectives

Vestigo's information-security objectives are to:
Protect client, insurer, employee and regulatory information.
Maintain resilient systems.
Manage cyber and technology risk.
Meet IRDAI and legal requirements.
Respond to security incidents.
Ensure third parties maintain safeguards.
Promote a culture of information security.
Clause 04

04. Governance & Accountability

Management is responsible for establishing oversight, assigning security responsibilities, providing reasonable resources, approving policies and monitoring material information-security risks. Business and technology owners are accountable for risks within their functions. Every authorised user is responsible for complying with security requirements, protecting credentials and promptly reporting suspected incidents.
Security policies, risk assessments and material controls will be reviewed periodically and following significant legal, regulatory, technological, operational or threat changes. Independent review, internal audit or external assessment may be undertaken where appropriate.
Clause 05

05. Core Security Principles

Confidentiality: information is accessible only to authorised persons for approved purposes.
Integrity: information is protected against unauthorised or accidental alteration and remains accurate and traceable.
Availability: systems and information required for critical operations are reasonably available and recoverable.
Privacy by design: personal data considerations are integrated into new processes, technology and vendor arrangements.
Least privilege and need-to-know: access is limited to what a user reasonably requires for authorised duties
Defence in depth: multiple preventive, detective, responsive and recovery measures are used rather than reliance on a single control
Continuous improvement: controls are reviewed and improved based on risk, incidents, testing, audit and evolving threats.
Clause 06

06. Information Classification and Handling

Vestigo classifies and handles information according to its sensitivity, business value and legal or contractual requirements. Confidential, personal, medical, financial, claims, KYC, credential and regulatory information is subject to enhanced access, transfer, storage, retention and disposal controls. Information must not be copied, transmitted, downloaded, printed or disclosed except for an authorised business purpose and through approved means.
Clause 07

07. Access Control & Identity Security

Access to systems and information is authorised according to role, approved business need and the principle of least privilege. Vestigo may use unique user identities, strong passwords, multi-factor authentication where appropriate, periodic access review, prompt removal or modification of access following role changes, and controls over privileged accounts. Users must not share passwords, authentication codes or credentials.
Clause 08

08. Technology, Network and Endpoint Security

Vestigo applies risk-appropriate controls to networks, devices, applications and infrastructure. These may include secure configuration, anti-malware, firewalls, endpoint protection, patching, vulnerability management, email security, encryption, secure remote access, backup, monitoring and restrictions on removable media or unauthorised software. Technology changes and new information-processing facilities are subject to appropriate review and approval.
Clause 09

09. Secure Development and Change Management

Where Vestigo develops, configures or procures applications, websites, integrations or automation, security and privacy requirements are considered during design, testing, implementation and change. Material changes are authorised, tested and documented commensurate with risk. Production data should not be used in testing unless appropriately protected and authorised.
Clause 10

10. Logging, Monitoring and Threat Detection

Vestigo maintains logs and monitoring appropriate to its systems, risk profile and applicable legal requirements. Security events may be reviewed to detect unauthorised activity, malware, data leakage, account compromise, fraud or operational failure. Logs are protected against unauthorised alteration and retained for the period required by applicable law, regulatory direction, investigation or business need.
Clause 11

11. Third-Party and Cloud Security

Before allowing a vendor or service provider to process or access material information, Vestigo considers the nature of the service, data sensitivity, security capability, location, subcontracting, incident management, continuity, confidentiality, audit and exit requirements. Contracts will contain appropriate information-security, privacy, confidentiality and cooperation obligations. Vestigo remains accountable for its regulatory obligations and does not treat outsourcing as a transfer of responsibility.
Clause 12

12. Physical and Paper Security

Vestigo applies reasonable physical safeguards to premises, work areas, records, equipment and visitor access. Confidential papers and media must be stored securely and disposed of through approved destruction methods. Unattended screens, portable devices and documents must be protected against unauthorised viewing, theft or loss.
Clause 13

13. Personnel Security, Awareness and Confidentiality

Personnel and relevant third parties are subject to role-appropriate screening, confidentiality obligations, acceptable-use requirements and security awareness. Training may cover phishing, social engineering, credential protection, safe handling of personal and claims information, remote working, incident reporting, fraud and regulatory responsibilities. Breach of security obligations may result in access restriction, disciplinary action, contractual remedies or reporting to authorities, as applicable.
Clause 14

14. Incident Management and Regulatory Reporting

All suspected cyber incidents, data breaches, malware, phishing, lost devices, unauthorised disclosure, credential compromise, fraud or security weaknesses must be reported immediately through approved channels. Vestigo will triage, contain, preserve evidence, investigate, remediate and document incidents and will cooperate with insurers, clients, service providers, law-enforcement and regulators as required.
Where applicable, Vestigo will make notifications or reports to CERT-In, IRDAI, the Data Protection Board of India, affected clients or individuals, and other competent authorities within legally prescribed timeframes. No employee or third party may conceal an incident, make an unauthorised public statement, or destroy relevant evidence.
Clause 15

15. Business Continuity, Backup and Recovery

Vestigo maintains risk-appropriate business-continuity, backup and recovery arrangements for critical operations. Backups are protected and tested at reasonable intervals. Continuity and recovery plans may be exercised, reviewed and improved based on testing, incidents, technology changes and business dependency.
Clause 16

16. Compliance, Review and Enforcement

Compliance with this Policy may be monitored through reviews, audits, testing, vulnerability assessment, incident analysis and management reporting. Exceptions must be documented, risk-assessed, time-bound and authorised. Violations may result in disciplinary, contractual, civil, regulatory or criminal consequences, depending on the circumstances.
Clause 17

17. Public Security Contact

A person who believes that Vestigo’s website, systems or information may be affected by a security weakness or incident should report it responsibly to enquiry@vestigoinsurance.com with the subject “Confidential Security Report”. The report should contain sufficient factual detail to permit investigation and should not involve unlawful access, disruption, exploitation, data extraction or public disclosure.
Clause 18

18. Policy Status and Updates

This is a public statement of Vestigo’s information-security commitments. Detailed control configurations, network architecture and internal procedures are confidential and are not disclosed through this website. Publication of this Policy does not represent that Vestigo holds any particular external certification unless expressly stated elsewhere with current evidence. This Policy may be updated to reflect changes in risk, law, regulation, technology or business operations.

Responsible Security Reporting

If you have identified a potential security weakness, bug, or vulnerability within Vestigo’s infrastructure, please notify our IT Security Desk responsibly.

• Include "Confidential Security Report" in the subject line.

• Detail steps to reproduce the issue without altering or accessing non-public data.

• Our team acknowledges reports within 24–48 hours.

Insurance is a subject matter of solicitation | Vestigo Insurance Brokers Pvt. Ltd. | IRDAI Regn. No: 1131 (Direct Broker (General & Life)) | CIN: U66220GJ2025PTC166605