
Information Security
Management System
Official statement of governance commitments by Vestigo Insurance Brokers Pvt. Ltd. to protect the Confidentiality, Integrity, and Availability of client and regulatory information assets.
Corporate Identity
CIN: U66220GJ2025PTC166605
Vestigo Insurance Brokers Pvt. Ltd.
Corporate Office
SF 201, Status Complex, Opp. Amrapali Complex, Pani Tanki Road, Karelibaug, Vadodara - 390018, Gujarat, India
Security Desk
enquiry@vestigoinsurance.com
www.vestigoinsurance.com
01. Purpose
02. Scope
03. Policy Objectives
04. Governance & Accountability
Security policies, risk assessments and material controls will be reviewed periodically and following significant legal, regulatory, technological, operational or threat changes. Independent review, internal audit or external assessment may be undertaken where appropriate.
05. Core Security Principles
06. Information Classification and Handling
07. Access Control & Identity Security
08. Technology, Network and Endpoint Security
09. Secure Development and Change Management
10. Logging, Monitoring and Threat Detection
11. Third-Party and Cloud Security
12. Physical and Paper Security
13. Personnel Security, Awareness and Confidentiality
14. Incident Management and Regulatory Reporting
Where applicable, Vestigo will make notifications or reports to CERT-In, IRDAI, the Data Protection Board of India, affected clients or individuals, and other competent authorities within legally prescribed timeframes. No employee or third party may conceal an incident, make an unauthorised public statement, or destroy relevant evidence.
15. Business Continuity, Backup and Recovery
16. Compliance, Review and Enforcement
17. Public Security Contact
18. Policy Status and Updates
Responsible Security Reporting
If you have identified a potential security weakness, bug, or vulnerability within Vestigo’s infrastructure, please notify our IT Security Desk responsibly.
• Include "Confidential Security Report" in the subject line.
• Detail steps to reproduce the issue without altering or accessing non-public data.
• Our team acknowledges reports within 24–48 hours.