NxtBanking — NxtBanking — API Infrastructure for Indian Fintech

Data Protection and Information Security Policy

How NxtBanking secures payment and personal data: encryption, access control, secure development, incident response, vendor management, business continuity and compliance with RBI, NPCI and DPDP Act requirements.

Updated October 6, 2026 5 min read

Effective date and last updated: 6 October 2026 · Applies to: NxtBanking (a product of Laraware Private Limited), its websites, APIs, dashboards and partner platforms.

1. Purpose

This policy describes the technical and organisational measures Laraware Private Limited uses to protect the confidentiality, integrity and availability of the information we handle for AEPS, BBPS, recharge, payout and other fintech Services. It supports the Privacy Policy and is aligned with the IT Act, 2000, the SPDI Rules, 2011, the DPDP Act, 2023, RBI guidance on payment-system security and NPCI information-security requirements.

NxtBanking is a software and API infrastructure provider. Where a service involves a regulated activity (for example BBPS bill payments, AEPS cash withdrawal, money transfer or prepaid recharge), that activity is carried out by the licensed or authorised entity concerned (such as a Bharat Bill Payment Operating Unit, a sponsor bank, a Payment Aggregator or a payment system operator) under its own licence and rules. NxtBanking does not hold customer funds as a bank, does not issue payment instruments and does not claim any licence or authorisation that it has not been granted.

2. Governance

  • Information security is overseen by senior management, with a named security lead and a Data Protection contact.
  • Policies are reviewed at least annually and after material changes.
  • All employees and contractors sign confidentiality undertakings and receive security training at induction and annually.
  • Information is classified (public, internal, confidential, restricted) and handled according to its class.

3. Access control

  • Least-privilege, role-based access to systems and data, reviewed at least quarterly.
  • Unique user IDs, strong passwords and multi-factor authentication for admin, production and remote access.
  • Prompt removal of access when roles change or people leave.
  • Privileged access is logged, and production data access is restricted and monitored.
  • Customer API keys and secrets are stored hashed or encrypted, and may be restricted by IP whitelisting.

4. Data protection

  • In transit: TLS 1.2 or higher on all external and sensitive internal connections.
  • At rest: strong encryption for sensitive data, with managed keys and rotation.
  • Sensitive authentication data such as card CVV, PINs, passwords and biometric data is not stored. Aadhaar numbers are masked as required.
  • Data minimisation: we collect only what is needed and keep it only for the periods in the Privacy Policy.
  • Masking and tokenisation are used where full values are not needed. Production data is not used in test environments without masking.
  • Secure deletion or anonymisation at the end of retention.

5. Network and infrastructure security

  • Hosting in secured data-centre or cloud environments with physical and logical controls.
  • Firewalls and web application firewall, network segmentation, intrusion detection and DDoS mitigation.
  • Hardened systems, timely security patching and secure configuration baselines.
  • Endpoint protection, device encryption and controls on removable media.

6. Secure development

  • Secure coding standards and code review, with separation of development, test and production.
  • Automated dependency and vulnerability scanning.
  • Vulnerability assessment and penetration testing of applications and infrastructure at least annually and after major changes, with tracked remediation.
  • Change management with approval and rollback plans.

7. Logging and monitoring

Security-relevant events, administrative actions and API access are logged and monitored with alerting. Logs are protected against tampering and retained for at least 12 months (or longer where required) to support investigations.

8. Incident management

  • A documented incident response plan with defined roles, severity levels and communication paths.
  • Security incidents are reported to the security lead at once and handled through containment, eradication, recovery and review.
  • Where required, we report incidents to CERT-In within 6 hours of noticing certain cyber incidents, to our partner banks and NPCI as their rules require, and to the Data Protection Board and affected individuals for personal data breaches.
  • Post-incident reviews feed corrective actions.

9. Business continuity and disaster recovery

We maintain backups, redundancy and a tested disaster recovery plan, with defined recovery time and recovery point objectives for critical payment services. Plans are tested at least annually.

10. Vendor and third-party management

Vendors with access to data or systems are assessed before engagement, bound by contract to security and confidentiality duties, and reviewed periodically. Sub-processors are listed on request.

11. Responsibilities of customers and partners

Partners and merchants must protect their credentials and devices, use certified devices and updated software, keep their API keys secret, report suspected compromise immediately, and comply with the Terms and Conditions and Acceptable Use Policy.

12. Responsible disclosure

If you find a security vulnerability in our Services, please report it to legalteam@laraware.com with details to reproduce it. Please do not access others' data, disrupt services or disclose publicly before we have fixed the issue. We will acknowledge within 2 working days and keep you informed.

13. Compliance and audit

We carry out internal reviews and cooperate with audits by regulators, partner banks and NPCI. Non-compliance by staff may lead to disciplinary action, and by partners to suspension or termination.

Contact us

Purpose Contact
General and customer support support@laraware.com
Refund and failed transaction queries refunds@laraware.com
Legal, compliance and grievance escalation legalteam@laraware.com
Phone 0731-4621515
Registered and correspondence address Laraware Private Limited, B-2/64, Vibhutikhand, Gomtinagar, Lucknow, Uttar Pradesh 226010, India
Ready when you are

Go live on NxtBanking rails.

Tell us which rails you need — payouts, AEPS, BBPS, UPI, KYC, or the full stack. Our solution architects map the right APIs to your use case, usually within a day.