Effective date and last updated: 6 October 2026 · Applies to: NxtBanking (a product of Laraware Private Limited), its websites, APIs, dashboards and partner platforms.
1. Purpose
This policy describes the technical and organisational measures Laraware Private Limited uses to protect the confidentiality, integrity and availability of the information we handle for AEPS, BBPS, recharge, payout and other fintech Services. It supports the Privacy Policy and is aligned with the IT Act, 2000, the SPDI Rules, 2011, the DPDP Act, 2023, RBI guidance on payment-system security and NPCI information-security requirements.
NxtBanking is a software and API infrastructure provider. Where a service involves a regulated activity (for example BBPS bill payments, AEPS cash withdrawal, money transfer or prepaid recharge), that activity is carried out by the licensed or authorised entity concerned (such as a Bharat Bill Payment Operating Unit, a sponsor bank, a Payment Aggregator or a payment system operator) under its own licence and rules. NxtBanking does not hold customer funds as a bank, does not issue payment instruments and does not claim any licence or authorisation that it has not been granted.
2. Governance
- Information security is overseen by senior management, with a named security lead and a Data Protection contact.
- Policies are reviewed at least annually and after material changes.
- All employees and contractors sign confidentiality undertakings and receive security training at induction and annually.
- Information is classified (public, internal, confidential, restricted) and handled according to its class.
3. Access control
- Least-privilege, role-based access to systems and data, reviewed at least quarterly.
- Unique user IDs, strong passwords and multi-factor authentication for admin, production and remote access.
- Prompt removal of access when roles change or people leave.
- Privileged access is logged, and production data access is restricted and monitored.
- Customer API keys and secrets are stored hashed or encrypted, and may be restricted by IP whitelisting.
4. Data protection
- In transit: TLS 1.2 or higher on all external and sensitive internal connections.
- At rest: strong encryption for sensitive data, with managed keys and rotation.
- Sensitive authentication data such as card CVV, PINs, passwords and biometric data is not stored. Aadhaar numbers are masked as required.
- Data minimisation: we collect only what is needed and keep it only for the periods in the Privacy Policy.
- Masking and tokenisation are used where full values are not needed. Production data is not used in test environments without masking.
- Secure deletion or anonymisation at the end of retention.
5. Network and infrastructure security
- Hosting in secured data-centre or cloud environments with physical and logical controls.
- Firewalls and web application firewall, network segmentation, intrusion detection and DDoS mitigation.
- Hardened systems, timely security patching and secure configuration baselines.
- Endpoint protection, device encryption and controls on removable media.
6. Secure development
- Secure coding standards and code review, with separation of development, test and production.
- Automated dependency and vulnerability scanning.
- Vulnerability assessment and penetration testing of applications and infrastructure at least annually and after major changes, with tracked remediation.
- Change management with approval and rollback plans.
7. Logging and monitoring
Security-relevant events, administrative actions and API access are logged and monitored with alerting. Logs are protected against tampering and retained for at least 12 months (or longer where required) to support investigations.
8. Incident management
- A documented incident response plan with defined roles, severity levels and communication paths.
- Security incidents are reported to the security lead at once and handled through containment, eradication, recovery and review.
- Where required, we report incidents to CERT-In within 6 hours of noticing certain cyber incidents, to our partner banks and NPCI as their rules require, and to the Data Protection Board and affected individuals for personal data breaches.
- Post-incident reviews feed corrective actions.
9. Business continuity and disaster recovery
We maintain backups, redundancy and a tested disaster recovery plan, with defined recovery time and recovery point objectives for critical payment services. Plans are tested at least annually.
10. Vendor and third-party management
Vendors with access to data or systems are assessed before engagement, bound by contract to security and confidentiality duties, and reviewed periodically. Sub-processors are listed on request.
11. Responsibilities of customers and partners
Partners and merchants must protect their credentials and devices, use certified devices and updated software, keep their API keys secret, report suspected compromise immediately, and comply with the Terms and Conditions and Acceptable Use Policy.
12. Responsible disclosure
If you find a security vulnerability in our Services, please report it to legalteam@laraware.com with details to reproduce it. Please do not access others' data, disrupt services or disclose publicly before we have fixed the issue. We will acknowledge within 2 working days and keep you informed.
13. Compliance and audit
We carry out internal reviews and cooperate with audits by regulators, partner banks and NPCI. Non-compliance by staff may lead to disciplinary action, and by partners to suspension or termination.
Contact us
| Purpose | Contact |
|---|---|
| General and customer support | support@laraware.com |
| Refund and failed transaction queries | refunds@laraware.com |
| Legal, compliance and grievance escalation | legalteam@laraware.com |
| Phone | 0731-4621515 |
| Registered and correspondence address | Laraware Private Limited, B-2/64, Vibhutikhand, Gomtinagar, Lucknow, Uttar Pradesh 226010, India |