Does FinBox have an information security policy and procedure? Yes, FinBox is ISO 27001 certified.
How often does FinBox perform VAPT?VAPT is performed by a CERT-IN empanelled vendor annually. VA scans are done every quarter by a CERT-IN empanelled vendor.
What are the encryption mechanisms used by FinBox?FinBox uses AES 256-bit DAR (data-at-rest) encryption. For data-in-transit, FinBox uses Transport Layer Security (TLS).
Does FinBox have a Change Management/SDLC Policy?Yes, FinBox does have a Change Management Policy, which contains details about procedures for any change in FinBox's information systems, environment, and services.
Does FinBox have a patch management policy?Yes, FinBox does have a Vulnerability Assessment and Patch Management Policy. VA scans are done quarterly, and yearly patch testing is done by a CERT-IN empanelled entity.
Does FinBox have an incident management policy and procedure? Yes, FinBox does have an Incident Management Policy that lays out a comprehensive ‘roles and responsibilities’ matrix.
Does FinBox have a physical security policy and procedure?FinBox does have a policy for physical and environmental security that contains details about secure areas and equipment usage.
Does FinBox have third-party vendor risk management procedures?Yes, FinBox does have a policy for third-party vendors that lays out risk management procedures.
Does FinBox have an Enterprise/Operational Risk Management Policy?Yes, FinBox has a defined risk assessment and treatment methodology. We perform risk assessment at periodic intervals and maintain details in a risk register.
Does FinBox conduct background checks of its employees?Yes, FinBox conducts thorough background checks to verify identity, criminal records (if any), and previous employment.