Security Policy

Last Updated: April 9, 2026

Security First: At JIEM India - NIHOんDIA, we take the security of your personal information and our systems seriously. This policy outlines our security measures and your role in maintaining a secure environment.

1. Our Security Commitment

We are committed to protecting:

  • Your personal and financial information
  • Course materials and intellectual property
  • Student academic records and progress data
  • System infrastructure and availability
  • Communication channels and user accounts

2. Technical Security Measures

2.1 Data Encryption

  • In Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3
  • At Rest: Sensitive data is encrypted using AES-256 encryption
  • Payment Information: PCI-DSS compliant encryption for all payment data
  • Passwords: Stored using bcrypt hashing with salt

2.2 Network Security

  • Enterprise-grade firewall protection
  • Intrusion detection and prevention systems (IDS/IPS)
  • DDoS protection and mitigation
  • Regular network security audits
  • Segmented network architecture

2.3 Application Security

  • Regular security code reviews
  • Automated vulnerability scanning
  • Web Application Firewall (WAF)
  • SQL injection and XSS prevention
  • CSRF token protection

2.4 Infrastructure Security

  • Secure cloud hosting with redundancy
  • Regular backup with encryption
  • Disaster recovery procedures
  • Physical security at data centers
  • 24/7 system monitoring

3. Access Control

3.1 User Authentication

  • Strong password requirements (minimum 8 characters, mixed case, numbers, symbols)
  • Multi-factor authentication (MFA) available
  • Account lockout after failed login attempts
  • Session timeout for inactive accounts
  • Password reset via verified email only

3.2 Staff Access

  • Role-based access control (RBAC)
  • Principle of least privilege
  • Access logging and monitoring
  • Regular access reviews
  • Immediate revocation upon termination

4. Data Protection

4.1 Personal Data

  • Collected and stored according to Privacy Policy
  • Access limited to authorized personnel only
  • Regular data audits and cleanup
  • Secure deletion procedures

4.2 Payment Security

  • PCI-DSS Level 1 compliant payment processing
  • We do not store complete credit card numbers
  • Tokenization for recurring payments
  • Secure payment gateway integration
  • Transaction monitoring for fraud detection

4.3 Backup and Recovery

  • Daily automated encrypted backups
  • Geographically distributed backup storage
  • Regular recovery testing
  • 30-day backup retention
  • Disaster recovery plan with 24-hour RPO

5. Security Monitoring

We maintain continuous security monitoring:

  • 24/7 automated security monitoring
  • Real-time threat detection and alerts
  • Log aggregation and analysis
  • Anomaly detection systems
  • Regular security incident reviews

6. Third-Party Security

We carefully vet all third-party service providers:

  • Security assessment before engagement
  • Data processing agreements with security clauses
  • Regular vendor security reviews
  • Limited data sharing with third parties
  • Compliance with international security standards

7. Employee Security

7.1 Training

  • Mandatory security awareness training for all staff
  • Regular phishing simulation exercises
  • Data handling and privacy training
  • Incident response training

7.2 Policies

  • Signed confidentiality agreements
  • Clear desk and clear screen policies
  • Acceptable use policies
  • Bring Your Own Device (BYOD) security requirements

8. Incident Response

In case of a security incident:

  1. Detection: Automated systems and manual monitoring identify incidents
  2. Assessment: Security team evaluates severity and impact
  3. Containment: Immediate actions to limit damage
  4. Investigation: Root cause analysis
  5. Notification: Affected users notified within 72 hours (if required by law)
  6. Remediation: Vulnerabilities patched and systems restored
  7. Review: Post-incident review and improvements

9. Your Security Responsibilities

Help us keep your account secure:

9.1 Password Security

  • Use a strong, unique password
  • Never share your password with anyone
  • Change your password regularly
  • Enable multi-factor authentication
  • Use a password manager

9.2 Device Security

  • Keep your device operating system updated
  • Install and maintain antivirus software
  • Use secure Wi-Fi connections (avoid public Wi-Fi for sensitive transactions)
  • Log out of your account when finished
  • Don't use shared computers for accessing your account

9.3 Suspicious Activity

Report immediately if you notice:

  • Unauthorized access to your account
  • Suspicious emails claiming to be from us
  • Unexpected password reset requests
  • Unusual account activity
  • Phishing attempts

10. Compliance and Certifications

We maintain compliance with:

  • ISO 27001: Information Security Management System
  • PCI-DSS: Payment Card Industry Data Security Standard
  • GDPR: General Data Protection Regulation (for EU students)
  • Indian IT Act: Information Technology Act, 2000

11. Reporting Security Issues

If you discover a security vulnerability:

  • Do not exploit the vulnerability
  • Do not publicly disclose the issue
  • Do report it immediately to security-nihondia@jiem.in
  • Include detailed information about the vulnerability
  • We will acknowledge receipt within 24 hours
  • We may offer a reward for responsible disclosure

12. Updates to This Policy

We review and update this Security Policy regularly to reflect:

  • Changes in technology and security practices
  • New regulations and compliance requirements
  • Lessons learned from security incidents
  • Industry best practices

13. Contact Security Team

For security-related concerns or questions:

Security Team

📧 General Security: security-nihondia@jiem.in

🔒 Vulnerability Reports: security-nihondia@jiem.in

📞 Security Hotline: +91 7719003131

📍 Address: Office No: 215, City Point, Boat Club Road, Bund Garden, Sangamvadi, Pune, Maharashtra 411001, India

⚠️ For urgent security issues, call immediately

Security Audit: Our systems undergo quarterly independent security audits by certified third-party security firms. Last audit completed: March 2026. No critical vulnerabilities found.

Chat with us on WhatsApp