Security Policy
Last Updated: April 9, 2026
Security First: At JIEM India - NIHOんDIA, we take the security of your personal information and our systems seriously. This policy outlines our security measures and your role in maintaining a secure environment.
1. Our Security Commitment
We are committed to protecting:
- Your personal and financial information
- Course materials and intellectual property
- Student academic records and progress data
- System infrastructure and availability
- Communication channels and user accounts
2. Technical Security Measures
2.1 Data Encryption
- In Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3
- At Rest: Sensitive data is encrypted using AES-256 encryption
- Payment Information: PCI-DSS compliant encryption for all payment data
- Passwords: Stored using bcrypt hashing with salt
2.2 Network Security
- Enterprise-grade firewall protection
- Intrusion detection and prevention systems (IDS/IPS)
- DDoS protection and mitigation
- Regular network security audits
- Segmented network architecture
2.3 Application Security
- Regular security code reviews
- Automated vulnerability scanning
- Web Application Firewall (WAF)
- SQL injection and XSS prevention
- CSRF token protection
2.4 Infrastructure Security
- Secure cloud hosting with redundancy
- Regular backup with encryption
- Disaster recovery procedures
- Physical security at data centers
- 24/7 system monitoring
3. Access Control
3.1 User Authentication
- Strong password requirements (minimum 8 characters, mixed case, numbers, symbols)
- Multi-factor authentication (MFA) available
- Account lockout after failed login attempts
- Session timeout for inactive accounts
- Password reset via verified email only
3.2 Staff Access
- Role-based access control (RBAC)
- Principle of least privilege
- Access logging and monitoring
- Regular access reviews
- Immediate revocation upon termination
4. Data Protection
4.1 Personal Data
- Collected and stored according to Privacy Policy
- Access limited to authorized personnel only
- Regular data audits and cleanup
- Secure deletion procedures
4.2 Payment Security
- PCI-DSS Level 1 compliant payment processing
- We do not store complete credit card numbers
- Tokenization for recurring payments
- Secure payment gateway integration
- Transaction monitoring for fraud detection
4.3 Backup and Recovery
- Daily automated encrypted backups
- Geographically distributed backup storage
- Regular recovery testing
- 30-day backup retention
- Disaster recovery plan with 24-hour RPO
5. Security Monitoring
We maintain continuous security monitoring:
- 24/7 automated security monitoring
- Real-time threat detection and alerts
- Log aggregation and analysis
- Anomaly detection systems
- Regular security incident reviews
6. Third-Party Security
We carefully vet all third-party service providers:
- Security assessment before engagement
- Data processing agreements with security clauses
- Regular vendor security reviews
- Limited data sharing with third parties
- Compliance with international security standards
7. Employee Security
7.1 Training
- Mandatory security awareness training for all staff
- Regular phishing simulation exercises
- Data handling and privacy training
- Incident response training
7.2 Policies
- Signed confidentiality agreements
- Clear desk and clear screen policies
- Acceptable use policies
- Bring Your Own Device (BYOD) security requirements
8. Incident Response
In case of a security incident:
- Detection: Automated systems and manual monitoring identify incidents
- Assessment: Security team evaluates severity and impact
- Containment: Immediate actions to limit damage
- Investigation: Root cause analysis
- Notification: Affected users notified within 72 hours (if required by law)
- Remediation: Vulnerabilities patched and systems restored
- Review: Post-incident review and improvements
9. Your Security Responsibilities
Help us keep your account secure:
9.1 Password Security
- Use a strong, unique password
- Never share your password with anyone
- Change your password regularly
- Enable multi-factor authentication
- Use a password manager
9.2 Device Security
- Keep your device operating system updated
- Install and maintain antivirus software
- Use secure Wi-Fi connections (avoid public Wi-Fi for sensitive transactions)
- Log out of your account when finished
- Don't use shared computers for accessing your account
9.3 Suspicious Activity
Report immediately if you notice:
- Unauthorized access to your account
- Suspicious emails claiming to be from us
- Unexpected password reset requests
- Unusual account activity
- Phishing attempts
10. Compliance and Certifications
We maintain compliance with:
- ISO 27001: Information Security Management System
- PCI-DSS: Payment Card Industry Data Security Standard
- GDPR: General Data Protection Regulation (for EU students)
- Indian IT Act: Information Technology Act, 2000
11. Reporting Security Issues
If you discover a security vulnerability:
- Do not exploit the vulnerability
- Do not publicly disclose the issue
- Do report it immediately to security-nihondia@jiem.in
- Include detailed information about the vulnerability
- We will acknowledge receipt within 24 hours
- We may offer a reward for responsible disclosure
12. Updates to This Policy
We review and update this Security Policy regularly to reflect:
- Changes in technology and security practices
- New regulations and compliance requirements
- Lessons learned from security incidents
- Industry best practices
13. Contact Security Team
For security-related concerns or questions:
Security Team
📧 General Security: security-nihondia@jiem.in
🔒 Vulnerability Reports: security-nihondia@jiem.in
📞 Security Hotline: +91 7719003131
📍 Address: Office No: 215, City Point, Boat Club Road, Bund Garden, Sangamvadi, Pune, Maharashtra 411001, India
⚠️ For urgent security issues, call immediately
Security Audit: Our systems undergo quarterly independent security audits by certified third-party security firms. Last audit completed: March 2026. No critical vulnerabilities found.