Scope and responsibility
This public policy summarises IYEC's security approach for systems, personnel, vendors, and data under our control. Detailed configurations, credentials, vulnerability information, and internal response playbooks are confidential for safety.
Security controls
- Role-based and least-privilege access, unique administrator accounts, and periodic access review.
- TLS encryption in transit, secure password hashing, session protections, input validation, rate limiting, and security headers.
- Restricted upload types and locations, malware and integrity checks where available, and separation of public from sensitive documents.
- Logging, backups, patching, dependency review, change control, and recovery procedures proportionate to risk.
- Contractual confidentiality and security requirements for personnel and vendors with access.
- Extra care for identity, tax, bank, payment proof, and company documents.
Payment security
Online card and UPI interfaces are provided by payment processors such as Razorpay. IYEC does not intentionally receive or store full card numbers, PINs, CVV values, or bank-login passwords. Users must never send those details by email, WhatsApp, uploads, or support tickets.
Incident response
We assess suspected incidents, contain access, preserve evidence, remediate causes, and notify affected people and authorities when required. Notification timing and content depend on verified risk and applicable law. Reports may be sent to contact@iyec.in with the subject "Security Incident".
User responsibilities and reporting
Use a unique strong password, protect OTPs, sign out from shared devices, verify payment pages, and report suspicious messages. Do not test, scan, or exploit systems without written permission. Good-faith vulnerability reports should include reproducible details and avoid privacy violations, disruption, persistence, social engineering, or public disclosure before remediation.
No absolute guarantee
Security risk cannot be eliminated completely. This policy is a commitment to reasonable safeguards, not a warranty that incidents will never occur. We review controls as services, threats, and legal requirements change.
Contact and legal notices
Indian Youth Entrepreneurship Council Foundation
CIN: U85500UP2026NPL247715
Registered office: C/O Anita, Kanakpur, Mayabazar, Faizabad, Uttar Pradesh 224161, India
Email: contact@iyec.in
Toll-free: 1800 309 8565
Website: iyec.in
When contacting us about an account, payment, privacy request, complaint, or legal notice, include enough information to identify the relevant transaction or account. Do not send passwords or full payment-card details.