INFORMATION SECURITY & CYBER COMPLIANCE POLICY
LAST UPDATED: July 24, 2026
OPERATIONAL ENTITY: The Cove & Kin LLP
APPLICATION SCOPE: All Digital Platforms, Progressive Web Applications (PWA), Cloud Infrastructure, Relational Databases, and Network Endpoints
1. PURPOSE AND REGULATORY FRAMEWORK
This Information Security & Cyber Compliance Policy (“Security Policy”) establishes the mandatory technical, organizational, and physical security measures executed by The Cove & Kin LLP (“The Club,” “We,” “Us,” or “Our”) to protect the confidentiality, integrity, availability, and privacy of member data, minor child information, and digital infrastructure.
This Policy is formulated in strict compliance with:
- The Cyber Security Directions issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B of the Information Technology Act, 2000;
- Section 8(5) of the Digital Personal Data Protection (DPDP) Act, 2023 (mandating reasonable security safeguards to prevent personal data breaches);
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; and
- Payment Card Industry Data Security Standard (PCI-DSS SAQ-A) frameworks.
2. TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs) & ENCRYPTION
The Cove & Kin enforces multi-layered defense-in-depth technical and organizational controls across its entire digital ecosystem:
2.1 Encryption in Transit
All network communications, web browser sessions, API calls, and Progressive Web Application (PWA) data exchanges across thecoveandkin.club and associated digital domains are strictly enforced using Transport Layer Security (TLS 1.3) encryption protocols. Unencrypted HTTP traffic is automatically blocked and redirected to secure HTTPS endpoints.
2.2 Encryption at Rest
All relational databases, user profile repositories, dynamic metadata stores, and media storage volumes are secured using enterprise-grade AES-256 equivalent encryption at rest. Cryptographic keys are managed within isolated, hardware-backed key management subsystems with restricted administrative access.
3. INFRASTRUCTURE & DATA LOCALIZATION BOUNDARIES
3.1 Localized Data Hosting
All core application servers, relational database instances, active user tables, and security logging systems are hosted within ISO 27001, SOC 1, and SOC 2 Type II certified enterprise cloud data centers physically located within the Republic of India (Mumbai Data Region).
3.2 Network Isolation & CDN Edge Defenses
Platform infrastructure is protected behind a global Content Delivery Network (CDN) and Web Application Firewall (WAF). Edge nodes inspect incoming traffic, terminate SSL/TLS connections, mitigate Distributed Denial of Service (DDoS) attempts, and filter malicious payloads before traffic reaches Our primary database infrastructure.
4. STATUTORY 180-DAY AUDIT LOGGING & NTP SYNCHRONIZATION
In strict adherence to the CERT-In Cyber Security Directions (2022/2023), The Cove & Kin maintains an automated, immutable audit logging subsystem within its localized database architecture:
- Mandatory Log Scope: The system automatically captures and retains operational logs, including user authentication events (successful and failed logins), administrative privilege changes, password resets, profile updates, ticket QR pass generations, entry scanning check-ins, system errors, and source IP addresses with corresponding HTTP access headers.
- Network Time Protocol (NTP) Synchronization: System clocks across all application servers, database engines, and logging subsystems are continuously synchronized using Network Time Protocol (NTP) servers anchored to Indian Standard Time (IST).
- 180-Day Retention Window: All security, access, and transaction logs are securely stored in an isolated database environment for a mandatory minimum period of one hundred and eighty (180) days, after which they are subjected to automated cryptographic purge routines.
5. PAYMENT SECURITY & PCI-DSS SAQ-A BOUNDARY
The Cove & Kin maintains a zero-cardholder-data footprint on its primary servers:
- Total Payment Tokenization: All membership dues and ticket purchases are processed via Our authorized, PCI-DSS Level 1 compliant payment gateway sub-processor (Razorpay).
- Outsourced Checkout Wrapper: Financial transactions execute inside an encrypted, hosted iframe/modal wrapper served directly from Razorpay’s secure servers.
- Zero Storage: No primary account numbers (PAN), CVVs, expiration dates, or bank credentials ever enter, process through, or store within Our cloud servers or MySQL database. The Club stores exclusively non-sensitive, tokenized transaction identifiers returned via secure webhooks.
6. ACCESS CONTROL, ROLE-BASED ISOLATION & DATA MINIMIZATION
6.1 Least Privilege Access Control
Access to administrative interfaces, backend management systems, and raw database parameters is governed strictly by the Principle of Least Privilege and Role-Based Access Control (RBAC). Standard member and applicant user roles maintain zero access to backend server configurations or administrative endpoints.
6.2 Sensitive Data Isolation
Sensitive personal data points—including child dates of birth, dietary preferences, health allergies, emergency contacts, and household relational pointers—are explicitly excluded from public directory API queries and restricted to authenticated, role-verified internal operations.
7. VULNERABILITY MANAGEMENT, WAF & EDGE PROTECTION
- Web Application Firewall (WAF): Real-time automated inspection rules filter all incoming HTTP requests to prevent SQL Injection (SQLi), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Remote File Inclusion (RFI) attacks.
- Brute-Force & IP Rate-Limiting: Automated threat intelligence modules actively monitor authentication endpoints, automatically rate-limiting and blocking IP addresses exhibiting brute-force credential stuffing behavior or rapid unauthorized requests.
- Sanitization Hooks: All user inputs submitted through web forms, PWA interfaces, or API parameters undergo strict server-side sanitization and validation prior to database execution.
8. CYBER INCIDENT NOTIFICATION PROTOCOL
In the event of a confirmed or suspected cybersecurity incident, unauthorized database access, or personal data breach:
- Immediate Containment: Our technical operations team will immediately isolate affected system components, revoke compromised credentials, and initiate incident analysis.
- 6-Hour CERT-In Reporting: In compliance with statutory CERT-In directions, any covered cyber security incident will be reported to the Indian Computer Emergency Response Team (
incident@cert-in.org.in) within six (6) hours of confirmation or notification. - Data Principal Notification: If a breach involves personal data posing a high risk to the rights or privacy of data principals, The Club will notify affected Members and the Data Protection Board of India in accordance with DPDP Act 2023 regulations.
9. GOVERNING LAW & COMPLIANCE CONTACT
This Security Policy shall be governed by and construed in accordance with the laws of the Republic of India.
For inquiries regarding cybersecurity practices, technical controls, or incident disclosures, please email – support@thecoveandkin.club