Data breaches in India are not rare events. They are background noise.
CERT-In handled 29.44 lakh cybersecurity incidents in 2025, up 44% from 2024.
IBM’s August 2025 report put the average cost of a data breach in India at Rs 22 crore, an all-time high.
CloudSEK projected Rs 20,000 crore in total cybercrime losses for 2025.
The victims are not only banks and tech platforms. 63% of all breaches in 2025 hit small and mid-sized businesses, leaking 352 million records globally. For Indian mid-market companies, the attack surface is compounded by how work actually happens: business decisions moving through WhatsApp, credentials shared across departments, one password unlocking email, ERP and banking portals.
As a small startup handling sensitive client data, our security posture is different, and we seek to adhere to the foundational principles of cybersecurity- CIA (Confidentiality, Integrity, Availability)- while designing our data systems.
What This Post Is (And Is Not)
This post explains the framework Nitisagar uses to handle client data across Vendor Readiness Assessments and subsidy facilitation engagements. It is written for two audiences: clients who want to understand where their data goes, and prospects who want to check that we take this seriously before they send us anything.
Some of what follows is what we do today. Some is what we are building over the next few quarters, with both marked clearly. As we build out and expand our cybersecurity posture, we will keep updating this blog post and our policies.
The full legal terms, including the Privacy Notice, the Client Terms of Service, and the Website Terms of Use, are on the legal page. This post is the readable version.
What Client Data Nitisagar Actually Touches
Nitisagar’s two core service lines each produce a distinct data footprint.
Vendor Readiness Assessment (VRA):
- Entity registration records (CIN, GSTIN, Udyam)
- Financial signals (turnover trends, credit indicators, paid-up capital)
- Statutory compliance extracts (EPFO headcount, GST filing status)
- Facility evidence (site photographs, machine asset registers, calibration records, lease deeds)
- Certificate verification results (ISO, BIS, NABL accreditation status)
- Discrepancy findings (declared vs. verified data, with severity grades)
Subsidy facilitation (IIPA 2019, PMEGP, and related schemes):
- Investment figures (fixed capital investment, plant and machinery value)
- Enterprise classification (Micro/Small/Medium per MSMED Act)
- Sector and location details (district, whether inside a notified park)
- Employment data (headcount, local hiring percentages for eligibility checks)
- SGST payment records for reimbursement claims
- Supporting documents (Eligibility Certificate applications, production commencement proof)
What Nitisagar does not collect:
- Aadhaar numbers or personal bank account details of promoters (unless a scheme form requires them at submission, in which case they are not retained after)
- Passwords, login credentials, or access tokens for any client system
- Client customer data (Nitisagar works with the MSME itself, not its end customers)
Where We Are Today, Where We Are Heading
We want to be upfront about a few facts at this point.
- Indian-data-residency cloud workspace for all client files
- Per-engagement folder structure with named access lists
- MFA on cloud workspace, email, and CRM
- Password manager rolled out to all team members
- Full-disk encryption enforced on every laptop that touches client data
- Ban on WhatsApp and personal email for client data, written into every engagement contract and consultant agreement
- Ban on public AI tools (ChatGPT, Claude, Gemini) touching client data
- Two-reviewer sign-off on every VRA report before issuance
- SHA-256 fingerprinting on issued VRA reports
- Data-handling attestation signed by every FTE and consultant at onboarding
- Formal quarterly training refreshers with attestation (currently ad-hoc)
- Simulated phishing tests twice a year (planned Q4 2026)
- Mobile Device Management on personal devices used for site visits
- Documented incident response playbook with tested notification cascade
- Formal vendor risk review cycle (currently informal)
- Full DPDP compliance workflow including consent format and right-to-erasure (dependent on Board rules being notified)
- Firm-issued devices for site-visit analysts (dependent on scale, currently BYOD with encryption enforced)
The reason to publish this split is simple. Clients deserve to know what we actually do, not a marketing version. If a control is live, we say so. If it is aspirational, we say when we expect to have it.
The Full Data Flow, End to End
Most client engagements usually moves through eight stages. The infographic below shows what is stored at each stage, who has access, and how long the data is retained.
This is the target-state framework; the notes above cover where implementation stands today.
To minimise data breach risks, we collect only the bare-minimum data. Before any client-submitted document enters the engagement folder, the engagement lead reviews it for data the engagement does not need. A subsidy eligibility memo needs the investment amount, the enterprise category, the sector, and the district. It does not need the promoter’s Aadhaar scan or personal bank statements. Excess PII is flagged, the client is asked to resubmit, and the original is deleted.
Working With Word and Excel Safely
Most of Nitisagar’s actual work happens in spreadsheets and documents. Subsidy calculations, eligibility memos, VRA scoring, working notes etc require tools like Excel and Word, and in many use cases, there are no alternatives.
The default: edit in the browser, never on the local disk.
When local editing is unavoidable (complex Excel models with heavy formulas, poor connectivity during a site visit):
- Download the specific file, work on it, upload back, delete the local copy
- Local disk must be encrypted
- No sync to personal OneDrive, iCloud, Google Drive personal account, or Dropbox
- No emailing the file to a personal address “so I can work from home”
Passwords on Word and Excel files are not real security. Office password protection is trivially bypassable and creates a false sense of security. Files are stored in access-controlled engagement folders instead.
Channels That Are Banned
These restrictions are contractual. Violations trigger access revocation.
- WhatsApp, Telegram, Signal, or any personal messaging app. No client data over personal messaging apps. Not “just a quick photo of the document.” Just one screenshot, a forwarded message, a phone backup to a personal cloud folder, and the data goes beyond anyone’s control.
- Personal email accounts. All client communication runs through @nitisagar.com addresses with enforced encryption. If a client sends sensitive documents to a personal email the team member will not download it; the client is redirected to the correct channel.
- Unencrypted email attachments for high-sensitivity files. Financial statements, credit reports, or any file containing PAN, Aadhaar, or bank account numbers is shared only through the cloud workspace’s secure link feature.
- Public AI tools with client data. No client data enters ChatGPT, Claude, Gemini, or any public AI model. If a client-specific analysis would genuinely benefit from AI assistance, the request goes through the engagement lead and only de-identified inputs are used.
People: Training, Credentials, and Devices
Most data breaches are not sophisticated attacks. They start with a person clicking a link, sharing a password, or losing a laptop. Controlling the people layer matters more than any single technical measure.
Training and awareness
Every FTE and consultant signs a data-handling attestation before touching client data. It covers the stripping rule, the banned channels, credential hygiene, and incident reporting.
- Live today: onboarding attestation, ad-hoc briefs when a specific threat pattern emerges (deepfake voice scams, vendor-account compromise)
- Being rolled out: quarterly refreshers with re-attestation, simulated phishing tests twice a year, one-on-one refresher after any failed simulation
Credential management
- MFA required on cloud workspace, CRM, email, and every firm system. No exceptions. Live today.
- Password manager: For individual vaults, rolled out to all team members. Team-shared credentials go through a separate role account with its own audit trail, not a shared password.
- No credential sharing. If a client asks for one login shared across the team, it gets a shared role account with individual attribution, not the actual client’s credentials on a shared spreadsheet
- Session timeout on all firm systems; re-authentication required after inactivity
Devices
Nitisagar does not issue laptops or phones today. Everyone uses their own device. To enforece security, this we require instead:
- Full-disk encryption enforced on every device that touches client data
- Screen lock policy requires automatic lock after five minutes of inactivity
- No personal cloud sync to iCloud, personal OneDrive, personal Google Drive, or Dropbox for anything containing client data
- Lost or stolen device protocol: the person notifies the firm within one hour of realisation. Passwords are changed, and cloud workspace sessions are revoked. If client data was on the device, the affected client is notified within 24 hours
- Aspirational: MDM policy will be rolled out to enrol personal devices used for site visits. Container-based enrolment keeps work data separate from personal content on the same phone
Public AI tools
- No pasting client documents, extracts, or identifying details into ChatGPT, Claude, Gemini, or any other public model
- No uploading client files to browser-based AI assistants
- Approved AI usage is limited to fully de-identified content or public-domain data
Full-Time Employees and Third-Party Consultants
Full-time employees operate under employment terms with confidentiality obligations and the data handling rules described above. They get access to the engagement folders assigned to them, not to the full client roster.
Third-party consultants (like field analysts for VRA site visits) sign a services agreement with a confidentiality clause that survives the engagement.
- Access is restricted to a single engagement folder, granted at assignment start
- Access is revoked immediately upon client acceptance of the final deliverable, not on a delayed schedule
- No access to the CRM, other client folders, or internal commercial data
- Same data-handling requirements as FTEs before first assignment
- Own device with encryption and MFA enforced; MDM enrolment when the aspirational rollout completes
A field analyst conducting a VRA site visit in MOrigaon gets access to that specific engagement’s intake data. The analyst uploads site-visit evidence to that engagement folder. Once the lead analyst and second reviewer sign off, the report is issued, and the client accepts delivery, the consultant’s folder access is revoked in the same working day. The consultant confirms in writing to deletion of any local files.
Offboarding
When an FTE leaves:
- All system access revoked on the exit day, not “within a few days”
- Active engagement handovers completed before the last working day
- Post-departure client queries route through the engagement lead, never directly to the former employee
- Personal-device attestation: former employee confirms deletion of any client data from personal devices
When a consultant finishes an assignment:
- Access revoked immediately upon client acceptance of the deliverable
- Consultant attests in writing to deletion of local files
- No retention of client materials for portfolio, marketing, or reference purposes without explicit written client consent
When a client engagement closes:
- Working files archived within 30 days of engagement close
- Issued deliverables (VRA reports, eligibility memos) retained for the published recheck schedule
- Statutory retention (contracts, invoices) governs the rest
- Client can request early deletion of non-issued working files at any time
Vendor Risk
Nitisagar relies on external systems. Those systems can themselves be potential breach points.
- Cloud workspace and CRM: We use tools with Indian data centres which are also SOC 2 certified. We review them annually for breach history and updated certifications
- Password manager : Open source, indusgtry-standard,third-party audited, zero-knowledge architecture
- Registry lookup providers (GST Suvidha Providers, MCA data services): Review focuses on how they handle the lookup queries themselves, not just the results
- New vendor onboarding: Requires a documented review before any client data touches the vendor’s systems
The Angel One breach in February 2025, where a dark-web monitoring partner’s compromise exposed 8 million users’ data, is a live example of why vendor access matters. Vendors do not need to be careless for their breach to become your breach.
Incident Response
If a breach or near-miss is detected, the process is defined and time-bound.
- Contain: the compromised account, device, or system is isolated within one hour of detection
- Assess: the incident lead determines scope. Which engagements, which clients, what data
- Notify:
- Affected clients within 24 hours of confirmed scope
- CERT-In within 6 hours per the 28 April 2022 directive
- Data Protection Board notifications once the DPDP breach-notification rules are operational
- Remediate: credential rotation, access revocation, forensic imaging
- Post-incident review: documented, shared with affected clients, and used to update policies
Our incident response methodology is not bound in stone: we will review and update it as and when necessary based on our cybersecurity frameworks and principles.
Integrity Controls on Issued Reports
A VRA report, once issued, is never edited. Corrections produce a new version; the previous version is marked superseded. Each report carries:
- A SHA-256 fingerprint registered at issuance. Recompute the hash of the PDF and compare it against the verification page to confirm the file has not been tampered with
- A unique report reference that resolves to a verification URL showing the report’s status: valid, superseded, or withdrawn
- A two-reviewer sign-off: the lead analyst who conducted the fieldwork, and a second reviewer who did not attend the site visit
- A fee-independence disclosure: Nitisagar’s fee does not depend on the assessment outcome
Subsidy facilitation deliverables (eligibility memos, scheme application packages) do not carry SHA-256 verification because they are working documents, not externally relied-upon assessment reports. They carry version numbering and are shared only through the cloud workspace.
How This Compares to Standard CA Firm Practice
The closest comparable in the Indian market to Nitisagar Advisory is a small chartered accountancy firm. Both handle sensitive commercial data. Both work with mostly personal devices. Both are covered by professional confidentiality norms (ICAI’s Code of Ethics for CAs, contractual confidentiality for Nitisagar).
Where standard small CA firm practice differs:
- Client data often moves over WhatsApp and personal email (these servers are usually located outside India)
- Excel files with sensitive data password-protected (which, as noted, is not real security)
- Shared logins on client portals across staff
- Local storage on office computers with informal backups
- Confidentiality by convention rather than technical enforcement
Where Nitisagar is today, compared to that baseline:
- Ban on WhatsApp and personal email is contractual, not aspirational
- Client data in an Indian-data-residency cloud workspace with per-engagement folders and audit trails
- MFA enforced across every system
- No public AI tool usage
- Two-reviewer independence on issued reports
- Cryptographic verification of issued documents
Where we still need to catch up:
- Formal training cadence (many established CA firms do this better)
- Documented incident response with tabletop testing
- Formal MDM enrolment
We will keep modifying our SOPs as and when necessary so that we can deliver highest possible data security standards.
DPDP Act Compliance
India’s Digital Personal Data Protection Act, 2023 sets the legal framework. The Data Protection Board is not yet fully operational, and the implementing rules are still being notified in tranches.
Much of what Nitisagar already does aligns with the DPDP’s core requirements:
- Purpose limitation: data collected only for the stated engagement purpose
- Data minimisation: the stripping rule at Stage 3
- Storage limitation: engagement data archived and deleted after retention windows close
- Consent and notice: clients informed at intake what data is being collected and why
- Security safeguards: the training, credential, and device controls described above
- Breach notification: CERT-In’s six-hour reporting directive is already in force and covered by the incident response process
Still ahead: formalising Data Fiduciary registration once the Board’s process is live, updating consent mechanisms to match the Act’s prescribed format, and implementing the right-to-erasure workflow end to end. The Privacy Notice will be updated as each tranche of DPDP rules is notified.
Additionally, we are also looking to get certified under ISO 27001 standards for information security (while adhering to many of its controls right now).
This Is an Evolving Situation
Data security is not a checklist that gets completed once.
- AI-generated phishing emails are 4.5 times more effective than their predecessors
- Deepfake voice scams are already in circulation in India
- Cloud misconfigurations remain the single most common breach vector for small businesses
- Vendor-account compromise (the Angel One pattern) is a growing share of Indian breaches
Nitisagar reviews its data handling policies quarterly. When a new threat vector becomes real (not theoretical, real, meaning someone has been breached by it), the policies are updated to cover it. When a new regulatory requirement is notified, the workflows are adjusted before the compliance deadline, not after.
Frequently Asked Questions
Can I see exactly what data Nitisagar holds about my company? Yes. Send a written request to hello@nitisagar.com with your engagement reference number. The response will list every data category held, the storage location, and the retention timeline.
Nitisagar does not issue devices. Doesn’t that make things less secure? It changes the shape of the controls. Instead of firm-issued laptops with centralised management, we require full-disk encryption on every device, MFA on every system, and browser-based editing so that most client files never touch the local disk. The aspirational rollout of MDM (Zoho’s ManageEngine MDM Plus free tier) will add device-level enforcement on personal devices used for site visits.
How do you actually work on Excel and Word files then? Default: in the browser. No local file exists. When local editing is unavoidable (heavy Excel models, poor site connectivity), the file is downloaded, edited, uploaded back, and the local copy is deleted. The local disk is encrypted so a lost or stolen laptop does not become a data spill.
Does Nitisagar use ChatGPT or other AI tools on my data? No. Client data does not enter any public AI tool. Approved internal AI usage is limited to de-identified or public-domain content only.
What happens if a Nitisagar team member’s personal laptop or phone is lost or stolen? The person notifies the firm within one hour of realisation. Passwords are rotated and cloud workspace sessions revoked. If client data was on the device, the affected client is notified within 24 hours.
What if a field analyst takes photos on a personal phone during a site visit? Photos upload to the cloud workspace during or immediately after the visit. Local copies are deleted after upload and the analyst confirms the deletion. Personal-account backups (iCloud, Google Photos) must be disabled on the enrolled device. Once MDM enrolment is live, this becomes technically enforced rather than attestation-based.
When does a consultant lose access to my engagement folder? Immediately upon your acceptance of the final deliverable.
How do I verify that a VRA report I received is genuine? Every VRA report includes a verification URL and a SHA-256 fingerprint. Visit the verification page, enter the report reference, and compare the published fingerprint against the hash of the PDF file you hold.
Is my data stored in India? Yes. All client data is stored on cloud infrastructure with data centres in India.
What if I believe my data has been mishandled? Write to hello@nitisagar.com with the engagement reference number. Nitisagar commits to acknowledging receipt within 24 hours and providing a substantive response within 5 business days.
Will these policies change? Yes. Data security is not static. As Nitisagar grows, the aspirational controls become live controls, new threats become new policies, and this post gets updated. The legal page always reflects the current version.
Nitisagar Advisory (OPC) Private Limited is a DPIIT-recognised policy advisory and MSME facilitation firm focused on Northeast India’s electronics and manufacturing ecosystem. The Assam MSME subsidy calculator covers live incentive schemes, and the Vendor Readiness Assessment is available for MSMEs positioning for anchor procurement pipelines.