Company

How Nitisagar Handles Your Data

An account of how Nitisagar Advisory handles client data today, what we are building next, and why a scrappy startup can still be more disciplined about this than most firms handling comparable information.

NA
Nitisagar Advisory
14 August 2026
Data SecurityDPDPPrivacy
image depicting Nitisagar's data privacy model, DPDP Act

Data breaches in India are not rare events. They are background noise.

CERT-In handled 29.44 lakh cybersecurity incidents in 2025, up 44% from 2024.

IBM’s August 2025 report put the average cost of a data breach in India at Rs 22 crore, an all-time high.

CloudSEK projected Rs 20,000 crore in total cybercrime losses for 2025.

The victims are not only banks and tech platforms. 63% of all breaches in 2025 hit small and mid-sized businesses, leaking 352 million records globally. For Indian mid-market companies, the attack surface is compounded by how work actually happens: business decisions moving through WhatsApp, credentials shared across departments, one password unlocking email, ERP and banking portals.

29.44 lakh
cybersecurity incidents handled by CERT-In in 2025, averaging over 8,000 per day, up 44% from 2024.

As a small startup handling sensitive client data, our security posture is different, and we seek to adhere to the foundational principles of cybersecurity- CIA (Confidentiality, Integrity, Availability)- while designing our data systems.

What This Post Is (And Is Not)

This post explains the framework Nitisagar uses to handle client data across Vendor Readiness Assessments and subsidy facilitation engagements. It is written for two audiences: clients who want to understand where their data goes, and prospects who want to check that we take this seriously before they send us anything.

Some of what follows is what we do today. Some is what we are building over the next few quarters, with both marked clearly. As we build out and expand our cybersecurity posture, we will keep updating this blog post and our policies.

The full legal terms, including the Privacy Notice, the Client Terms of Service, and the Website Terms of Use, are on the legal page. This post is the readable version.

What Client Data Nitisagar Actually Touches

Nitisagar’s two core service lines each produce a distinct data footprint.

Vendor Readiness Assessment (VRA):

Subsidy facilitation (IIPA 2019, PMEGP, and related schemes):

What Nitisagar does not collect:

Where We Are Today, Where We Are Heading

We want to be upfront about a few facts at this point.

Live today
  • Indian-data-residency cloud workspace for all client files
  • Per-engagement folder structure with named access lists
  • MFA on cloud workspace, email, and CRM
  • Password manager rolled out to all team members
  • Full-disk encryption enforced on every laptop that touches client data
  • Ban on WhatsApp and personal email for client data, written into every engagement contract and consultant agreement
  • Ban on public AI tools (ChatGPT, Claude, Gemini) touching client data
  • Two-reviewer sign-off on every VRA report before issuance
  • SHA-256 fingerprinting on issued VRA reports
  • Data-handling attestation signed by every FTE and consultant at onboarding
Aspirational, being rolled out over the next quarters
  • Formal quarterly training refreshers with attestation (currently ad-hoc)
  • Simulated phishing tests twice a year (planned Q4 2026)
  • Mobile Device Management on personal devices used for site visits
  • Documented incident response playbook with tested notification cascade
  • Formal vendor risk review cycle (currently informal)
  • Full DPDP compliance workflow including consent format and right-to-erasure (dependent on Board rules being notified)
  • Firm-issued devices for site-visit analysts (dependent on scale, currently BYOD with encryption enforced)

The reason to publish this split is simple. Clients deserve to know what we actually do, not a marketing version. If a control is live, we say so. If it is aspirational, we say when we expect to have it.

The Full Data Flow, End to End

Most client engagements usually moves through eight stages. The infographic below shows what is stored at each stage, who has access, and how long the data is retained.

This is the target-state framework; the notes above cover where implementation stands today.

Eight-stage data flow diagram showing how client information moves through Nitisagar's engagement lifecycle from inquiry to archive

To minimise data breach risks, we collect only the bare-minimum data. Before any client-submitted document enters the engagement folder, the engagement lead reviews it for data the engagement does not need. A subsidy eligibility memo needs the investment amount, the enterprise category, the sector, and the district. It does not need the promoter’s Aadhaar scan or personal bank statements. Excess PII is flagged, the client is asked to resubmit, and the original is deleted.

Working With Word and Excel Safely

Most of Nitisagar’s actual work happens in spreadsheets and documents. Subsidy calculations, eligibility memos, VRA scoring, working notes etc require tools like Excel and Word, and in many use cases, there are no alternatives.

The default: edit in the browser, never on the local disk.

When local editing is unavoidable (complex Excel models with heavy formulas, poor connectivity during a site visit):

Passwords on Word and Excel files are not real security. Office password protection is trivially bypassable and creates a false sense of security. Files are stored in access-controlled engagement folders instead.

Channels That Are Banned

Hard rules, written into every contract

These restrictions are contractual. Violations trigger access revocation.

People: Training, Credentials, and Devices

Most data breaches are not sophisticated attacks. They start with a person clicking a link, sharing a password, or losing a laptop. Controlling the people layer matters more than any single technical measure.

Training and awareness

Every FTE and consultant signs a data-handling attestation before touching client data. It covers the stripping rule, the banned channels, credential hygiene, and incident reporting.

Credential management

Devices

Nitisagar does not issue laptops or phones today. Everyone uses their own device. To enforece security, this we require instead:

Public AI tools

Full-Time Employees and Third-Party Consultants

Full-time employees operate under employment terms with confidentiality obligations and the data handling rules described above. They get access to the engagement folders assigned to them, not to the full client roster.

Third-party consultants (like field analysts for VRA site visits) sign a services agreement with a confidentiality clause that survives the engagement.

How this works in practice

A field analyst conducting a VRA site visit in MOrigaon gets access to that specific engagement’s intake data. The analyst uploads site-visit evidence to that engagement folder. Once the lead analyst and second reviewer sign off, the report is issued, and the client accepts delivery, the consultant’s folder access is revoked in the same working day. The consultant confirms in writing to deletion of any local files.

Offboarding

When an FTE leaves:

When a consultant finishes an assignment:

When a client engagement closes:

Vendor Risk

Nitisagar relies on external systems. Those systems can themselves be potential breach points.

The Angel One breach in February 2025, where a dark-web monitoring partner’s compromise exposed 8 million users’ data, is a live example of why vendor access matters. Vendors do not need to be careless for their breach to become your breach.

Incident Response

If a breach or near-miss is detected, the process is defined and time-bound.

Our incident response methodology is not bound in stone: we will review and update it as and when necessary based on our cybersecurity frameworks and principles.

Integrity Controls on Issued Reports

A VRA report, once issued, is never edited. Corrections produce a new version; the previous version is marked superseded. Each report carries:

Subsidy facilitation deliverables (eligibility memos, scheme application packages) do not carry SHA-256 verification because they are working documents, not externally relied-upon assessment reports. They carry version numbering and are shared only through the cloud workspace.

How This Compares to Standard CA Firm Practice

The closest comparable in the Indian market to Nitisagar Advisory is a small chartered accountancy firm. Both handle sensitive commercial data. Both work with mostly personal devices. Both are covered by professional confidentiality norms (ICAI’s Code of Ethics for CAs, contractual confidentiality for Nitisagar).

Where standard small CA firm practice differs:

Where Nitisagar is today, compared to that baseline:

Where we still need to catch up:

We will keep modifying our SOPs as and when necessary so that we can deliver highest possible data security standards.

DPDP Act Compliance

India’s Digital Personal Data Protection Act, 2023 sets the legal framework. The Data Protection Board is not yet fully operational, and the implementing rules are still being notified in tranches.

Much of what Nitisagar already does aligns with the DPDP’s core requirements:

Still ahead: formalising Data Fiduciary registration once the Board’s process is live, updating consent mechanisms to match the Act’s prescribed format, and implementing the right-to-erasure workflow end to end. The Privacy Notice will be updated as each tranche of DPDP rules is notified.

Additionally, we are also looking to get certified under ISO 27001 standards for information security (while adhering to many of its controls right now).

This Is an Evolving Situation

Data security is not a checklist that gets completed once.

Nitisagar reviews its data handling policies quarterly. When a new threat vector becomes real (not theoretical, real, meaning someone has been breached by it), the policies are updated to cover it. When a new regulatory requirement is notified, the workflows are adjusted before the compliance deadline, not after.

Frequently Asked Questions

Can I see exactly what data Nitisagar holds about my company? Yes. Send a written request to hello@nitisagar.com with your engagement reference number. The response will list every data category held, the storage location, and the retention timeline.

Nitisagar does not issue devices. Doesn’t that make things less secure? It changes the shape of the controls. Instead of firm-issued laptops with centralised management, we require full-disk encryption on every device, MFA on every system, and browser-based editing so that most client files never touch the local disk. The aspirational rollout of MDM (Zoho’s ManageEngine MDM Plus free tier) will add device-level enforcement on personal devices used for site visits.

How do you actually work on Excel and Word files then? Default: in the browser. No local file exists. When local editing is unavoidable (heavy Excel models, poor site connectivity), the file is downloaded, edited, uploaded back, and the local copy is deleted. The local disk is encrypted so a lost or stolen laptop does not become a data spill.

Does Nitisagar use ChatGPT or other AI tools on my data? No. Client data does not enter any public AI tool. Approved internal AI usage is limited to de-identified or public-domain content only.

What happens if a Nitisagar team member’s personal laptop or phone is lost or stolen? The person notifies the firm within one hour of realisation. Passwords are rotated and cloud workspace sessions revoked. If client data was on the device, the affected client is notified within 24 hours.

What if a field analyst takes photos on a personal phone during a site visit? Photos upload to the cloud workspace during or immediately after the visit. Local copies are deleted after upload and the analyst confirms the deletion. Personal-account backups (iCloud, Google Photos) must be disabled on the enrolled device. Once MDM enrolment is live, this becomes technically enforced rather than attestation-based.

When does a consultant lose access to my engagement folder? Immediately upon your acceptance of the final deliverable.

How do I verify that a VRA report I received is genuine? Every VRA report includes a verification URL and a SHA-256 fingerprint. Visit the verification page, enter the report reference, and compare the published fingerprint against the hash of the PDF file you hold.

Is my data stored in India? Yes. All client data is stored on cloud infrastructure with data centres in India.

What if I believe my data has been mishandled? Write to hello@nitisagar.com with the engagement reference number. Nitisagar commits to acknowledging receipt within 24 hours and providing a substantive response within 5 business days.

Will these policies change? Yes. Data security is not static. As Nitisagar grows, the aspirational controls become live controls, new threats become new policies, and this post gets updated. The legal page always reflects the current version.


Nitisagar Advisory (OPC) Private Limited is a DPIIT-recognised policy advisory and MSME facilitation firm focused on Northeast India’s electronics and manufacturing ecosystem. The Assam MSME subsidy calculator covers live incentive schemes, and the Vendor Readiness Assessment is available for MSMEs positioning for anchor procurement pipelines.

Don't miss policy updates

Get the latest intelligence on industrial schemes, subsidy disbursements, and policy shifts across Northeast India, delivered to your inbox.

Original industrial intelligence on Northeast India. We don't sell or share your address.

Related content
Ready to claim what's yours?

We'll map your project against UNNATI 2024 and Assam's incentive stack, complimentary, no commitment.

Get a Free Pre-Assessment