ଓଡ଼ିଆ   Translated for convenience. Loan terms and legal documents are in English and prevail. Read this page in English
ଗୁରୁତ୍ୱପୂର୍ଣ୍ଣ ପରିଶୋଧ କେବଳ advancerupay.com କିମ୍ବା AdvanceRupay ଆପ ମାଧ୍ୟମରେ ହିଁ କରନ୍ତୁ। ଆପଣଙ୍କ OTP, UPI PIN କିମ୍ବା ପାସୱାର୍ଡ କେବେ ବି କାହାକୁ ଜଣାନ୍ତୁ ନାହିଁ।
ହୋମ / Policy / IT security policy

IT security policy

How the platform is secured, and what happens if something goes wrong.

advancerupay.com/it-security-policy Last updated 31 July 2026
01

Encryption

All traffic between your device and our systems travels over encrypted channels. Sensitive records are encrypted at rest, and identifiers such as PAN are tokenised or hashed rather than stored in the clear.

02

Access control

Internal access to identity and financial records is limited by role, granted on a need-to-know basis, reviewed periodically and logged. Administrative access requires multi-factor authentication.

03

Logging and audit

Decision inputs, consent records and administrative actions are logged immutably so any application or account change can be reconstructed and audited.

04

Vulnerability management

Dependencies are monitored and patched on a defined cycle, and the platform is subject to periodic security testing. Findings are tracked to closure by severity.

05

Incident response

Suspected incidents follow a documented response process covering containment, assessment, regulatory notification where required, and notification to affected customers. Report a suspected vulnerability to security@advancerupay.com.

06

Business continuity

Data is backed up on a defined schedule with tested restoration, so servicing and repayment can continue through an outage.

07

How your data is protected in transit and at rest

Traffic between your device and our systems is encrypted in transit. Sensitive identifiers are stored as one-way hashes rather than in readable form — a PAN, for example, is tokenised and the raw number is never retained. Bank account numbers are stored masked.

08

Who inside the company can see what

Access is role-limited and granted on the least-privilege principle: support staff see what they need to answer your question and no more, and access to underwriting inputs is restricted to the people making that decision. Access is logged, and the log is reviewed rather than merely retained.

09

When something goes wrong

We maintain an incident response process covering detection, containment, assessment and notification. Where an incident affects your data, we notify affected users and the relevant authority as required, and we say what happened rather than describing it vaguely.

10

How do you vet the services you use?

Verification, payment and communication providers are assessed before integration and are contractually bound on data handling, retention and deletion. A provider cannot use what it processes for us for any purpose of its own.

11

What should I do if I get a suspicious message?

Only repay through advancerupay.com or the AdvanceRupay app, and never share an OTP, UPI PIN or password with anyone — including anyone claiming to be from AdvanceRupay. We will never ask for those. Report the message to us with the number it came from.

କାଗଜପତ୍ର ବିନା ଋଣ

No documentation, disbursal to your own bank account, and every charge disclosed in your Key Fact Statement before you accept.

ଏବେ ଆବେଦନ କରନ୍ତୁ