The following is the authoritative and complete legal policy framework governing ANISH ENTERPRISES. Each policy is written in publication-ready legal prose and includes Purpose, Scope, Definitions, Applicability, User Responsibilities, Company Responsibilities, Security Considerations, Compliance Requirements, Legal Basis, Exceptions, Enforcement, Reporting Procedures, Best Practices, Frequently Asked Questions, and Cross References. Citations link to official Indian legal sources where applicable.
1. Privacy Policy
Purpose: This Privacy Policy describes how ANISH ENTERPRISES ("Company," "we," "us," "our") collects, uses, discloses, stores, transfers, and otherwise processes personal data in connection with its websites, services, products, research activities, and business operations. The policy explains data subject rights and the Company's commitments to lawful, fair, and transparent processing.
Scope: This policy applies to all personal data processed by the Company in India and internationally, including data collected through https://AnishEnterprises.site and other Company-controlled channels, and data processed on behalf of clients within the scope of contractual engagements.
Definitions:
- Personal Data: Any data that identifies or can reasonably be used to identify a natural person.
- Processing: Any operation performed on personal data including collection, storage, retrieval, disclosure, erasure, and analysis.
- Controller: The entity (ANISH ENTERPRISES) that determines purposes and means of processing.
- Processor: Third-party entities that process personal data on behalf of the Company.
Applicability: All employees, contractors, partners, processors, and third parties processing personal data under Company control or on Company instructions.
User Responsibilities: Individuals must provide accurate information and, where required by law, valid consent. Users should exercise their data subject rights (access, correction, deletion, objection) by contacting privacy@AnishEnterprises.site and must cooperate in identity verification procedures before requests are fulfilled.
Company Responsibilities: The Company shall maintain records of processing activities, implement privacy-by-design and by-default principles in product and service design, conduct Data Protection Impact Assessments (DPIAs) where necessary, appoint appropriate data handling personnel, and maintain contractual and technical safeguards with processors.
Security Considerations: Technical measures include TLS for data in transit, AES-based encryption for data at rest where appropriate, RBAC and least-privilege access controls, SIEM-enabled logging, timely patching, endpoint protection, and secure configuration baselines. Organizational measures include access reviews, training, and incident response integration with Privacy and Security teams.
Compliance Requirements: Processing shall conform to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and other applicable Indian laws. Cross-border transfers require a documented assessment and lawful transfer mechanism.
Legal Basis: Lawful bases for processing include contractual necessity, compliance with legal obligations, legitimate interests balanced against data subject rights, and consent when required by law.
Exceptions: Data anonymized in a manner that prevents re-identification may be used for analytics and research. Lawful disclosures to government authorities or courts are exceptions when compelled by law.
Enforcement: Breaches of this policy by employees or contractors may result in disciplinary measures or termination; breaches by processors may result in contract remedies, including termination and indemnities.
Reporting Procedures: Data subject rights requests and privacy queries must be submitted to privacy@AnishEnterprises.site. Suspected breaches should be reported immediately to security@AnishEnterprises.site and will be handled per the Incident Response Policy and applicable statutory timelines.
Best Practices: Minimize collection, retain data only as long as necessary, pseudonymize where feasible, maintain a documented retention schedule, conduct periodic privacy risk assessments, and implement contractual safeguards with third-party processors.
FAQ: How can I request deletion of my personal data? Send a verified request to privacy@AnishEnterprises.site with sufficient identification; the Company will respond within the timelines required by law.
Cross References: Data Protection Policy; Information Security Policy; Cookie Policy; Analytics Policy; Incident Response Policy.
2. Terms of Service
Purpose: These Terms of Service describe the contractual relationship between ANISH ENTERPRISES and users of its website, services, and products. The Terms set out permitted uses, responsibilities, and limitations designed to protect users and the Company.
Scope: Applies to all access to and use of the Company's public web properties, free and paid services, and documentation unless a separate Master Services Agreement or Statement of Work is executed.
Definitions:
- Services: Consulting, security testing, managed services, software, AI/automation products, and research outputs.
- Account: Registered identity associated with access to services.
User Responsibilities: Users must provide accurate account information, safeguard credentials, use services lawfully, and comply with the Acceptable Use Policy and any published Rules of Engagement for security testing.
Company Responsibilities: The Company will provide services with reasonable skill and care in accordance with industry standards, maintain confidentiality obligations, and perform services as set out in applicable agreements.
Security Considerations: Access to production systems is governed by RBAC, MFA, and network segmentation. All security testing requires written authorization and adherence to stated Rules of Engagement.
Compliance Requirements: Service delivery shall respect applicable Indian laws (including the Information Technology Act, 2000) and contractual SLAs. Payment and tax obligations are governed by local tax laws.
Legal Basis: Accessing and using services constitutes acceptance of these Terms; contractual modifications require written agreement by authorized representatives.
Exceptions: Specific enterprise clients may operate under separate negotiated agreements which, where specified, supersede public terms.
Enforcement: The Company reserves rights to suspend or terminate access for breaches, pursue damages, and seek injunctive relief where appropriate.
Reporting Procedures: Legal queries and dispute notices should be sent to legal@AnishEnterprises.site. Billing disputes to billing@AnishEnterprises.site.
Best Practices: Maintain SOWs with clear acceptance criteria, ensure change control documentation, and keep contact and emergency escalation lists current.
FAQ: Do these Terms apply to enterprise customers? Enterprise customers may have separate MSAs; where a conflict exists, the MSA governs.
Cross References: Terms & Conditions; Payment Policy; Limitation of Liability; Indemnification.
3. Terms & Conditions
Purpose: This document sets forth contractual terms and conditions for supply of services and products, including representations, warranties, delivery, acceptance, and remedies.
Scope: Applies to transactions and orders not governed by a separate negotiated contract.
Definitions: Deliverables means outputs described in the SOW; Acceptance refers to the criteria by which Deliverables are validated.
User Responsibilities: Provide timely information and approvals, ensure legal authority over systems for testing, and fulfil payment obligations.
Company Responsibilities: Deliver according to SOW, provide documentation, and remediate defects within agreed warranty periods.
Security Considerations: Include remediation timelines for security findings and support secure transfer and storage of artefacts.
Compliance Requirements: Governed by the Indian Contract Act, 1872 and applicable statutory provisions.
Legal Basis: Contract formation under law; remedies to be determined by contract terms.
Exceptions: Changes to scope must be agreed in writing.
Enforcement: Contractual enforcement, injunctive relief, and damages as permitted by law.
Reporting Procedures: Contract issues to legal@AnishEnterprises.site.
Best Practices: Use SOWs with measurable acceptance criteria and maintain evidence of delivery.
4. Cybersecurity Policy
Purpose: To establish mandatory cybersecurity controls, roles, and responsibilities enabling the Company to protect information assets and provide secure services to clients.
Scope: All Company-managed IT systems, development and production environments, cloud resources, client-managed assets where the Company is contracted, and research infrastructure.
Definitions: Vulnerability, Threat, CVSS (Common Vulnerability Scoring System), SOC (Security Operations Center), and RoE (Rules of Engagement).
Applicability: All employees, contractors, suppliers, and partners.
User Responsibilities: Comply with password policies, use MFA, report suspicious activity, and adhere to access privileges.
Company Responsibilities: Operate a security program aligned to NIST CSF (Identify, Protect, Detect, Respond, Recover), maintain asset inventories, perform vulnerability management, conduct regular penetration testing, and apply security controls in development and operations.
Security Considerations: Technical controls include network segmentation, endpoint protection, secure logging, DLP where appropriate, container security, CI/CD pipeline security, SAST and DAST, and third-party supply-chain security assessments. Development teams must follow OWASP Top 10 mitigations for web applications.
Compliance Requirements: Adhere to CERT-In advisories (CERT-In), applicable provisions of the Information Technology Act, and contractual obligations to clients.
Authorized Security Testing & Rules of Engagement: All security testing requires written authorization. A signed RoE shall specify scope, permitted techniques (e.g., network/host/application tests), permitted windows, safewords, contact information, and acceptable limits. Red team exercises and social engineering require explicit prior consent. Tests must avoid destructive actions unless expressly authorized.
Evidence Collection: Forensically sound evidence collection protocols must be used when recording logs, artifacts, and PoCs; chain-of-custody must be maintained where legal action may ensue.
Risk Classification: Findings are triaged using CVSS scoring and an internal risk matrix to determine remediation priority and SLA tiers.
Enforcement & Exceptions: Non-compliance may result in revocation of privileges, disciplinary measures, or contract termination. Emergency mitigations can be applied prior to written authorization where immediate risk to safety or critical infrastructure is detected, subject to post-action review.
Reporting Procedures: Report incidents and suspected vulnerabilities to security@AnishEnterprises.site. Critical incidents will be escalated to Incident Response and, if required, to CERT-In in accordance with statutory obligations.
Best Practices: Regular patching cadence, periodic third-party audits, continuous monitoring, purple-team exercises, and secure SDLC integration.
FAQ: Can I scan ANISH systems? Only with written authorization as described above; unauthorized scanning may be treated as an attack and result in legal action.
5. Responsible Vulnerability Disclosure Policy
Purpose: To provide a clear and constructive channel for security researchers and users to disclose vulnerabilities affecting Company-managed systems or products so that issues can be remediated safely and promptly.
Scope: This policy covers vulnerabilities affecting Company-owned systems, client systems for which the Company is the authorized receiver, and distributed products/services.
Reporting Requirements: Submit reports to security@AnishEnterprises.site with a concise title, affected asset identifiers, reproduction steps, impact assessment, supporting logs or PoC, and preferred secure contact details. For sensitive submissions, encrypt the message using the published PGP key.
Acknowledgement & Triage: The Company will acknowledge receipt within 72 hours and provide an initial triage classification. We will use CVSS to classify severity and publish remediation timelines consistent with severity.
Safe Harbor: The Company offers safe harbor for individuals acting in good faith who abide by this policy and avoid privacy violations or unnecessary system disruption. Safe harbor does not apply to actions that materially harm individuals or systems or where the researcher acts in bad faith.
Remediation & Disclosure: The Company will coordinate remediation with reporters and, when appropriate, publish coordinated disclosures with credit to the researcher unless anonymity is requested. Public disclosure by reporters before remediation may lead to loss of safe harbor protections.
Legal Basis: Good-faith disclosure under this policy aims to reduce risk and improve security. However, compliance with applicable law (including the Information Technology Act, 2000) is required.
Exceptions & Enforcement: Reports containing PII must be handled securely. Reports that evidence criminal conduct will be referred to law enforcement. Reporters acting in bad faith may be blocked and referred to authorities.
Cross References: Cybersecurity Policy; Penetration Testing Policy; Incident Response Policy.
6. Penetration Testing Policy
Purpose: To establish standards for planning, authorizing, executing, reporting, and remediating penetration tests conducted by or on behalf of ANISH ENTERPRISES.
Scope: All internally executed tests and tests performed for clients under contractual engagement.
Written Authorization & Rules of Engagement: No active testing shall commence without a signed authorization (SOW and RoE). RoE must identify scope, targets, excluded systems, permitted techniques, timing, safewords, and escalation contacts.
Testing Standards: Tests shall follow non-destructive methods unless explicit destructive authorization is provided. Testers must document methods, PoCs limited to demonstrating impact without causing persistence, and collect artifacts per forensic standards.
Reporting: Deliverables include an executive summary, technical findings, CVSS scores, step-by-step reproduction, impact analysis, and prioritized remediation recommendations. Reports will avoid disclosure of PII and sensitive data in public summaries.
Client Responsibilities: Provide valid authorization, backups, and required access; designate emergency contacts and accept risk where production testing is authorized.
Legal Considerations: Tests are lawful only within authorized scope; unauthorized tests may violate the Information Technology Act, 2000 and other laws.
Enforcement: Violations lead to cessation of testing, contractual remedies, and potential legal action.
7. Ethical Hacking Policy
Purpose: To provide ethical standards and procedural safeguards for authorized offensive security activities performed by Company personnel or authorized third parties.
Principles: Authorization, minimal necessary scope, non-disclosure, prioritization of safety, protection of human subjects, and avoidance of collateral impact. Social engineering requires explicit client consent.
Applicability: Security staff, researchers, and contractors authorized to perform simulated attacks.
Reporting & Oversight: Ethical hacking engagements must be overseen by the Information Security Officer and legal counsel; findings reported through secure channels and remediated per severity.
8. Acceptable Use Policy (AUP)
Purpose: To define permitted and prohibited activities on Company systems, networks, and services to protect operational integrity and legal compliance.
Prohibited Activities: Unauthorized access, distribution of malware, infringement, attempted data exfiltration, denial-of-service, unauthorized scanning of third-party systems, and any conduct violating the Information Technology Act, 2000.
Enforcement: Violation may result in access suspension, disciplinary action, and referral to law enforcement.
9. Data Protection Policy
Purpose: To define operational controls for protection of personal and sensitive data including retention, access control, encryption, and processor management.
Key Controls: Data classification; encryption; access management; DPIAs for high-risk processing; contractual clauses with processors; regular audits; and data subject rights handling.
10. Information Security Policy
Purpose: To maintain the confidentiality, integrity, and availability of Company information assets through an ISMS aligned to industry frameworks and regulatory obligations.
Components: Governance, risk assessment, control implementation, monitoring, incident management, business continuity, and training.
11. Artificial Intelligence Policy
Purpose: To govern the responsible development, testing, validation, deployment, and monitoring of AI systems and models developed or used by the Company.
Model Risk Management: Maintain model cards, data provenance records, reproducibility artifacts, bias and fairness assessments, security testing for adversarial robustness, and human oversight for high-risk use-cases.
12. Responsible AI Policy
Purpose: To ensure AI systems are developed and used ethically, transparently, and with due attention to privacy, non-discrimination, and explainability.
Key Commitments: Accountability, transparency, human oversight, privacy protection, fairness testing, and proportionate risk mitigation.
13. Automation Policy
Purpose: To provide governance for safe design, approval, testing, and deployment of automation and orchestration systems.
Controls: Version-controlled automation code, staged deployment, runbook authorizations, emergency rollback provisions, and least privilege for automated agents.
14. Software Development Policy
Purpose: To require secure SDLC practices across development projects including threat modeling, code reviews, automated testing, dependency management, secrets handling, and release controls.
Controls: SAST/DAST integration, dependency vulnerability scanning, code review gates, CI/CD security checks, and reproducible builds.
15. Security Research Policy
Purpose: To define the ethical, legal, and operational parameters for security research undertaken by the Company.
Research Governance: Project approval, ethical review, containment controls, avoidance of unnecessary harm, and responsible publication policies.
16. Bug Reporting Policy
Purpose: Provide procedures for receiving, triaging, and remediating software defects and security issues.
Procedure: Submit to bugs@AnishEnterprises.site or security@AnishEnterprises.site with reproduction steps; the Company will acknowledge and track until resolution.
17. Incident Response Policy
Purpose: To orchestrate a consistent, timely, and effective response to security incidents to minimize impact and restore operations.
Core Elements: Incident identification, containment, eradication, recovery, communication, and post-incident review. Notification to regulators and affected parties will be performed as required by law.
18. Risk Management Policy
Purpose: Define risk assessment, treatment, monitoring, and reporting processes to manage operational, security, legal, and strategic risks.
Process: Maintain a risk register, categorize risks, assign owners, and track mitigations to closure.
19. Client Responsibilities Policy
Purpose: To clarify client duties during engagements, including providing authorization, access, backups, and cooperation needed for safe and effective delivery.
Expectations: Clients must ensure legal authority over systems, provide accurate documentation, and accept residual risk as documented in SOWs.
20. Confidentiality Policy
Purpose: Protect confidential information entrusted to the Company and define permitted uses and disclosure exceptions.
Measures: NDA use, role-based access, encryption, and limited disclosure under legal compulsion with notice where permitted.
21. Non-Disclosure Principles
Purpose: Provide the legal and operational framework for NDAs, including obligations of parties, duration, permitted disclosures, and remedies for breach.
22. Intellectual Property Policy
Purpose: Protect Company IP and ensure correct licensing and assignment of inventions, code, and creative works.
Practices: Maintain inventor records, perform IP clearance, and use contributor license agreements for external contributions.
23. Copyright Policy
Purpose: Process copyright claims, manage takedown requests, and protect copyrighted works in accordance with the Copyright Act, 1957.
24. Trademark Policy
Purpose: Govern use, registration, and enforcement of Company trademarks in compliance with the Trade Marks Act, 1999.
25. Open Source Software Policy
Purpose: Ensure responsible use and contribution to open source projects, including license compliance and security vetting.
Controls: Maintain an OSS inventory, perform license reviews, and require legal approval for public releases.
26. Communication Policy
Purpose: Centralize and govern public communications, press statements, and incident communications to protect confidentiality and reputational interests.
27. Cookie Policy
Purpose: Explain cookie usage on the Company website, distinctions between essential and non-essential cookies, retention, and opt-out mechanisms, consistent with privacy law.
28. Analytics Policy
Purpose: Describe telemetry collection practices, minimization, anonymization, and retention for product and website analytics.
29. External Links Policy
Purpose: Explain responsibilities and disclaimers for third-party links published by the Company.
30. Payment Policy
Purpose: Set billing, invoice, payment methods, and security requirements for handling payment instruments without retaining raw card data unless PCI-DSS compliant processors are used.
31. Refund Policy
Purpose: Define eligibility and processes for refund requests in accordance with contractual terms and consumer protection laws.
32. Cancellation Policy
Purpose: Describe termination and cancellation rights, notice periods, and any applicable fees.
33. Service Availability Policy
Purpose: State target availability commitments and maintenance notification procedures; specific SLAs are defined in client SOWs.
34. Accessibility Statement
Purpose: Affirm commitment to web accessibility and outline reporting and remediation processes for accessibility barriers.
35. Children's Privacy Policy
Purpose: Establish protections and parental consent requirements when the Company processes data of minors, consistent with applicable law.
36. Export Control Statement
Purpose: Describe export control obligations for software, cryptography, and technical assistance and require classification and licensing where necessary.
37. Sanctions Compliance Statement
Purpose: Commit to screening customers and partners against sanctions lists and refusing service where required by law.
38. Limitation of Liability
Purpose: Define caps, exclusions, and the allocation of risks between the Company and counterparties in accordance with contract law and statutory limits.
39. Disclaimer
Purpose: Disclaim warranties except as expressly stated in contractual agreements.
40. Indemnification
Purpose: Allocate defense and indemnity obligations for claims arising from breach, negligence, or third-party claims as per negotiated contract terms.
41. Force Majeure
Purpose: Define relief from performance obligations for events beyond reasonable control, the notification process, and remedies.
42. Termination & Suspension Policy
Purpose: Describe grounds for termination or suspension, notice periods, and data handling upon termination.
43. Governing Law & Jurisdiction
Purpose: Specify the applicable law and dispute resolution forum for agreements with the Company. Unless otherwise agreed, contracts shall be governed by the laws of India and subject to the exclusive jurisdiction of courts in Bihar (or as otherwise specified in the contract).
44. Policy Updates
Purpose: Describe the cadence, governance, and notification process for policy amendments. Material changes will be published with effective dates and notice to stakeholders.
45. Contact Information
Legal: legal@AnishEnterprises.site
Privacy: privacy@AnishEnterprises.site
Security: security@AnishEnterprises.site
Billing: billing@AnishEnterprises.site
AI Governance: ai-governance@AnishEnterprises.site
References: Information Technology Act, 2000 (https://www.indiacode.nic.in/); Digital Personal Data Protection Act, 2023 (https://www.meity.gov.in/); Copyright Act, 1957 (https://copyright.gov.in/); Trade Marks Act, 1999 (https://ipindia.gov.in/); CERT-In (https://www.cert-in.org.in/); OWASP (https://owasp.org/); NIST Cybersecurity Framework (https://www.nist.gov/cyberframework).