1. Governance
The portal policy version identifies MoniSa as the responsible company and routes data-protection questions to privacy@monisaenterprise.com and security reports to security@monisaenterprise.com. Formal owners, provider reviews and access reviews are programme actions; evidence should be recorded as each action is completed.
2. Safeguards
Controls evidenced for this portal release include HTTPS in transit, password hashing, server-side validation, parameterised account and profile writes, private authorised CV delivery with PDF safety checks, versioned policy-acceptance records, security response headers, and recoverable file deployment backups. Role-based least privilege review, security-log governance, recovery testing, incident response exercises, confidentiality controls and provider oversight remain programme requirements and are not represented as completed or certified.
Safeguards should be adjusted to the sensitivity, volume, context and risk of the processing.
3. Regulatory alignment
The control programme is designed around the Digital Personal Data Protection Act, 2023 and the staged Digital Personal Data Protection Rules, 2025; the Information Technology Act and applicable security rules; CERT-In cyber-incident directions; and, where applicable, the GDPR/UK GDPR. The operational provisions of the Indian Rules have staged commencement dates, so MoniSa is implementing the notice, security, rights and provider controls in advance rather than claiming a certification.
4. Limits of this statement
This page describes controls; it is not a certification, penetration-test report or guarantee that incidents cannot occur. Security details that would increase risk are not published. Customers may request appropriate due-diligence information under confidentiality.