Security Disclosure
Treasatech Global Private Limited
Effective Date: 17 September 2026 · Last Updated: 17 September 2026 · Version: 1.0
1. Introduction
Treasatech Global Private Limited (“Treasatech Global”, “Treasatech”, “we”, “us”, or “our”) recognises the importance of security in the design, development, deployment, and operation of enterprise financial technology.
Our technology is designed for institutional environments where security, controlled access, auditability, operational resilience, and accountability are important considerations.
This Security Disclosure explains our general approach to security, how security concerns can be reported to us, and the information we request when reporting a potential security vulnerability.
This disclosure applies primarily to the Treasatech Global public website and publicly accessible digital services unless a separate security agreement or customer contract applies.
2. Our Security Approach
Security is treated as an architectural and operational consideration rather than as an isolated feature.
Treasatech Global’s technology philosophy includes:
- Secure by design;
- Controlled access;
- Identity and entitlement management;
- Separation of customer and product data;
- Auditability;
- Controlled integrations;
- Operational resilience;
- Monitoring and logging;
- Secure development practices; and
- Accountability for controlled actions.
The specific security controls applicable to a particular TreasuryFlow deployment may vary depending on the deployment model, customer requirements, architecture, contractual commitments, regulatory requirements, and operating environment.
3. TreasuryFlow Platform Security
TreasuryFlow OS provides the underlying enterprise platform layer for TreasuryFlow applications.
The platform architecture is designed around capabilities such as:
- Identity and access;
- Tenancy and organisational boundaries;
- Entitlement management;
- Controlled navigation;
- Integration and connectivity;
- Auditability;
- Platform administration; and
- Security controls.
TreasuryFlow 360 and TreasuryFlow GlobNos remain independent commercial applications with their own business-domain functionality and data boundaries.
The platform does not require the public website to expose customer operational or financial information.
4. Access Control
Treasatech Global uses access-control mechanisms appropriate to the systems and services involved.
Depending on the relevant environment, these may include:
- Authentication;
- Authorisation;
- Role-based access;
- Entitlement-based access;
- Administrative controls;
- Session controls; and
- Other appropriate security mechanisms.
Access to information and functionality is intended to be limited according to applicable roles, permissions, organisational context, and business requirements.
5. Data Protection
Treasatech Global applies reasonable technical and organisational measures to protect personal data and other information processed through its systems.
Depending on the relevant system, safeguards may include:
- Access controls;
- Authentication and authorisation;
- Secure development practices;
- Security monitoring;
- Logging;
- Vulnerability management;
- Backup and recovery procedures;
- Incident response procedures;
- Personnel controls; and
- Third-party and service-provider controls.
The processing of personal data is additionally governed by our Privacy Policy.
6. Customer Data
Treasatech Global recognises that enterprise customers may process sensitive financial, operational, and business information through TreasuryFlow products.
Customer data handling depends on the applicable deployment architecture and contractual relationship.
Where a customer deployment is governed by a separate agreement, the applicable security, confidentiality, data-processing, and operational provisions of that agreement will apply.
Treasatech Global does not publicly disclose customer-specific security architecture, confidential configurations, credentials, internal network information, or other sensitive security information.
7. Integration Security
TreasuryFlow products are designed with integration and connectivity as important architectural considerations.
Integration mechanisms may be configured according to the customer’s environment and applicable requirements.
Sensitive authentication credentials and other confidential connection information should not be submitted through the public Treasatech Global website.
Detailed integration and security architecture information may be provided to qualified enterprise customers during an appropriate technical or security evaluation, subject to applicable confidentiality arrangements.
8. Security Monitoring and Logging
Treasatech Global may use security monitoring and logging mechanisms to:
- Detect suspicious activity;
- Investigate security events;
- Support incident response;
- Maintain system integrity;
- Troubleshoot technical issues;
- Meet applicable legal or regulatory requirements; and
- Support auditability and accountability.
Security logs and related technical information may be retained for periods required by applicable law, regulation, contractual requirements, or legitimate security needs.
9. Vulnerability Disclosure
Treasatech Global welcomes responsible reports of potential security vulnerabilities affecting our publicly accessible systems.
If you believe you have identified a security vulnerability, please report it to us as soon as reasonably possible.
Security reports should be submitted through:
Security Contact: info@treasatechglobal.com
Subject: Security Vulnerability Report – [Brief Description]
Please do not disclose the vulnerability publicly before Treasatech Global has had a reasonable opportunity to investigate and address the issue.
10. Information to Include in a Security Report
To help us investigate efficiently, please include as much of the following information as reasonably possible:
- A clear description of the suspected vulnerability;
- The affected website, application, endpoint, or component;
- Steps required to reproduce the issue;
- Proof-of-concept information, where appropriate;
- The potential security impact;
- Relevant request/response information;
- Screenshots or supporting evidence, where appropriate;
- The date and approximate time of discovery;
- Your contact information; and
- Any other information that may help our security team understand and reproduce the issue.
Please avoid including unnecessary personal data or confidential information in your report.
11. Responsible Testing
Security researchers and other individuals reporting vulnerabilities should take reasonable steps to avoid:
- Accessing or modifying data that does not belong to them;
- Accessing another person’s account;
- Disrupting services;
- Destroying or altering information;
- Introducing malware;
- Performing denial-of-service testing;
- Conducting social engineering against Treasatech personnel;
- Testing physical security;
- Obtaining or attempting to obtain credentials;
- Sending unsolicited communications to employees or customers; or
- Performing activities that may negatively affect customers, users, or production systems.
Where possible, use the minimum level of testing necessary to demonstrate the suspected vulnerability.
12. Prohibited Security Testing
Unless Treasatech Global has provided explicit written authorisation, do not perform:
- Denial-of-service or distributed denial-of-service testing;
- High-volume automated scanning that may affect service availability;
- Social engineering;
- Phishing;
- Credential attacks;
- Physical security testing;
- Malware deployment;
- Destructive testing;
- Data exfiltration beyond what is reasonably necessary to demonstrate the vulnerability; or
- Testing against customer environments or systems.
Unauthorised testing may cause disruption and may result in legal or other action.
13. Customer Environments
Treasatech Global products may be deployed in customer-controlled or customer-specific environments.
Security testing of customer environments must not be performed without the customer’s and, where applicable, Treasatech Global’s explicit written authorisation.
Do not attempt to access, test, scan, or investigate another customer’s environment.
If you believe that a vulnerability may affect a customer environment, report it to Treasatech Global without attempting to independently access or validate the customer’s data.
14. Security Report Handling
When Treasatech Global receives a security report, we may:
- Acknowledge receipt;
- Assess the report;
- Attempt to reproduce the issue;
- Determine severity and potential impact;
- Identify affected systems;
- Implement containment or remediation measures;
- Monitor the issue;
- Communicate with the reporter where additional information is required; and
- Close the report when appropriate.
Response times may vary depending on:
- Severity;
- Complexity;
- Availability of sufficient information;
- Affected systems;
- Operational circumstances; and
- Other relevant factors.
Submission of a report does not guarantee a particular response time, remediation timeline, reward, or public acknowledgement.
15. Security Severity
Treasatech Global may assess reported vulnerabilities based on factors including:
- Exploitability;
- Potential impact;
- Scope;
- Exposure;
- Likelihood of exploitation;
- Affected users or systems;
- Availability of compensating controls; and
- Business and security context.
We may use industry-recognised vulnerability assessment methodologies where appropriate.
A reported vulnerability’s classification may change as additional technical information becomes available.
16. Security Updates
Where appropriate, Treasatech Global may implement security updates, configuration changes, mitigations, monitoring controls, or other corrective measures in response to identified vulnerabilities.
The remediation approach will depend on the nature and severity of the issue and the systems affected.
We may not publicly disclose detailed technical information about vulnerabilities, mitigations, infrastructure, or internal security controls where doing so could increase security risk.
17. Coordinated Disclosure
We support coordinated vulnerability disclosure.
If a security vulnerability is confirmed, we may coordinate with the reporter regarding appropriate disclosure.
The timing and content of any public disclosure may depend on:
- Severity of the vulnerability;
- Availability of remediation;
- Risk to customers and users;
- Dependency on third parties;
- Regulatory requirements;
- Legal requirements; and
- Other security considerations.
We request that security researchers provide Treasatech Global with a reasonable opportunity to investigate and address a vulnerability before making technical details publicly available.
18. No Bug Bounty
Unless expressly announced by Treasatech Global, this Security Disclosure does not constitute a bug bounty programme.
Treasatech Global does not currently promise financial compensation, rewards, employment opportunities, or other consideration for vulnerability reports.
If a formal vulnerability rewards programme is introduced in the future, it will be governed by separate terms.
19. Security Contact
Security vulnerabilities should be reported to:
Treasatech Global Private Limited
Security Team
Security Email: info@treasatechglobal.com
General Contact: info@treasatechglobal.com
Registered Office: Plot No. 9, 4 Bay, Sector 32, Gurugram, Industrial Area Faridabad, Faridabad, Faridabad– 121001, Haryana
Website: treasatechglobal.com
For privacy-related matters, please refer to the Treasatech Global Privacy Policy.
20. Security Incident Reporting
If you believe that a Treasatech Global system has experienced a security incident, unauthorised access, data exposure, or other security event, please notify us promptly through the designated security contact.
Please provide:
- The nature of the suspected incident;
- The affected system or service;
- The approximate date and time;
- Relevant evidence;
- Any known or suspected impact; and
- Your contact information.
Do not include unnecessary sensitive personal data or confidential customer information in the initial report.
21. Protection of Confidential Information
Security researchers, customers, partners, and other parties should not intentionally access, copy, disclose, publish, or distribute confidential information belonging to Treasatech Global or its customers.
If confidential information is unintentionally accessed while demonstrating a security vulnerability, stop further access where reasonably possible and notify Treasatech Global promptly.
22. Security Documentation for Enterprise Customers
Treasatech Global may provide additional security and architecture information to prospective or existing enterprise customers as part of an appropriate evaluation or procurement process.
Depending on the engagement, this may include information concerning:
- Security architecture;
- Deployment architecture;
- Access control;
- Data protection;
- Integration security;
- Auditability;
- Operational controls;
- Business continuity;
- Incident response; and
- Other relevant security practices.
Certain information may be provided only under appropriate confidentiality or contractual arrangements.
23. Security Claims and Certifications
Treasatech Global does not represent that it holds any particular security certification, accreditation, compliance certification, or regulatory approval unless expressly stated and currently applicable.
Security certifications, audit reports, penetration-testing reports, compliance attestations, and similar materials will be disclosed only where they are current, accurate, applicable, and authorised for disclosure.
Nothing in this Security Disclosure should be interpreted as a representation that Treasatech Global has obtained a particular certification or accreditation unless expressly stated.
24. Limitation of Security Disclosure
This Security Disclosure describes our general security approach and vulnerability reporting process.
It does not disclose:
- Confidential infrastructure details;
- Customer-specific security configurations;
- Internal network architecture;
- Authentication credentials;
- Cryptographic keys;
- Security-sensitive source code;
- Internal security tooling;
- Vulnerability details that could increase security risk; or
- Other confidential security information.
Additional security information may be provided during an appropriate enterprise security evaluation.
25. Third-Party Services
Treasatech Global may use third-party technology and service providers for certain website, infrastructure, communications, security, analytics, or business functions.
The security and privacy practices applicable to such services may be governed by their respective agreements, policies, and security controls.
Where appropriate, Treasatech Global seeks to evaluate and manage third-party service providers in accordance with applicable business, security, privacy, and legal requirements.
26. Security and Website Availability
Security measures are intended to reduce risk but cannot eliminate all possible security threats.
No internet-connected system can be guaranteed to be completely secure or continuously available.
Threats may arise from:
- New vulnerabilities;
- Human error;
- Third-party dependencies;
- Infrastructure failures;
- Cyberattacks;
- Configuration issues; or
- Other circumstances outside reasonable control.
Treasatech Global continuously seeks to identify and address security risks appropriate to its systems and operating environment.
27. Changes to this Security Disclosure
Treasatech Global may update this Security Disclosure from time to time to reflect:
- Changes in our technology;
- Changes in security practices;
- Changes in vulnerability reporting procedures;
- Changes in applicable law;
- Regulatory requirements;
- Changes in our products or services; or
- Other operational requirements.
The latest version will be published on the Treasatech Global Website with an updated “Last Updated” date.
28. Governing Law
This Security Disclosure shall be governed by and interpreted in accordance with the laws of India, subject to applicable mandatory provisions of law.
Nothing in this Security Disclosure is intended to exclude or restrict any right or remedy that cannot legally be excluded or restricted.
29. Contact
For general security questions:
Treasatech Global Private Limited
Security Team
Security Email: info@treasatechglobal.com
Registered Office: Plot No. 9, 4 Bay, Sector 32, Gurugram, Industrial Area Faridabad, Faridabad, Faridabad– 121001, Haryana
Website: treasatechglobal.com
For privacy-related requests or grievances, please refer to the Privacy Policy.
For general website usage matters, please refer to the Terms of Use.
30. Effective Date and Version
Effective Date: 17 September 2026
Last Updated: 17 September 2026
Version: 1.0
End of Security Disclosure