Core Assurance: As a premier cybersecurity practice specializing in Vulnerability Assessment and Penetration Testing (VAPT), FQRS adheres to strict non-disclosure obligations, ISO 27001 data handling standards, and zero-leakage protocols for all client data, source code, and security vulnerability reports.
1. Institutional Scope & Overview
FQRS (Forensic Quality Reporting Solutions) is committed to upholding the highest standards of data privacy, confidentiality, and technical information security. This Privacy Policy governs the processing of personal data, corporate telemetry, project scopes, and security research findings collected through our primary domain www.fqrs.co.in and during our professional cybersecurity engagements.
2. Information We Collect & Process
In the course of providing VAPT, security advisory, and vulnerability research services, FQRS collects information strictly necessary for service delivery and legal compliance:
- Corporate & Representative Information: Names, official business email addresses, designated contact phone numbers, job titles, and company affiliations provided during proposal requests or contract execution.
- Scope & System Telemetry: Domain names, IP ranges, application build binaries (Android APKs, iOS IPAs), API endpoints, and architectural documentation provided explicitly for security testing under formal Statements of Work (SOW).
- Security Findings & Technical Reports: Vulnerability data, proof-of-concept (PoC) exploit scripts, HTTP request/response logs, and remediation verification data generated during security assessments.
- Digital Interaction Data: Technical logs, browser user-agent strings, and IP addresses automatically collected during website visits for security monitoring and DDoS protection.
3. Strict Purpose & Non-Disclosure Protocols
FQRS processes collected data solely for legitimate, contracted security purposes. Under no circumstances does FQRS sell, lease, commercialize, or share client information or vulnerability data with advertising networks or unauthorized third parties.
- To perform rigorous VAPT audits and generate forensic-quality security reports.
- To communicate critical vulnerability findings directly to client-designated security teams via encrypted channels.
- To manage official cybersecurity partnerships, such as our ongoing infrastructure & application security management for Sales Funda®.
- To comply with statutory law enforcement mandates under valid Indian legal frameworks and judicial orders.
4. Forensic Data Encryption & Security Controls
Because security reports contain high-risk technical findings, FQRS enforces institutional security controls to protect client information:
- End-to-End Encryption: All client reports and vulnerability logs are stored on isolated, encrypted storage volumes utilizing AES-256 encryption at rest and TLS 1.3 in transit.
- Role-Based Access Control (RBAC): Access to client security findings is restricted strictly to assigned Lead Security Engineers working on the project.
- Secure Disposal: Upon final remediation verification and contract completion, temporary testing logs, intercept traces, and test binaries are permanently wiped in accordance with NIST SP 800-88 guidelines.
5. Confidentiality of Security Findings
All vulnerability assessment reports, vulnerability severity ratings, and proof-of-concept scripts developed during engagements remain the strict intellectual and confidential property of the client. FQRS will never publicly disclose specific vulnerabilities discovered in client systems without explicit, signed consent from the client's executive leadership.
6. Third-Party Partners & Platform Engagements
When FQRS acts as an Official Cybersecurity Partner (such as for Sales Funda®), security oversight extends to cloud infrastructure, CRM/ERP backend systems, and client-facing mobile applications. All cross-entity data transfers are governed by mutual Non-Disclosure Agreements (NDAs) and strict data protection addendums.
7. Incident Response & Breach Notification
In alignment with CERT-In directives and global data protection standards, FQRS maintains a rigorous Incident Response Plan (IRP). In the highly unlikely event of a data breach compromising client confidentiality:
- Affected clients will be notified without undue delay (within 24-72 hours of verification).
- Notifications will include the nature of the breach, compromised data categories, and immediate mitigation steps taken.
- FQRS will fully cooperate with client security teams and relevant statutory authorities for forensic investigation.
8. Sub-Processors & Data Sovereignty
FQRS utilizes enterprise-grade sub-processors for secure hosting and encrypted communication (e.g., AWS, Azure, enterprise email providers). All sub-processors are vetted for SOC2/ISO 27001 compliance. Furthermore, FQRS prioritizes data sovereignty; client assessment data for Indian enterprises is hosted strictly within geographic data centers in India, ensuring compliance with local data localization mandates.
9. Log Data, Cookies, & Telemetry
To maintain the security and performance of our digital infrastructure, our servers automatically record standard technical telemetry (Log Data) when you visit www.fqrs.co.in. This includes IP addresses, user-agent strings, and request timestamps. We use essential security cookies to prevent Cross-Site Request Forgery (CSRF) and DDoS attacks. We do not employ invasive tracking or third-party marketing cookies.
10. Client Data Rights & Access Requests
Clients and website visitors retain the right to inquire about their personal data, request rectification of contact details, or request formal confirmation of data purge upon contract conclusion. Data requests should be directed to our Data Protection & Security Officer at [email protected].
11. Contact & Governance Desk
For questions, formal legal notices, or privacy inquiries concerning this policy, please reach out to our team:
FQRS — Forensic Quality Reporting Solutions
Information Security & Compliance Desk
Email: [email protected]
Phone: +91 9022893397 | +91 8898784181
Web: www.fqrs.co.in