1. Security controls
The production application is designed to use HTTPS, security headers, rate limiting, server-side environment variables, controlled upload types and audit logging where configured. Database credentials are not intended to be embedded in browser code.
2. Upload handling
Supported spreadsheet formats are validated at upload. File size limits and server storage locations are configurable. Operators should configure appropriate retention, backups and access controls for their environment.
3. Incident handling
Security incidents are investigated and handled according to applicable law, contractual commitments and service procedures. Where applicable, organisations should also consider the requirements and directions issued by CERT-In under section 70B of the Information Technology Act, 2000.
4. Enterprise deployments
Organisations with special requirements should request an appropriate security or data-processing schedule before uploading regulated or highly sensitive datasets.
Legal drafting notice: This document is drafted in a formal legal-policy style using current publicly available Indian statutory and regulatory sources and applicable Google publisher requirements. It is not a representation that an advocate or law firm has reviewed or issued this document. Pritika Enterprises should obtain a qualified Indian legal review before relying on it for a regulated or enterprise deployment.
