QEMRA legal
Security Policy
This document explains the rules, responsibilities, and protections that apply when you use QEMRA.
1. Security approach
QEMRA uses layered controls designed to protect customer data and keep business automation reliable. This page describes current security commitments; it is not a guarantee that incidents can never occur.
2. Data protection
QEMRA uses industry-standard protections to encrypt data in transit and at rest where applicable within QEMRA-managed storage and approved providers.
3. Access controls
QEMRA is designed around workspace/tenant isolation, server-side authorization, role-based access, least privilege, protected administrative operations and audit logging.
Authorized KRAVIA/QEMRA personnel may access customer conversations only when reasonably necessary for support, security, abuse investigation or troubleshooting. Such access is restricted and logged.
4. Authentication
QEMRA supports secure account sessions and optional multi-factor authentication. Stronger MFA enforcement may be required for administrators or offered under enterprise controls.
Inactive sessions normally expire after 30 days, with earlier revocation after relevant security events.
5. Payment security
QEMRA does not store full card/payment credentials. Cashfree or another approved payment processor handles payment credentials and applicable payment-security requirements.
6. Logging and monitoring
QEMRA maintains internal error and operational monitoring. Diagnostic logs are designed to collect only the minimum technical information reasonably needed for troubleshooting and reliability.
Full customer message content or sensitive data is not intentionally placed in error logs unless strictly necessary for an active investigation.
Default internal error-log retention: 30 days. Security/audit records: 1 year by default.
7. Backups
Protected backups are used where appropriate for recovery. After deletion in the active service, residual data may remain in backups until normal rotation removes it, normally within 30 days.
Backup copies are not used for ordinary product operations.
8. Incident response
QEMRA maintains procedures to detect/investigate incidents, contain affected systems, preserve relevant evidence, remediate vulnerabilities, recover service and notify materially affected customers without undue delay where required.
9. Vulnerability management
Confirmed critical security vulnerabilities are targeted for mitigation within 72 hours where practicable. Lower-severity issues are prioritized based on risk and exploitability.
10. Responsible disclosure
Security researchers may report vulnerabilities to noreply@qemra.vmnexa.co.in.
Please include the affected feature/URL, reproduction steps, potential impact, safe proof-of-concept where useful and contact details.
QEMRA targets acknowledgment of valid reports within 48 hours.
Safe harbor
KRAVIA/QEMRA will not pursue legal action against good-faith security research that follows this policy and avoids privacy harm, unnecessary customer-data access, service disruption, extortion, data destruction, unauthorized persistence, social engineering and actions beyond the minimum needed to demonstrate the issue.
This safe harbor does not authorize activity prohibited by law.
11. Customer responsibilities
Customers are responsible for securing their credentials, devices, team access, connected Meta/WhatsApp accounts, third-party integrations and user permissions.
12. Service status
Operational incidents may be published at https://status.qemra.vmnexa.co.in.
The public status page is intended to retain approximately 6 months of incident/outage history.
13. Security questions
Contact: noreply@qemra.vmnexa.co.in
