Effective date 24 June 2026
This Information Security Policy (“Policy”) describes the security principles and practices adopted by Controlshift Talent Private Limited (“Controlshift”, “Yuruka”, “Company”, “we”, “our”, or “us”) to protect the confidentiality, integrity, and availability of information processed through Yuruka.
This Policy applies to all products, services, employees, contractors, systems, infrastructure, and third-party service providers involved in the operation of Yuruka.
The purpose of this Policy is to:
This Policy applies to:
Controlshift Talent Private Limited is committed to:
Access to systems and data is granted strictly on a need-to-know basis.
Security controls include, where appropriate:
Access is removed promptly when no longer required.
Users are responsible for maintaining the confidentiality of their credentials.
Yuruka implements appropriate authentication mechanisms designed to protect customer accounts.
Customers are responsible for:
Yuruka uses industry-standard encryption practices where appropriate.
This includes:
Yuruka is deployed using professionally managed infrastructure and cloud technologies.
Security measures may include:
Infrastructure components may change as our platform evolves.
Security is considered throughout the software development lifecycle.
Practices may include:
Yuruka applies security controls to AI-powered features.
These may include:
AI outputs should always be reviewed before being relied upon for significant decisions.
Customer Data is processed in accordance with:
Customers remain responsible for ensuring that their use of Yuruka complies with applicable privacy regulations.
Yuruka maintains logging and monitoring designed to:
Logs are retained in accordance with operational and legal requirements.
Controlshift Talent Private Limited works to identify and remediate security vulnerabilities.
This may include:
We encourage responsible disclosure of security vulnerabilities.
Yuruka maintains procedures for responding to suspected security incidents.
Our response process may include:
We implement reasonable measures intended to support service continuity.
These measures may include:
Despite these measures, uninterrupted availability cannot be guaranteed.
Personnel with access to systems or Customer Data are expected to:
Access is granted only where necessary for legitimate business purposes.
Yuruka relies on selected third-party providers to support the Services.
Where appropriate, we seek to ensure that providers handling Customer Data are contractually required to implement reasonable security measures.
Third-party providers may include services supporting:
Customers are responsible for:
If you believe you have identified a security vulnerability affecting Yuruka, please report it responsibly.
Please include sufficient information to reproduce the issue where possible.
Do not exploit vulnerabilities or access information that does not belong to you.
Security reports may be submitted to:
Email: support@yuruka.com
Yuruka is designed to support compliance with applicable legal and contractual obligations, including, where applicable:
This Policy does not constitute a certification or guarantee of compliance with any specific security standard unless expressly stated in writing.
We may update this Information Security Policy from time to time to reflect:
The latest version will be made available through our website.
Security-related questions or vulnerability reports may be directed to:
Controlshift Talent Private Limited
Registered Office:
944, Block C Sushant Lok Phase 1 Gurugram, Haryana – 122001 India
Website: https://yuruka.com
Email: support@yuruka.com
© Controlshift Talent Private Limited. All Rights Reserved.