Yuruka

Security Policy

Effective date 24 June 2026

1. Introduction

This Information Security Policy (“Policy”) describes the security principles and practices adopted by Controlshift Talent Private Limited (“Controlshift”, “Yuruka”, “Company”, “we”, “our”, or “us”) to protect the confidentiality, integrity, and availability of information processed through Yuruka.

This Policy applies to all products, services, employees, contractors, systems, infrastructure, and third-party service providers involved in the operation of Yuruka.

2. Purpose

The purpose of this Policy is to:

  • Protect Customer Data.
  • Protect Candidate Data.
  • Protect Company Information.
  • Maintain platform availability.
  • Prevent unauthorized access.
  • Reduce cybersecurity risks.
  • Support compliance with applicable laws and contractual obligations.

3. Scope

This Policy applies to:

  • Yuruka Platform
  • APIs
  • AI Services
  • Recruitment Services
  • Enterprise Services
  • Internal Systems
  • Cloud Infrastructure
  • Customer Data
  • Candidate Data
  • Employees
  • Contractors
  • Third-party Service Providers

4. Security Principles

Controlshift Talent Private Limited is committed to:

  • Confidentiality
  • Integrity
  • Availability
  • Least Privilege Access
  • Defense in Depth
  • Secure by Design
  • Privacy by Design
  • Continuous Improvement
  • Risk-Based Security

5. Access Control

Access to systems and data is granted strictly on a need-to-know basis.

Security controls include, where appropriate:

  • Role-Based Access Control (RBAC)
  • Least Privilege
  • Administrative Approval Processes
  • Periodic Access Reviews
  • Secure Authentication
  • Multi-Factor Authentication for privileged accounts
  • Account Lockout Controls
  • Password Security Requirements

Access is removed promptly when no longer required.

6. Authentication

Users are responsible for maintaining the confidentiality of their credentials.

Yuruka implements appropriate authentication mechanisms designed to protect customer accounts.

Customers are responsible for:

  • Choosing strong passwords.
  • Protecting account credentials.
  • Managing internal user permissions.
  • Reporting suspected unauthorized access.

7. Encryption

Yuruka uses industry-standard encryption practices where appropriate.

This includes:

  • Encryption of data in transit using TLS/SSL.
  • Encryption of sensitive data at rest where appropriate.
  • Secure communication between services.
  • Encrypted administrative access where applicable.

8. Infrastructure Security

Yuruka is deployed using professionally managed infrastructure and cloud technologies.

Security measures may include:

  • Firewalls
  • Network Segmentation
  • Access Logging
  • Security Monitoring
  • Infrastructure Hardening
  • Secure Configuration Management
  • Patch Management
  • DDoS Mitigation (where supported)
  • Backup Systems

Infrastructure components may change as our platform evolves.

9. Application Security

Security is considered throughout the software development lifecycle.

Practices may include:

  • Secure Coding Practices
  • Code Reviews
  • Dependency Management
  • Vulnerability Remediation
  • Authentication Controls
  • Authorization Controls
  • Input Validation
  • Output Encoding
  • Logging
  • Error Handling

10. AI Security

Yuruka applies security controls to AI-powered features.

These may include:

  • Access controls
  • Request validation
  • Abuse detection
  • Usage monitoring
  • Prompt protection
  • Rate limiting
  • Human oversight where appropriate

AI outputs should always be reviewed before being relied upon for significant decisions.

11. Data Protection

Customer Data is processed in accordance with:

  • Privacy Policy
  • Data Processing Addendum (where applicable)
  • Applicable Data Protection Laws

Customers remain responsible for ensuring that their use of Yuruka complies with applicable privacy regulations.

12. Logging & Monitoring

Yuruka maintains logging and monitoring designed to:

  • Detect suspicious activity.
  • Investigate incidents.
  • Improve platform reliability.
  • Support security investigations.
  • Troubleshoot technical issues.

Logs are retained in accordance with operational and legal requirements.

13. Vulnerability Management

Controlshift Talent Private Limited works to identify and remediate security vulnerabilities.

This may include:

  • Security Reviews
  • Patch Management
  • Dependency Updates
  • Infrastructure Maintenance
  • Risk Assessments
  • Internal Testing

We encourage responsible disclosure of security vulnerabilities.

14. Security Incident Response

Yuruka maintains procedures for responding to suspected security incidents.

Our response process may include:

  • Detection
  • Investigation
  • Containment
  • Eradication
  • Recovery
  • Root Cause Analysis
  • Corrective Actions
  • Customer Notification where required by law or contract

15. Business Continuity & Disaster Recovery

We implement reasonable measures intended to support service continuity.

These measures may include:

  • Data Backups
  • Disaster Recovery Procedures
  • Infrastructure Redundancy where appropriate
  • Operational Monitoring
  • Recovery Planning

Despite these measures, uninterrupted availability cannot be guaranteed.

16. Employee Security

Personnel with access to systems or Customer Data are expected to:

  • Maintain confidentiality.
  • Follow internal security procedures.
  • Protect credentials.
  • Report suspected security incidents.
  • Complete security awareness activities as required.

Access is granted only where necessary for legitimate business purposes.

17. Third-Party Providers

Yuruka relies on selected third-party providers to support the Services.

Where appropriate, we seek to ensure that providers handling Customer Data are contractually required to implement reasonable security measures.

Third-party providers may include services supporting:

  • Cloud Infrastructure
  • Payment Processing
  • Telephony
  • Identity Management
  • Calendar Integration
  • Email Delivery
  • Analytics
  • Customer Support

18. Customer Responsibilities

Customers are responsible for:

  • Protecting account credentials.
  • Configuring user permissions.
  • Reviewing AI-generated outputs.
  • Securing endpoint devices.
  • Maintaining secure networks.
  • Providing lawful access to Customer Data.
  • Reporting suspected unauthorized access promptly.

19. Responsible Disclosure

If you believe you have identified a security vulnerability affecting Yuruka, please report it responsibly.

Please include sufficient information to reproduce the issue where possible.

Do not exploit vulnerabilities or access information that does not belong to you.

Security reports may be submitted to:

Email: support@yuruka.com

20. Compliance

Yuruka is designed to support compliance with applicable legal and contractual obligations, including, where applicable:

  • GDPR
  • UK GDPR
  • India’s Digital Personal Data Protection Act, 2023
  • Applicable information security obligations under customer agreements

This Policy does not constitute a certification or guarantee of compliance with any specific security standard unless expressly stated in writing.

21. Changes to this Policy

We may update this Information Security Policy from time to time to reflect:

  • Security improvements
  • Operational changes
  • Regulatory developments
  • Technology changes
  • Business requirements

The latest version will be made available through our website.

22. Contact

Security-related questions or vulnerability reports may be directed to:

Controlshift Talent Private Limited

Registered Office:

944, Block C Sushant Lok Phase 1 Gurugram, Haryana – 122001 India

Website: https://yuruka.com

Email: support@yuruka.com

© Controlshift Talent Private Limited. All Rights Reserved.